
What a Week
Discussed in this episode
Boost this Episode
Send sats directly to the creators. Value for Value.
Plus 1% to Podcast Index.
Show Notes
A bi-weekly news show informing you on the latest in Bitcoin, privacy and open source tech hosted by Ungovernables, Max and Q.
THIS IS THE TWEET Q WANTS YOU TO SEE: https://x.com/justh0dl/status/2086202393998291138
AOB
- What a fucking week
- KeyOS v1.3.1 now publicly available
- Something exciting to share on Friday's FTF (delayed by 2 weeks)
NEWS
The Coldcard entropy catastrophe
Sources: Coinkite technical backgrounder / The Rage, L0la L33tz / TRM Labs / coldcard.rip / cktripwire.com / Bitcoin Magazine victim survey
EXPLAINER
The largest self-custody theft on record, and it traces back to a single wrong conditional. In March 2021 a build guard checked whether Coldcard's hardware random number generator was defined rather than whether it was enabled, so seed generation silently fell back to a deterministic software PRNG. Every seed made on an affected device from that point carried roughly 40 bits of entropy on Mk2 and Mk3, and about 72 on Mk4, Mk5 and Q, instead of the intended 128. That is guessable. Someone did the maths offline, derived the addresses, checked them against the public chain, and swept everything with a balance. Somewhere between 1,400 and 1,800 bitcoin gone, depending on whose forensics you trust, with a median victim loss of one BTC. The part people keep missing: updating the firmware does not fix an existing seed. A weak seed is weak forever.
ACTION FOR LISTENERS
- Move funds to a brand new seed BEFORE upgrading firmware (Lopp's guidance, on reports of update problems).
- Use high fees. If you see your own coins in the mempool, the attacker opted into RBF and you can outbid them. Window is minutes.
- Multisig users: consider a private mempool like Marathon's Slipstream.
- Keep the device; the UID may prove ownership in any recovery process.
- Updating does NOT fix an existing seed. A weak seed is weak forever.
- You are exempt only if you added 50+ fair independent private dice rolls, or used a strong unique BIP39 passphrase stored separately.
BTCPay Server: unauthenticated LND macaroon theft, actively exploited
Sources: BTCPay security advisory / v2.4.2 release / CoinDesk / TFTC
CRITICAL FRAMING NOTE: this is ONE story, not two. The "BTCPay bug" and the "LND credential exploit" are the same event. The vulnerability is the macaroon leak. The Aug 8-9 wave of coverage is follow-up hardening, not a new incident. Do not present them separately.
REMEDIATION (updating alone is NOT enough)
- Update to v2.4.2. Verify "2.4.2" in the footer.
- Update NBXplorer to 2.6.10+.
- Revoke and regenerate LND macaroons. Updating stops new theft but does nothing about already-stolen credentials. Deleting files is insufficient; the macaroon root signing key must be destroyed at node level. v2.4.2 does this automatically for standard Docker deployments. Custom reverse proxies, separate Tor services or port forwarding must rotate manually.
- Move funds out of any BTCPay-generated on-chain hot wallet and recreate it.
- Update LND to 0.21.1. Audit for unrecognised channel closures, unknown peers, unexplained balance changes.
SIDE EFFECT WORTH FLAGGING: v2.4.2 removes public LND API access on Docker deployments, which breaks remote wallet connections such as Zeus connecting to your own BTCPay node. Intentional, no restoration timeline published.
BREAKING CHANGE: Greenfield Basic authentication disabled by default five minutes after account creation (#7492). BTCPay: "We are not aware of any user impacted by this breaking change, as API Keys authentication is generally used."
Boltz suspends all swaps indefinitely
Sources: Boltz statement / canary.boltz.exchange / The Defiant / TFTC / Bull Bitcoin statement
CORRECTION TO THE COMMON FRAMING: Boltz has not shut down. It suspended swap services indefinitely. And the canary sequence runs the opposite way to the rumour: lapsed → suspended → renewed clean.
The Bitcoin Red Team
Sources: Calle and Rob Hamilton on Nostr/X / Bitcoin Magazine / CoinDesk / TFTC / OpenSats Red Team Fund
SUMMARY
This is the story that explains the other four. After the Coldcard exploit, Calle and Rob Hamilton pointed frontier AI models at the open-source Bitcoin stack and started auditing everything. In 108 hours, 25 developers scanned 501 projects and produced 7,958 findings, 1,280 of them rated high or critical, at a compute cost north of 58,000 dollars. They found the BTCPay bug's neighbours, and Boltz cited exactly this dynamic when it switched itself off. The uncomfortable symmetry is that the same capability doing the defending is what an attacker almost certainly used on Coldcard in the first place. And the bottleneck turns out not to be finding bugs, it is telling anyone: only 19.5% of the projects they scanned even have a SECURITY.md file, and only 13.1% list a security contact. The scanners move at machine speed. Responsible disclosure is still hunting around for an email address.
BIP-110: the fork that mined two blocks and froze
Sources: bip110monitor.com / Peter Todd code review / Aaron van Wirdum, Bitcoin Magazine / Lopp's Layman's Guide / Saylor essay / CoinDesk
RELEASES
Bitcoin core / protocol
- libsecp256k1 v0.8.0 - 2026-08-03
- Adds a native Silent Payments (BIP-352) module directly into the crypto library nearly every self-custody wallet builds on, plus up to ~11% faster signature verification. Quietly the most consequential positive release of the fortnight: it lowers the bar for every wallet to ship reusable static receive addresses.
- Bitcoin Knots v29.4 - 2026-08-08
- Non-urgent maintenance: fixes a chainstate DB bug causing repeated large rewrites, and adds corruption-detection safeguards around BIP-110 mandatory signaling. No critical fixes. (No Bitcoin Core release in window; latest is v31.1 from 2026-07-08.)
Hardware / signing
- Coldcard Firmware 4.2.0 (Mk2/Mk3) - 2026-08-03
- The patch for the entropy catastrophe. Affected ranges: Mk2/Mk3 4.0.1 through 4.1.9; Mk4/Mk5 all before 5.6.0; Q all before 1.5.0Q. Companion fixes shipped the same day: 5.6.0 Mk4/Mk5, 1.5.0Q, 6.6.0X Edge, 6.6.0QX Edge Q. Updating does NOT fix an existing seed - changelog says Mk3 users "must regenerate any seeds made on earlier versions as their entropy is critically low at just ~40 bits." TAPSIGNER, OPENDIME and SATSCARD unaffected.
