<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Bitcoin.Review]]></title><description><![CDATA[Updates and commentary on Bitcoin and related projects.]]></description><link>https://substack.bitcoin.review</link><image><url>https://substackcdn.com/image/fetch/$s_!Kwpr!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a95ac75-ac77-4167-9383-9930a48690bb_1080x1080.png</url><title>Bitcoin.Review</title><link>https://substack.bitcoin.review</link></image><generator>Substack</generator><lastBuildDate>Wed, 29 Apr 2026 02:22:20 GMT</lastBuildDate><atom:link href="https://substack.bitcoin.review/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Bitcoin Review Podcast]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[bitcoinreview@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[bitcoinreview@substack.com]]></itunes:email><itunes:name><![CDATA[NVK]]></itunes:name></itunes:owner><itunes:author><![CDATA[NVK]]></itunes:author><googleplay:owner><![CDATA[bitcoinreview@substack.com]]></googleplay:owner><googleplay:email><![CDATA[bitcoinreview@substack.com]]></googleplay:email><googleplay:author><![CDATA[NVK]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[BR097 - Cove Wallet, Harbor, ecash, Sparrow, Liana, Bull Bitcoin, JoinMarket, Hardware Wallets, Coinbase Breach, BitLocker Vulnerability, Lightning Phoenixd, LSP Legality + MORE ft. Praveen, Ben, Paul]]></title><description><![CDATA[I&#8217;m joined by guests Praveen Perera, Future Paul & Ben Carman to go through the list.]]></description><link>https://substack.bitcoin.review/p/br097-cove-wallet-harbor-ecash-sparrow</link><guid isPermaLink="false">https://substack.bitcoin.review/p/br097-cove-wallet-harbor-ecash-sparrow</guid><dc:creator><![CDATA[STACK TO THE FUTURE]]></dc:creator><pubDate>Thu, 05 Jun 2025 17:36:07 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a95ac75-ac77-4167-9383-9930a48690bb_1080x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I&#8217;m joined by guests <a href="https://x.com/PraveenPerera">Praveen Perera</a>, <a href="https://twitter.com/futurepaul">Future Paul</a> &amp; <a href="https://twitter.com/benthecarman">Ben Carman</a> to go through the list.</p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://bitcoin.review/podcast/episode-97/&quot;,&quot;text&quot;:&quot;Listen on your favorite podcast app&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://bitcoin.review/podcast/episode-97/"><span>Listen on your favorite podcast app</span></a></p><div><hr></div><h3><strong>Housekeeping</strong></h3><ul><li><p>New COLDCARD Co-Sign (CCC) Tutorial: Automated Multisig with Spending Policies [<a href="https://www.youtube.com/watch?v=EDd6HYh7XbU">YouTube</a>]</p></li></ul><h3><strong>Bitcoin</strong></h3><h4><strong>Software Releases &amp; Project Updates</strong></h4><ul><li><p>00:01:29 Cove Wallet</p><ul><li><p><a href="https://github.com/bitcoinppl/cove/releases/tag/v0.5.1">v0.5.1</a></p><ul><li><p>Added</p><ul><li><p>Terms and Conditions popup, which is required to use the app</p></li></ul></li><li><p>Bug Fixes</p><ul><li><p>Show updated label on UTXO list screen</p></li><li><p>Show updated label on transaction details screen</p></li><li><p>Hot wallet import flow where erasing to a correct word would not show the word as valid</p></li></ul></li></ul></li><li><p><a href="https://github.com/bitcoinppl/cove/releases/tag/v0.5.0">v0.5.0</a></p><ul><li><p>Coin Control</p><ul><li><p>New UTXO list screen to search, filter, sort and select individual UTXOs</p></li><li><p>Select individual UTXOs to send from</p></li><li><p>Set a custom amount to send from a UTXO list (the rest will be sent to change)</p></li><li><p>Show UTXO labels on the confirm screen</p></li><li><p>Search UTXOs by amount</p></li></ul></li><li><p>Others</p><ul><li><p>Add warning if fee is more than 20% of the amount you are sending</p></li><li><p>Disallow sending if the fee is more than 100% of the amount you are sending</p></li></ul></li></ul></li><li><p><a href="https://github.com/bitcoinppl/cove/releases/tag/v0.4.1">v0.4.1</a></p><ul><li><p>Redesign address QR receive sheet</p></li><li><p>Redesign &#8220;Advanced More Details&#8221; sheet in the send flow</p></li></ul></li></ul></li><li><p>00:18:14 <a href="https://bitcoin.review/podcast/episode-97/Harbor.cash">Harbor</a></p><ul><li><p>Harbor 