- Krux 26.08.0 - 2026-08-04
- Maintainer odudex is stepping down and the project may be archived. "Krux was not created by me: Jeff started it and passed it on to me, and now it is my turn to pass the torch." On succession: "Krux may be carried on by another maintainer, if a proof-of-work backed Krux contributor accepts the role. Otherwise the Krux project will be put in sunset mode and gracefully archived in a few months." Cause is hardware, not drama: "K210 chips are no longer produced, and Canaan dropped the Kendryte line entirely." Substantial release regardless: fixes a heap buffer overflow in the camera entropy module, adds stricter PSBT fee-calculation checks, replaces the Python UR stack with a faster C module, and makes Krux Installer fully offline.
- Frostsnap v0.3.0 - 2026-08-05
- FROST threshold-signing device ships reproducible/deterministic builds and "a fresh release signing key as part of an overhauled release-signing pipeline." Well timed in a fortnight where "can you verify what is running on your signer" is the whole conversation. Catch: the new key breaks in-place Android updates, so direct-APK users must uninstall, reinstall, and re-visit their threshold devices to restore.
- Trezor Suite v26.7.4 - 2026-08-04
- Lowers minimum Normal-priority fee rate to 0.2 sat/vB and ships updated Safe 7/5/3 and Model T firmware with security improvements.
- BitBoxApp 4.51.4 - 2026-08-07
- Bundles new BitBox02 firmware v9.26.5.
- Specter Desktop v2.1.11 - 2026-08-09
- Genuinely security-relevant: adds auth and CSRF protection to the HWI bridge settings, restores validation of active API tokens so revoked JWTs are rejected, and warns that Specter's auth layer does not encrypt the data folder. Also ships an in-app Coldcard Mk3 seed-entropy advisory.
- Bitkey source/2026-08-02-0031 - 2026-08-02
- Block's consumer hardware wallet, routine source drop.
Lightning
- BTCPay Server v2.4.2 - 2026-08-07
- Actively exploited, funds already stolen. "This release contains fix of a critical vulnerability that is being actively exploited. You need to update as fast as you can." Unauthenticated remote .macaroon disclosure for LND, plus a TOTP 2FA bypass via Greenfield Basic auth. Requires NBXplorer 2.6.10. Breaking change: Basic auth disabled by default five minutes after account creation. See News item 2 for full remediation.
- lnd v0.21.2-beta.rc1 and v0.20.3-beta.rc1 - 2026-08-08
- Not security releases and not related to the BTCPay exploit. Migration/stability fixes only: KV-to-SQL payment migration edge case, channeldb migration recovery, invoice handling, data races, bounded memory on graph sync.
- Zeus v13.1.3 - 2026-07-27
- Adds LND v0.21.1-beta support for embedded and remote nodes; patches known vulnerabilities in the ws, js-yaml and markdown-it dependencies. (Note: Zeus also shipped an unreleased swap-security sprint on 08-04 - verify…
Bitcoin is close to becoming worthless.
Now what's the Bitcoin? Bitcoin's like rat poison. Yeah. Oh. The greatest scam in history. Let's get it. Bitcoin will go to fucking zero.
Welcome back to the Bitcoin Brief, the show where me and q and a catch up every two weeks to talk about Bitcoin, privacy, open source, keeping your Bitcoin secure, and the news and software updates that matter.
I just wanted to say a massive thank you to everyone who's been supporting Ungovernable Misfits, and a big thank you to Foundation Devices for supporting the show. If you haven't already checked them out, go to foundation.xyzed.
They make cipherpunk tools for fuckwits, and anyone can use this, even me. If you have any questions or you want to reach out, feel free, and I'll be happy to go through things with you. For anything super technical, I'll pass you on to queue. If you wanna buy one of these incredible passports, use the code ungovernable.
It will get you a discount, and it will let them know that I'm shilling. I'd also like to say a huge thank you to the Cake Wallet team. Not only are they supporting this show, but they're also bringing out some incredible features.
For those of you who actually use Bitcoin and actually care about their privacy and security, Cakewallet make it incredibly simple for you to live outside of the traditional financial system.
You can use CakePay within the app to buy gift cards for food, petrol, and whatever else you might need day to day. You can use silent payments, and, of course, you can use Monero. You can connect both Bitcoin and Monero nodes, use coin control, and this team are constantly innovating.
And I'm really excited to be working with them. If you have any questions, you can reach out to me, but check them out at cakewallet.com. Download the APK or start using this today on Mac, Windows, Linux, iPhone, or, of course, your Android device.
Enjoy the show. Good morning, mate. How are you? Have you had some sleep? I have had a little bit of time away from the laptop this weekend, is very, very much needed. It's it's been a week. I sent a tweet actually. It's hands down the busiest week I've ever had in my almost five years at foundation. It's just been absolutely
intense, is is probably putting it quite lightly. Mhmm. And we're gonna dive into why, obviously, for those people that have been living under a rock. But, yeah, the the the barrage of notifications for the past seven days or slightly more than seven days because it all started going down on on the Thursday, didn't it? Mhmm. Has just been
just nonstop. Like, I look away from my computer and then there's there's like another 10 emails come in or, you know, you got another 25 notifications on Twitter or something like that. So it's it's been a wild ride.
So thankfully, I don't want to speak too soon and my desk is wooden and I'm touching it profusely here, but it seems like things might calm down this week. I thought that on Thursday and then the B2B thing happened, and then the world got turned upside down again. We'll get into that in a minute. But,
yeah, it feels like we're in a new world. It feels like everything's changed in a very, very, very, very short space of time. Yeah. So, yes, I was able to get out my bike yesterday, go and touch some grass, which is much needed. Bit of a mental reset after a truly Harrowing?
Harrowing. Yeah. I was trying to find the right word to describe it. A truly harrowing week. Yes. It was much needed. So how about you? Yeah. Not like yours, mate. As you know, nobody would come to me for self custody advice or help.
So it's it's very different being a self custody robot in these sort of times, and, yeah, I did feel for you. Obviously, normal challenges outside of Bitcoin, but nothing nothing like you were going through. Just more more just observing it. And like you say, it feels like a new world.
There was all the cold card stuff, and then I suddenly get a message like, ah, BTP. Problem. You go get your funds off and jump on there, and all all my channels are closed. I'm like, oh, fucking hell. And then I it's like, get it all off there.
So I'm fiddling around getting funds out, and then the website went down, and our VPS went down. And it's just like it was just one thing after another. And I was ripping out a kitchen at the time just covered in rubble and shit and filth and just, like, running back and forth from my laptop trying to get done. It's just
yeah. It felt as I had the rubble dropping off me, kinda felt like a good metaphor for, like, that feels what Bitcoin space is like. Just it is rubble at the moment, and it's a bit scary with the attacks that are going on with the capabilities of these models.
Yeah. Do you know what? Looking at like, we're gonna talk about a lot of doomerous stuff on on well, true to form. Like, we we seem to do that quite a lot on the brief. Lately anyway. But I genuinely think that, you know, aside from all of the heartbreaking
stories that we're going to talk about, because people have literally lost a lot of money as a result of this stuff, The silver lining is that when the dust has settled, we are gonna be so much stronger and more secure as an industry than we ever were before.
We we were all guilty of resting on our laurels way too much and not practicing what we preach in terms of, you know, don't trust, verify, like Mhmm. It's become very apparent that not many people were doing that. Yeah.
So I think, yeah, there's gonna be, there's clearly been a lot of pain in the last couple of weeks. And I don't doubt for one minute, there's probably gonna be plenty more
over the course of the next, God knows, maybe even twelve months, who knows, with with the way that the AI timeline is is shaping up. But we will be we once we've got over that, I think we will be stronger for it as a collective.
Yeah. I think that's fair. Like, like the very beginning of everything going on with AI, and I think now that as far as I can see, all the teams, all the responsible teams anyway, are heavily, heavily leaning into it and checking themselves and others.
And like any tool, you know, if it's the attackers that are using it first, we're gonna have these problems. And then once it's used by the people defending, it balances out to some degree. Yeah. But, yeah, it is crazy to see. And I suppose, like you say, it's better it happens this way than it's only accessible
by governments or three letter agencies or whatever, and then they cause the carnage, and we're not prepared in any way. Yeah. I think I I don't think this was on anybody's timeline, but, like, a lot of people are saying thank god for China.
Yeah. He ran about way because all all of the stuff that we're talking about and all of the improvements that are gonna come out of it are largely because of Chinese models. Because The US models, just they're too gated and they don't let you do this level of kind of
attacking your own code. And, you know, I understand why they might be putting those guardrails in. But like, then it's like you just said, it's like, who who gets the wielder power? It's it's a tricky one. I'm not saying I've got the the answer for it, but Yeah. Think it's clear. It like, from my side anyway,
everything being open seems to be a safer overall Yep. Situation because everyone has access. So you you have that counterbalance of good versus evil and, you know, whatever. So the fact that everyone has access is a better situation. I'm reading a book called chaos at the moment about the mansions.
That's a bit of a tangent here, but it goes into some of the depravity of the types of people who run things like MK Ultra. Their goals aren't always necessarily just complete evil, but they are prepared to do anything and use anything at their disposal to to have power and control.
Mhmm. And this is something that we see, like, consistently. So even if you have good people in some parts of government or who have access to
these types of tools and the likes of you or Seth or Zach or whoever who wants to, like, secure their own stuff and look after their customers don't have access, but these people do. You might have 10 people who are actually pretty good. They might do some questionable things, but they're actually pretty good.
The heart's in the right place. But you you're gonna have some fucking evil psychopaths in there as well. And you want them to have access to this stuff, but not you guys. It I just can't see how that works and who makes the decision of who has what. It it feels like it has to be open. That's the only way that you you get
a true, like, counterweight. Yeah. I think you're right. Alright. Well, I've got three items on my AOB list. The first one, we've kind of covered. It was short titled, What a Fucking Week.
I don't know whether you got the notes up or I have it. Yeah. Yeah. Just the next one, a bit more positive news, KeyOS version one point three point one is now available for your passport prime. Nice.
This one is a feature fast track off the back of all of this cold card debacle. Loads of users screaming for Dice rolls. Well, to be clear, this is not dice rolls yet. I know Zach's been teasing that on a separate That's not publicly available yet, but it is already kind of working on device and stuff.
One three one, the one that is publicly available that you can install right now is user added entry via pulling random seed words from the list out of out of a hut or a container so that you can type in the first 11 or the first 23 words depending on what seed word length you want.
And then when you do that, the the final word is, you know, some people kind of colloquially colloquially
call it like the checksum word where you need to do some computation basically. So you can't do it by hand. So you can't just pick 12 random words because it won't be a valid seed because the final one is kind of partially a product of the preceding 11 or 23 basically. You can't just do it all yourself.
So Passport Prime will do that for you. So you can bring your own entry in a very simple way just by picking words out of a hat. Mhmm. We've had that on Passport Core for quite some time, so this is just bringing Passport Prime up to speed, and that's available right now.
And yes, people have had god knows how many notifications, DMs, dice rolls is coming. Mhmm. Nice. Yeah. It's it's been cool to see how quickly you guys have been iterating since this. Like, that that seems like every day, there's something new and and another either blog post or iteration or feature or change.
Yeah. Not not much sleep has been had at Team Foundation recently. It's good. I mean, like, I I feel sorry for you a little bit. Not really. It's not really. No. You didn't know that be honest But yeah. Definitely deserve to some extent, but just generally the team.
But it's just good to see. And I think, again, this is, the good side of the AI. My guess is there's a decent amount of it being used for a lot of what you're building and iterating this fast unless you are just complete fucking machines.
So Of course. Like, we we we use it heavily, you know, and we also have heavy human gating on everything that ever gets anywhere near public facing. But, yeah, of course, we're we're using AI all over the place to to help streamline
Yeah. To help improve the security, like, in all facets of everything that we do, we're we're leveraging AI. While we're talking about KeyOS, did you see the image I tweeted this morning? Maybe not because I know it's early in the North Pole.
Did I? I saw a tweet saying that you were coming online with me and not sure what we're gonna talk about. It was it was an image, just a little teaser image of of Passport Prime showing a screen that says no installed apps a screen where you can add publishers and enable developer mode. Yeah. That side
load and install your own applications onto physical hardware. That is coming in the very next release version one point three point two, which again, I I reluctant to give any time scales, but you know, probably three to four weeks away maybe, pending how testing goes.
And this is going to open the floodgates basically. You know, you've heard me talking to to Max about all of the the apps that I've been vibe coding and there's loads on the website that other people have been submitting as well. So once one three two is available,
if you're if you want to, again, it's not mandatory, of course, install any app signed by a third party developer or signed by Foundation. You can go and do that as a side load. Sits very similar way that you would with with kinda like an Android APK.
You would just add it to a USB drive or a micro SD card, pop that into the bottom of your Passport Prime, and add whatever new app it is to add that additional functionality. So that's gonna become a reality very soon, and basically means that we
at Foundation no longer are the guardians of what lives on your passport prime. That's completely up to you and whatever anybody, yourself included, wants to build. Very nice. Very cool. And then the the the last one on my AOB is something that we've said, I think, maybe on the last two Bitcoin briefs, and
we've teased that there's something exciting coming on week. Friday. However, after the the cold card exploit, we have done two shows Mhmm. Talking about and delving into the the latest developments there because obviously it's the biggest thing to happen to Bitcoin self custody, unfortunately for the wrong reason,
in a number of years. So we've been spending a lot of time going over that, and thanks to Orange Turf for coming on last Friday. That was great. That was a really good one. So pending, you know, there's no World War three breaks out or something else catastrophic happens between now and Monday, August 10, and this Friday,
we will be ex sharing something exciting and new to the ungovernable We will. This Friday.