1.0 is now available</p></li><li><p>Mac, Windows (kind of), and Linux binaries available</p></li><li><p>Head over to the <a href="https://github.com/HarborWallet/harbor/releases">release page on GitHub</a> to download it</p></li></ul></li><li><p>00:35:45 Sparrow Wallet</p><ul><li><p><a href="https://github.com/sparrowwallet/sparrow/releases/tag/2.2.2">v2.2.2</a></p><ul><li><p>Retrieve and show next block median fee rate in Recent Blocks view where available</p></li></ul></li><li><p><a href="https://github.com/sparrowwallet/sparrow/releases/tag/2.2.1">v2.2.1</a></p><ul><li><p>Update Tor library to fix missing UUID issue when starting Tor on recent macOS versions</p></li><li><p>Repackage <code>.deb</code> installs to use older gzip instead of zstd compression</p></li><li><p>Remove display of median fee rate where fee rates source is set to Server</p></li><li><p>Add icons for external sources in Settings and Recent Blocks view</p></li></ul></li><li><p><a href="https://github.com/sparrowwallet/sparrow/releases/tag/2.2.0">v2.2.0</a></p><ul><li><p>Add Recent Blocks view to Send tab</p></li><li><p>Convert all bitmapped images to theme aware SVG format for all wallet models and dialogs</p></li><li><p>Support send and display of pay to anchor (P2A) outputs</p></li><li><p>Switch camera library to openpnp-capture</p></li><li><p>In the Download Verifier, prefer verifying the dropped file over the default file where the file is not in the manifest</p></li><li><p>Show a warning when importing a wallet with a derivation path matching another script type</p></li><li><p>Avoid server address resolution for public servers</p></li><li><p>Add a tooltip to indicate truncated labels in table cells</p></li><li><p>Dynamically truncate input and output labels in the tree on a transaction tab, and add tooltips if necessary</p></li><li><p>Improve tooltips for wallet tabs and transaction diagrams with long labels</p></li><li><p>Show the address where available on input and output tooltips in transaction tab tree</p></li><li><p>Show the total amount sent in payments in the transaction diagram when constructing multiple payment transactions</p></li><li><p>Show transaction diagram fee percentage as less than 0.01% rather than 0.00%</p></li><li><p>Optimize and reduce Electrum server RPC calls</p></li><li><p>And more</p></li></ul></li></ul></li><li><p>00:37:05 BDK bdk_chain <a href="https://github.com/bitcoindevkit/bdk/releases/tag/chain-0.23.0">v0.23.0</a></p><ul><li><p>This release of bdk_chain v.0.23.0 introduces a new option to cache and persist derived script pubkeys, improving performance on KeychainTxOutIndex startup, the tx_graph module now tracks and persists the first_seen timestamp for transactions which is useful for transaction ordering. The bdk_core crate added convenient is_empty methods to types TxUpdate, {Sync,Scan}Response, making it easier to check for no-op updates.</p></li><li><p>Also released:</p><ul><li><p>bdk_core v0.6.0</p></li><li><p>bdk_bitcoind_rpc v0.20.0</p></li><li><p>bdk_electrum v0.23.0</p></li><li><p>bdk_esplora v0.22.0</p></li><li><p>bdk_file_store v0.21.0</p></li><li><p>bdk_testenv v0.13.0</p></li></ul></li></ul></li><li><p>00:37:52 Liana <a href="https://github.com/wizardsardine/liana/releases/tag/v11.0">v11.0</a></p><ul><li><p>Add multi-wallet support</p></li><li><p>Add coin control for recovery transactions</p></li><li><p>Add a new RPC command to list addresses that have been revealed to the user, whether used or not</p></li><li><p>Add ability in the GUI to view unused addresses that were previously generated by the user</p></li><li><p>Add support airgap flow (SD card) for Coldcard &amp; Krux signing devices</p></li><li><p>It also includes various other improvements and fixes</p></li></ul></li><li><p>00:38:24 Nunchuk Android <a href="https://github.com/nunchuk-io/nunchuk-android/releases/tag/android.1.68.1">v1.68.1</a></p><ul><li><p>Custom blockchain explorer</p></li><li><p>Ability to archive wallets</p></li><li><p>Ability to long-press &amp; reorder wallets on Home</p></li><li><p>Anti-fee sniping setting</p></li></ul></li><li><p>00:39:02 Bull Bitcoin Mobile</p><ul><li><p><a href="https://github.com/SatoshiPortal/bullbitcoin-mobile/releases/tag/v5.0.0">v5.0.0</a></p><ul><li><p>The