Let's hope. It'd be so nice if that happens and there's no other fires to put out. And and the the eagle eyes on the governables may have already spotted it, but I've not seen anybody say anything publicly yet, which is which is nice. Yes. Yeah. So, yeah, thanks for not sharing.
Yeah. Look forward to that. Fingers crossed. We don't have any other fires. Onto the doom. Okay. So for those of you that haven't been listening to the last two weeks of Freedom Tech Friday, if you haven't, shame on you. And you haven't been on Twitter or Nosta, and you basically had your head under a rock for two weeks.
The the largest self custody theft on record, I believe, don't quote me on that, took place not last Thursday, but the Thursday before. There was a catastrophic exploit found in the cold card firmware that had been active and unfound undetected, excuse me, for five
years. What happened was, basically, there there was a change, a significant change to their code base back in 2021 where they changed how they generate their the library that's used to generate the the the entropy or the randomness,
which is like the super important part of a of any hardware wallet is generating random numbers so that your seed words, your wallet essentially, is kind of not easy to guess and, you know, it's essentially the randomness that gives it its security.
As part of those changes, they made a colossal fuck up essentially, which meant that it didn't work as they thought they did, it did, and it silently fell fell back to a deterministic software based random number generator, which basically meant that any seeds generated on most models for a number of years
leveraged this very, very weak random number generation. And basically meant that the seeds did not have anywhere near enough entropy, so that they were very easy to guess with some relatively modest amount of hardware.
In the well, we're we're we're like a week and a half into this now, and unfortunately, the estimates are somewhere between $1,418,100 bitcoin have been wiped and swept from these wallets by attackers that are basically brute forcing easy to guess seed words now that they know that this, you know, people were generating
using cold cards to generate very weak seeds. People are kind of grinding through checking addresses from each resulting Bitcoin wallet millions of times a minute sweeping all of the funds.
So what this means for for cold card customers if they are using one of the affected devices, which for all intensive purposes is most of them from the mark three onwards. Think maybe the mark two might have been affected, but check the link in the show notes anyway. Yeah.
Basically means that if you allowed the device to generate the seed for you, and you didn't import your own seed, and you didn't either dice roll your seed or add your dice rolls to the entropy that the device the little entropy that the device was using to generate seed for you, then you have a very weak seed that's not random.
And to be honest, by now, it's probably already been swept. However, if you are listening to this thinking, shit. I have a cold card, I just let the device generate the seed for me, you need to take action immediately. Like, don't even listen to the rest of this podcast.
Go and move your funds right this second. Although, if I'm being honest, it's probably already gone. And that hence, why we did the live shows to to try and raise that, that awareness. They the Call Card team have,
since fixed the vulnerability, but, obviously, the nature of how this works is that it's already too late. Basically, the only kind of fallback you have is to move the funds. There are multiple different kind of attacker fingerprints here. So it's it it doesn't seem like it's just one person,
which makes sense because, like, once this kind of was known Yeah. People jumped on it, started throwing computer at it, and I've started draining draining funds. If you're if you're a hacker and you're, you know, you don't feel bad about stealing
Yeah. You would be like, well, this is a fucking good opportunity, isn't it? So the the aside now we've got like the obvious stuff out of the way, which is probably not news to most people if they listen to any of the people shows.
Just to recap, if you have a CoinKite product or a cold card product and you didn't you're you're not 100% confident that you added your own entry and it was sufficient, move your funds and never use that device again. Simple as that. Point blank.
Yeah. In the days that followed, the Internet did what the Internet likes to do, and they started doing some sleuthing. Mhmm.
There's there's been a couple of red flags raised, and I'm not gonna speak about this as fact. I'm gonna speak about this as, you know, there are multiple separate reports of questionable practices that were going on that may have contributed towards this issue.
Things like their lead developer doc hex, who's is the name, has also been found to have a separate name called Sweep. I think. Sweep. Who's using the same GPG key to sign to sign releases, so it's trivial for for people to to find out or link that they were the same people.
And it was this secondary name which weirdly was talking to the other name in public chats. So Doc X was talking to Switch, even though we now know that that's the same person. This Switch name was the one that made the library that essentially didn't work and caused the whole headache.
So there's lots of people asking very pointed questions as to this doesn't look very good. It hasn't been addressed to my knowledge by the Coincare team. They've been fairly silent, and weirdly, they're still selling devices. They they have communicated that they've destroyed any devices that contain
the the the boogie firmware, which would lose your funds. But they've rightly so also got a lot of stick for, like, continuing to to sell and remaining relatively silent other than I can't believe the fact that their store is still up. I can I can believe it because NV Gay is just the worst?
Yeah. What a fucking cock. You can't I just gonna go on a long rant there about what twatty is, but go on, mate. Well, can I can do it quite succinctly because people know I have biases and that foundation has had the long running differences with their CEO, NVK?
Yeah. But the the thing aside from what I just said about the store still being online and their apparent kind of lack of, you know, public disclosure, there's just so many red flags like the the NIM thing, the store still being online, the fact that MVK was calling this FUD just days before. Well respected
developer James O'Byrne actually reported a similar kind of issue, I believe, over a year ago and basically got shot down. If please go and check James' Twitter for the details. So coverage pivots to Peter Gray, who I believe is is Doc Hex
And Switch. Basically and Switch. Yeah. Ignoring the the twenty twenty five warnings from James O'Byrne. There's just there's just a lot of red flags. There's there's still no post mortem from it, from what I've seen.
Obviously, they have warnings and stuff and they've updated the firmware, but for most people unfortunately, that is too late. And throughout all of this, whilst there is, you know, almost radio silence from the Coincare team and it apparently took three or four days for them to email customers,
MVK is going around deleting tweets and deleting his Twitter history. Yeah. Presumably, he's trying to save some face, but unfortunately, like, people see it happening, and it really doesn't look good for you. Obviously, I have my biases as well just from seeing how that team has acted or not that team, really, just MVK,
specifically to, like, you guys at the seed signer and, like, just the problems that that bloke has caused. I have my own biases. But even if I take myself away from those biases and I look from an outside perspective, everything that you've just said looks really, really bad. Yep.
Whether it's just a massive fuck up or it's something more malicious than that, people have still lost their funds. Like, in a way, it doesn't matter so much. Like, people have lost their funds. It's devastating.
Like, I know a lot of the personal stories because some people are in our groups and stuff, and it's it's just heartbreaking. If it is what it sort of looks like, you've got to sort of question the motives and who's behind it, etcetera, because it certainly doesn't look good.
Rather than scrambling to try and help people who are losing funds and being on the other end of a call like someone like you is doing and, like, helping people. Instead, you're going and you're deleting tweets, and you've got your your lead dev is is two different people and and merging code from someone else who's actually themselves.
And then you've gotta think about how many devices they're actually have been selling over the years and how much money they've been spending on having influence over people, which is huge.
There's just a part of me that looks at it and goes, this doesn't add up. Yeah. Like I say, I can't speak in absolute facts, but there's there's a lot there's a lot of red red flags that have been raised since this has all gone down. Yeah. A couple of other kind of things that I wanna add on to this. If you're listening to this again and
you're a multisig user and cold cards form a majority of your key set, you need to take action quickly. You're not the lowest hanging fruit. Obviously, you have multisig, but you are still at risk, especially if you did the, you know, the basic c generation where you didn't add your own entropy.
You you still need to take action, and you still need to look to rotate those keys out if you're in the affected or users of the affected devices or more specifically, the affected devices running the firmware, the affected firmware at the time that you generated the seeds on those devices. That's the crucial part. So
don't rest on your laurels and think I've got multisig, I'm safe. Like, take a look at your your stack sorry, your your setup and if call cards form a majority key set, please take some action.
I don't know if there's anything else to add on this really. I think we've done it to death. I think there's shady shit that we can't fully go into the TLDR as if you have funds anywhere linked in any way, whether it's multi sig, single sig, dice rolls, has a passphrase, doesn't have a passphrase, whatever.
Just fucking get the funds off and then never use that company ever again. And don't forget who was involved, who shield it, who funded it, who pushed it, and who's trying to cover their tracks.
Take notes. Yep. Alright. Well, we can assume safely that it was probably an AI agent that found that bug given that I'm sure there was at least some code review for Call Card in the last five years since they introduced that bug. Clearly, it wasn't enough code review to find the bug.
But the the general consensus is that AI probably found it and began, you know, the exploits at the hand of, unfortunately, people who well, non white hat hackers, I guess, black hat hackers.
On this vein, I think we're gonna see lots more of this. Last Thursday, another, we believe, AI powered vulnerability. Another very severe one was discovered in BTC pay server. So a project that we talk about quite a lot on on the brief, one of our, you know, popular products or popular projects that we talk about.
Self hosted Bitcoin payment software basically allows you to, you know, be a merchant and accept Bitcoin directly. Many people run it with LND, the popular Lightning implementation, and this is where the bug was found.
LND uses credential files called macaroons. And the macaroon basically is kind of like a a bearer token that basically says, you know, whoever holds this macaroon, this token can do something, can have some permissions on this node.
There's no password, no second factor. Possession is authorization. It's kind of like a YubiKey sort of thing for you know, if you have the YubiKey, you can sign, and it's the same sort of thing for your LND node. If you have the admin Macaroon, you kind of have god mode to to that to that Lightning node. So the bug, BTCPay
was exposing those Macaroon files to unauthenticated remote attackers. No login, no credentials. Anybody who knew where to look could download the keys to your Lightning node, close channels, and sweep the funds.
To be specific, this is not a flaw within LND. LND, if you operate it outside of BTCPay, it is fine. If if this is only specific to LND users within BTC pay server. Is it? Yeah. I believe so. Yeah. Well, can I just throw a little frag in here? Oh, dear. I use c lightning,
and on the day of this exploit and when everything was kicking off, all my lightning channels were closed. Well, yeah, that'll be because you've got on the L and D side. Yes. Right. Fine. Okay. So take that back out again then. What does that mean that my funds were not even though I didn't have the lightning channels open,
they wouldn't have been at risk if they were open somehow? If I, like, had channels with other c lightning people? Yeah. Because if they if the person on the other end got attacked,
they would have run the channel the the attacker would have run the channel closure, and whatever funds were rightfully yours within the channel would have gone back to your Lightning node, the on chain part of your Lightning node. So you would be safe. Yes. Okay. Alright.
Fine. So, again, open call out. If you run BTCPay server, you have two things to do. Don't wait. Do them straight away. You need to update to version two point four point two, and you also need to revoke and regenerate your LND macaroons.
Updating the the BTP server software stops the new theft, but I I'm pretty sure I'm correct here. It doesn't do anything about any already stolen credentials. Although, let's be honest, if the credentials have already been stolen, then
your funds probably would have already been drained. But as a as a safety, regenerate your LND macaroons as well.
So that's the the action that you need to take. And, yeah, we we actually got hit at Foundation with this one. Zach's already mentioned it publicly, so I feel like I'm okay to talk about it. Yeah. Obviously, was a lightning node. You know, it wasn't a life changing amount of money.
The company's not gonna fall because of it, because we, you know, we have risk mitigations in place to manage that sort of stuff, but
doesn't make it any more any less annoying. It was actually me. I actually found this on our BC pay server before, like, seven hours before there was a public disclosure of the bug. So I don't know whether we maybe were one of the first first ones to get hit potentially.
But I I woke up to an email from our BTCPay server basically saying we had liquidity issues. And off the back of all of the cold card debacle, obviously, our sales have been absolutely through the roof. So I thought, oh, well, that makes sense. The channels are full.
I'll drain some funds off because we've had loads of, you know, inbound traffic, so the channels are probably full. Got online, saw all the channels closed, and then two blocks later, full sweep of the entire balance off to a legacy address. And I was like, fuck,
that doesn't look good. Because I know generally speaking, when we do any of that sort of admin back end y stuff, we just don't use legacy addresses. No.
So I spent the next, like, five to six hours panicking because obviously I'm in The UK and everybody most of the other team rest of the team who would be concerned with this are in The US, so they were all asleep. So I'm trying to figure out what the hell's going on, and basically couldn't do it. And we, you know, we we were doing
lots of triage throughout the day, and then the BT Pace of announcement, you know, their team announced that the vulnerability, were like, ah, okay. Well, now we know what it was. Little too late, obviously, but, yeah, it's a wild time. Yeah.
It's especially, like, you guys getting hit. Like, you do things right, you know, you're monitoring things, and you're still getting hit. You'd be reacting faster than most people.
I managed to get we had basically no funds on that. We do we had, like, two or three hoodie sales worth of stuff on there. You know? It wasn't, like, massive, but managed to get it off. And I and then I saw you guys have been hit, and I was like, fucking hell. This is not just, like, hitting
people who haven't done things right. It's it's like a real major attack because I hadn't really given it too much thought. And and let me say, the the one of the next things that's in the list today is another thing that we've talked about on the brief for so long.
BTCPay, without BTCPay, like, a lot of the ecosystem just goes down. And then we've also talked about Bolts, which we're get onto a bit. And, like, without that, a lot of the ecosystem goes down.
And so, like, we have cold card then that then that, and it just it's fucking I mean, we said at the beginning of the show, but it really is sometimes we do these episodes, and it's like some cunt in the government has suggested more KYC, KYC, another fucking retard, and another government said another thing about less freedom.
And it's like, there's news, but it's kind of not news. It's not really, like,
technically affecting us at that specific moment, and there's not really anything that we can do about it. And then suddenly, three things that are, like, directly affecting us and people we care about, like, bang, bang, bang. It's
it's scary, but in in a little kind of way, it feels like the old days where things were a bit more, like, dynamic and exciting. Yeah. Yeah. I know what you mean. Yeah. Just wild times. And and, again, it's all being driven by AI and and more specifically the the proliferation of open source Chinese models that are actually good.
There's a, you know, general consensus forming that Kimi I forget the model number now, k three maybe, is what people are using because it's, you know, it's almost like Opus sorry, Fable or or like the latest codex models level of ability, but it's open source and you got no guide rails. So if you're a
well, anybody really, you can point it at something and and, you know, ask it to do whatever you want. And if it, you know But if you were to point Fable at code base and say, try and find me some vulnerabilities that I can exploit, it's going to turn around and cut you off.
So it's kind of like a perfect storm, really. And I guess the only saving grace, like we said earlier, is that we all, you know, the white hackers, the good guys, if you like, also have access to this sort of stuff. So it then becomes a bit of a race as to who can find and fix their own stuff before people find and exploit
it from the other angle, if you know what I mean. And and since since the whole cold car stuff went down, like, we the amount of, I'll use air quotes, vulnerability reports we've had, like, I'm I'm the first put, like, first point of call where all of that stuff lands, obviously, on the support side of things.
It's been like a full time job in itself, just dealing with those and triaging those. Some of them have some weight, some of them are, you know, a lot of them are duplicates because people are all using similar models and pointing it at the exact same code base, inevitably you're going to get duplicates.
Almost become kind of like a bit of a DDoS on our time trying to kind of get over the mound here and work out what we need to do something about, triaging it all. Then it gets to the engineers, and they've got to look at it and try and fix it. And
and I think it's gonna continue like that for at least a couple of weeks whilst we kind of break the back of this. And but, again, harch back to, like, brave new world. The software will be stronger for it. And to be very, very clear, as of right now, none of those reports have been showstoppers for us at Foundation.
Obviously, I can't speak for anybody else, but all of the reports we've had have all been relatively minor, and there's no funds at risk whatsoever. I'm very confident in saying that. There is definitely stuff that we're gonna look to harden and fix, and we've already been tweeting about that sort of stuff going forward.
And we're we're thankful to all of the people that are coming forward with these vulnerabilities or, you know, code patches and stuff. But the amount of work that it takes to kind of
go through the process with each and every one of them is absolutely colossal, and I'm sure all of the Bitcoin companies are are feeling the pressure of that at the moment. Yeah. For sure.
Alright. Should we talk about Bolts?
Yeah. Another project we talk about well, we don't actually talk about it that often because it kind of it's one of those pillars of the Bitcoin ecosystem that kind of loads of people use it whether they know it or not, and it just kind of works. It's very useful. They don't do much singing or dancing about themselves. It's just there.
It's reliable. And We have we have talked about it quite a lot. We we actually have said if we if we checked the tapes, one day we have to have an AI do this. But many times, we've said fucking hell. They just ship. It's, like, incredibly important. If that goes down, we've got major problems.
Everyone uses it. It's fucking useful. It just works. The fees are decent. We've talked about it at length and saying it would be a major problem if it went down and then bang. Yeah. So the Bolts news, I'm actually gonna read their tweet announcement verbatim because it's very good at explaining
what's happened and why it's happened. Mhmm. So basically, bolts.exchange is disabled until further notice. Their API remains available for anybody to process refunds cooperatively, so no funds are locked up.
But in any case, your unilateral refunds will work as well if you've got the relative information. The support team stays reachable, and their quote, here's the the kind of crux of it. To be clear, this is not a response to a single incident.
Over the past months, we have seen a steady rise in automated AI assisted probing of our infrastructure, and we have dealt with several exploits. Each was contained, but the pattern is clear. Attackers now iterate faster than a team of our size can find a patch.
In the past few days alone, we saw a drastic acceleration, and we do not believe this asymmetry will reverse. After reviewing the results of our own recent security scans, we cannot responsibly re enable Bolt Swaps, especially as we are being actively targeted by what appear to be multiple
resourceful groups while whilst we race to deploy fixes. What we are seeing is a major paradigm shift for Bitcoin services operating on an open source stack, and it needs careful analysis.
Do not expect swap services to resume shortly. To be explicit, no funds were ever at risk. Bolt is noncustodial by design, and as a fully bootstrapped company, the losses were ours alone.
We don't know how yet how things will continue from here, but we'll keep you posted as soon as we can as soon as we've had time to catch our breath and make a decision. I think that's like the perfect summary of everything that we've just been talking about for the past half an hour. Right? Mhmm. Yeah.
So I mean, hats off to them for basically temporarily shutting down the business whilst they, you know, figure out what they're gonna do. And again, all of the Bitcoin companies are are kind of going through this.
The the flip side, I guess the bolt is that it's a live service that deals directly with funds and any vulnerability there is obviously very high stakes. So I can understand that, you know, their risk is kind of live.
Yeah. Which is different for like, you know, offline devices like what we produce and sell. So I hope it comes back because it's a fantastic service and we've already seen the rippling effect of this. You know, I mentioned earlier that Bolt is kind of like a pillar that props up a lot of the ecosystem and
the back end of a lot of wallets that have swap functionality. Bolt is what those wallets plug into. So you've got things like bull bitcoin, aqua, I think cake wallet had some exposure to it. Breeze, I believe, Zeus.
I don't know about Zeus, but there's lots of wallets basically that use bolts as a as a back end for whenever you And did a that just went went away overnight. So a lot of those providers are obviously looking for for alternatives.
And, yeah, that's the general gist of it, basically. If you are looking for for alternatives, if you wanna go from Lightning to Onchain or vice versa, can use Phoenix Wallet. A bit more costly, obviously.
Is Quite a lot more costly. Yes. You've got CoinOS, but I believe that's custodial, so be very careful there. Electrum desktop wallet has a submarine swap service, believe. I've never tested it. Please be careful, and it doesn't do liquid.
And then you've got, like, the the non sorry, the custodial versions like fixed float, side shift, and that sort of stuff. But again, it's custodial, so please be careful. And you could always just run a lightning node, open a channel, and use lightning. Of course. Yeah. Absolutely. There is always that option. And,
like because, you know, sometimes you don't wanna talk about these the the privacy things. But to some extent, anyone who's been a previous, like, Whirlpool user and all that kind of, like, actually cared about their privacy.
And if you want to use Bitcoin on chain to do anything really which touches the normal world, you have an issue. Like, you wanna do a swap, it's gonna get held. You wanna do you wanna buy gift cards, it's gonna get held. You wanna do a top up, it's gonna get held. And so Lightning was not perfect, but a pretty good way to break
links to something that broke links but then causes issues. And without faults, that's that's a big problem for people. So running a Lightning node even for people who maybe don't particularly like Lightning, it is a step that people can take to separate themselves from post books.
Yep. Absolutely. Alright. Final news item. It's kind of a news item. It's more of a shout out. In fact, I wanna do two shout outs. The first one I should have done earlier when we're talking about the call card stuff. I did a lot of talking down about them and the situation, and rightly so.
However, there is one person I do wanna call out, their their support guy, Dee. I can't even imagine what he'd gone through in the past two weeks. He is one of the good guys on that team. I've met him in person a couple of times, shared the stage with him more than once at various conferences.
He has his heart very squarely in the right place, and he's been working his fucking ass off whilst the CEO is running around deleting his tweets, is fucking ridiculous. But, anyway, just wanna give him a shout. Hope he's doing okay. I have no idea if he listens to this. But, anyway, if you are,
you know, caught up by this, please give him an easy time. He he's probably dealing with hundreds, if not thousands of people that are very, very pissed off, and I'm sure he's doing his best. I yeah. I mean, I I don't know the bloke, but if he's actually staying around and helping people who need help Yep. That is very admirable because
I'll be honest, if I was in his shoes and the CEO's deleting tweets and I've seen all the stuff that's come out, I'd be fucking out there. I'd be gone. So, yeah, respect you, mate. That's that's very cool.
Yeah. And then the next call out is, basically, as a response to everything that we talked about for the past forty five minutes. The the Bitcoin Red team was formed, I believe, by Rob Hamilton, CEO of Anchor Watch.
Basically, he spun up a team of volunteers that have now since called themselves the the Bitcoin Red Team to basically just point open source AI models at open source Bitcoin projects, finding as many bugs as they can and responsibly disclosing them to those projects so that they can go and fix them.
But it's all done in a responsible way, there's no flexing on Twitter. There's no, you know, stealing fund if they find something critical. They are spending their own money and their own time to go through all of this and basically contacting people sorry, contacting companies and projects to say, look, here's what we found.
We you know, it's AI powered. We haven't substantiated all of them because we're trying to get around as many people as we can.
But here's what we found. Do with it what you want, and and they even go as far as classifying all of the stuff as well. And they've spent tens of thousands of dollars of their own money doing this shit, and I believe there's now, you know, a fund so that people can contribute towards that. I thought it was funded by OpenSats
or one of those ones. I didn't know now has a fund open to support them. I believe Vic at Cake even gave them $10,000 as well, so shout out to Vic. Yeah. Thanks, man. And they there's been they've been posting updates on Twitter and stuff.
They've done like five over 500 projects. They've got nearly 8,000 findings. According to their findings, 16% of those are high or critical bugs. And they've got a cumulative spend. Again, this is probably gonna be moving all the time, but of over, well, nearly $60,000.
Jeez. And this is all on AI tokens for Kimi k three. Right. Okay. Okay. And with this kind of stuff, there's you're still better off just using tokens rather than your own hardware. There's no, like, tipping point where it's like Well, Kimi Kimi k three at at full weight, like, you need a data farm to run it. So you have to use API.
Fine. Okay. When you say a data farm, like, what's the infrastructure that you need for something like Probably a $100? Yeah. So it's okay. So a 100 so so my question is really, like, at what point if they've already spent 60 k, and this has been spun up since the the hack.
Yeah. But don't forget time is of the essence. Like, you can't wait No. I get it. No. No. I'm I'm not I'm not suggesting that. I'm just saying at what point if if this continues and you need a team checking projects constantly and doing this kind of work, at what point is there a fund to actually
have some hardware and then have that just running all the time for Yeah. For Bitcoin cup like, for example, you know, if you have, like, the the ten, twenty Bitcoin companies, top Bitcoin companies, hardware companies, software companies, you guys, cake, etcetera, and you'll go, do you know what? Look.
We'll check ten ten care at this, and let's all do that. Right? We got $200 in the pot. Let's have this thing running. Yeah. No. It's that's a good idea. And then you you reach out to base or or one of those guys in the the pleb minor groups and say, look. Can you sort me out a very good energy contract?
And you speak to John or one of those guys and say, can we run it using your power, and and have this thing in a container, etcetera. You know, at what point do we do something like that and it makes sense?
Yeah. Yeah. Well, I think it makes sense straight straight away, but I wanna be crystal clear here. Like, if you run a Bitcoin project, especially, you know, if you're a proper company, like, you should be doing this yourself, and you should have been doing it for quite some time. Yeah. Don't wait for for white hat white hat,
good hearted people like Cali and like Rob Hamilton to do it for you because it might already be too late. You you have like, you have no choice now. Do it yourself for every single release, or somebody else will, and it might lead to your customers losing funds.
No. No. I agree. I'm and I'm not I'm not suggesting that that is sort of like an instead of. I'm just suggesting it's an additional or or that there's a collective pool to share hardware.
So you, you know, you have the the top 10 or 20 companies or whoever it is who wants to invest some money into it, and they have the use ongoing to consistently just be reviewing their code. That that's more what I'm getting at. Not just, oh, let's just hope that a couple of good hearted people take their time.
Yeah. Yeah. I agree. I agree. Last one on, the news list, mate. This is gonna come as as a huge shock to you, mate. Are you sat down ready for this? I'm I'm literally just sitting down now. Tell me what's going on. Ready.
Bit one ten, it failed. What? Yeah. I know. Can you believe it? Oh my god. The game theory just didn't play out. I I don't know I don't know what we're gonna do. That's fine.
Nice. I saw the video going round of the the little gaggle of mongs who were watching it live, and it was just priceless. I don't know if you saw that. Really is. Yeah. Yeah. I did. So quick recap.
Bit one ten, it proposed a one year self expiring cap on arbitrary data within transactions designed to, quote, save the children and fight the spam. It capped new outputs at 34 bytes, op returns at 83 bytes, basically to try and fight ordinals, runes, b r c 20, anything with large data payloads.
And they set mandatory signaling was due to start block 961,632, and any block not signaling for bit one ten will be rejected as invalid by bit one ten nodes. And that took place on Friday.
And in a complete shock to everybody, they immediately forked themselves off the network and ground to a complete halt because none of the miners followed the the minority chain, and it well, it ground to a complete halt.
I'm looking at bit110.orange. Surf as of right now. There have been three blocks since Friday on that chain, and the next difficulty adjustment is scheduled Now to be clear, this is difficulty adjustment not halving is scheduled for four point seven years from now.
So a complete fail. Nobody saw it come in. And yeah. I mean, in all seriousness, like, none of this is a surprise. Those of you that paid absolutely zero attention to this whatsoever, well done. Well done for save saving your time. Yeah. Let's move on.
A 100%. I am interested to see what the the big bit one ten shillers who are on Twitter start doing now. Like, what what's their next move? I I am sort of watching that from the sidelines with interest. But, yeah, neither of us are interested in any of this bullshit since the start.
And in many ways, I wish we had just ignored it, but the memes were too funny, and we got pulled in. Yeah. Indeed. They they are they haven't waved the white flag yet, the one ten crowds.
I'm just looking at a couple of tweets now from Luke. He says there's one here, yes, hold tight. There's ongoing discussions today about how we can move forward. There's a Discord chat if you really wanna waste your time. No, don't. Don't do it. Don't do Yeah. I wouldn't bother.
It's my guess is that they're gonna change proof of work algorithm and go full b cash.
But we'll see. I I have no idea. Okay. Let's see.
Okay. Let's let's do some boosts. Let's hear from the ungovernables. I will kick us off. Late stage Hubble, 6,006. I hear the boosts and immediately say, damn it, they forgot to read my boost.
Then I check and find that I'm just a retard and I forgot to boost the last episode. Keep up the good work, gents. We'd love to hear an episode on the best way to sell off this new BIP, with a P, coin, to get more sats. Well, yeah, you might be waiting for a long time to get confirmed into a block.
Yeah. Even he said, even some of the custodial options. I wonder what places like Riverfold Unchained or any of the other shitcoin casinos might do or how it works with non custodial solutions also.
My guess is that it never even gets that far. Yeah. I I can't imagine that it would do. Chad Farrow streamed 1,205 sats. Sorry, mate. Can you give me literally two minutes? I just need to stop someone making a load of noise. One sec.
BTC Jason streamed 987 sats. Shadrach streamed oh, no. He sent 939 sats and said, thank you, gents, forty hours per week. Cast peeling streamed 784 sats. Pleb to polymath streamed 550 sats.
Reven stokes sent 500 sats and said, watch out when selling your bitcoins. They are directly linked to your real bitcoins. User seven three two four one four three seven at fountain.fm sent a streamed a 190 sats. And as always, nosdygang sent us a 111 sats, and they said, repent.
I think there's quite a few people repenting now. We just hit a a couple of releases, because I wanna wrap us up because I'm I'm almost at time. I forgot to mention a couple of fun little tidbits around the the Bit $1.10 nosedive.
Jordan, please remind me to put these in the show notes to link them because they are comedy goals. The the so Knoop Svanholm, Bitcoin Mechanic, Matt Crater and some other podcast guy were doing a livestream when when the Mandatory Signal went live. Yeah, this is what I watched, was amazing.
And basically, so they're all on on camera and there's a mempool dot space open, a bit one ten version and a and a actual Bitcoin version. And the the block that was mined that didn't signal for bit one ten that forked them off the network was mined by who, Max?
Ocean. And you can just see the life just drain out of Bitcoin mechanic when it pops up on screen. And I I know you shouldn't find pleasure in other people's Other people's pain. Discomfort, but,
know, these people have been running and running around calling people pedophiles for the last six months. So Yeah. Yeah. I feel a bit more comfortable having a little chuckle when that happened.
Yeah. And and the awkward, like, they were, like, trying to, like, laugh it off. Yeah.
Somebody calls. So please, please, please, Jordan, don't forget to put that to link that tweet in the show notes. It's absolute genius. Yeah. And, again, like I said, with all the cold card stuff, this is this is not as bad, obviously, but remember the people who try and steer you wrong
and and do you harm. Just remember them and don't sort of next cycle again, just forget and and let them weasel their way into your thoughts. Just just draw a line onto them and just say, nah, monks.
Yep. Absolutely.
And then the other one was a tweet from Ocean. When did they send this? Well, late last night, UK time. Update for Ocean miners. We wanted to clarify yesterday's activity around a bit one ten and non bit one ten mining operations.
For roughly eighteen hours, some miners using Ocean's stratum templates may have believed they were they were mining on the bit on the non
bit one ten chain, basically, actual Bitcoin. Yeah. Actual Bitcoin. While their hash rate was directed to the bit one ten chain. Naughty naughty. Yeah. So in fairness, they recognized it, and they're going to be distributing approximately naught 0.3 bitcoin to affected miners.
So good to see that they've kind of been open and corrected it, but I thought that was a bit of a chuckle as well. Alright, quickly going to whiz through the releases. Zeus has got an update thirteen point one point three, and it updates their LND version, and then a load of bug fixes.
And then the last one, Ashigaru desktop version one point one point two, live connection status, one click disconnect, reconnect,
and faster startup connectivity to your Dojo as well. And finally, the Whirlpool coordinator warning clears on recovery. So if you have a warning that says can't reach the Whirlpool coordinator, the banner now disappears as soon as the coordinator is reachable again. Hold tight, Jordan.
Right. I hope to see you in two weeks with more positive news, mate, but I'm not holding my breath. Yeah. Yeah. Definitely don't do that. We'll speak on Friday anyway. We will. Thanks everyone for tuning in, for sharing the show, and I hope that everyone has now, if they could,
saved their funds. If anyone needs help, probably speak to queue. If anyone needs just a shoulder to cry on or someone to rant with, you you can reach out to me. We're always here. So hope everyone is good, and we'll catch you on Friday.
Alright. Love you all. Stay safe. Before you go, mineinbox. Help keep your online presence hidden. They provide anonymous server hosting solutions, virtual, private, and dedicated servers, domain registration and DNS parking, they don't require any of your personal information and you can purchase using Bitcoin,
Lightning or Monero. No personal information required. None. Zero. Minenbox.io. Stay ungovernable.
Machine transcript; expect the odd mishearing. Click a passage to play from there.