entire application has been rearchitected from the ground up for: Ease of adding new features, debugging and collaboration</p></li><li><p>Additionally; the app has a fresh new UI that focuses on simplicity and consistency</p></li><li><p>Supported Features</p><ul><li><p>Create/Recover Default (Bitcoin/Liquid Wallet)</p></li><li><p>Send/Receive</p></li><li><p>Swaps - LN (Bolt11 &amp; LN Address) &amp; Chain</p></li><li><p>Payjoin (0.23)</p></li><li><p>Transaction History</p></li></ul></li></ul></li><li><p><a href="https://github.com/SatoshiPortal/bullbitcoin-mobile/releases/tag/v5.0.3">v5.0.3</a></p><ul><li><p>Support for fiat currency preference</p></li><li><p>Swap Fee Breakdown</p></li><li><p>Fix calculation of absolute fees</p></li><li><p>High Fee warning in send</p></li><li><p>Default RBF true</p></li></ul></li></ul></li><li><p>00:40:39 Blue Wallet <a href="https://github.com/BlueWallet/BlueWallet/releases/tag/v7.1.8">v7.1.8</a></p><ul><li><p>Add: single-address Taproot wallets support (import from WIF)</p></li><li><p>Add: Search txs</p></li><li><p>Add: ManageWallets search address</p></li></ul></li><li><p>00:41:00 Bitkey App <a href="https://bitkey.world/en-US/releases">v2025.10.0</a></p><ul><li><p>Introduce Security Hub: Display all security and recovery settings in one place, with clear recommendations that help take the guesswork out of protecting your bitcoin.</p></li></ul></li><li><p>00:43:10 RoboSats <a href="https://github.com/RoboSats/robosats/releases/tag/v0.7.8-alpha">v0.7.8</a></p><ul><li><p>For Users:</p><ul><li><p>New coordinator: LibreBazaar</p></li><li><p>New payment method: Nomad</p></li><li><p>Major libraries update</p></li><li><p>Coordinator ratings are now cryptographically verified</p></li><li><p>Private chat message are also sent as nip17 as part of the full migration of the chat to nostr</p></li><li><p>Android adaptive Icons support</p></li></ul></li><li><p>For Coordinators:</p><ul><li><p>Nostr notes are now additionally published to port 7778</p></li></ul></li></ul></li><li><p>00:43:21 FullyNoded <a href="https://github.com/Fonta1n3/FullyNoded-Server/releases/tag/v0.1.1-beta">v0.1.1-beta</a></p><ul><li><p>Add icons to display Join Market session, conjoin and maker status</p></li><li><p>Dedicated button for configuring the Join Market network, useful when switching networks with Core</p></li><li><p>Ability to easily delete Core wallets, proceed with caution&#8230;</p></li><li><p>Tor updated to v0.4.8.14</p></li></ul></li><li><p>00:44:03 Zaprite <a href="https://help.zaprite.com/en/articles/11457769-zaprite-release-notes-2025-05-26">v2025-05-26</a></p><ul><li><p>Enable new Auto-pay feature for all accounts</p></li><li><p>Enable Auto-pay and customer card management for our Stripe connection</p></li><li><p>Add Misty Breez LNURL integration</p></li><li><p>Add new filter on the Orders page that shows Abandoned Orders</p></li><li><p>Add message to the Checkout UI showing the customer how much they could save if paying with a discounted payment method</p></li><li><p>Add new Filters to the Transactions table: Currency, Method, Connection, and Type</p></li><li><p>Add small preview to image upload fields which shows a small thumbnail of the image after it has been uploaded</p></li></ul></li><li><p>00:45:43 BoltzExchange</p><ul><li><p>boltz-client <a href="https://github.com/BoltzExchange/boltz-client/releases/tag/v2.6.1">v2.6.1</a></p><ul><li><p>Add new <code>getpairs</code> CLI command</p></li><li><p>Handly unavailable backend gracefully on startup</p></li></ul></li><li><p>boltz-backend <a href="https://github.com/BoltzExchange/boltz-backend/releases/tag/v3.11.0">v3.11.0</a> - Counteroffer</p><ul><li><p>Add support for Reverse Swaps to BOLT12 offers</p></li><li><p>gRPC hooks to change the behaviour of the backend</p></li><li><p>And many more added features</p></li></ul></li></ul></li><li><p>00:45:46 Padawan Wallet <a href="https://github.com/thunderbiscuit/padawan-wallet/releases/tag/v0.16.0">v0.16.0</a> - Xeric X-Wing</p><ul><li><p>Improve transitions between important screens</p></li><li><p>Pull out translations into separate structure (localizations/ directory)</p></li><li><p>Re-write theme (Tatooine Desert)</p></li></ul></li><li><p>00:46:23 Blockstream Green Android <a href="https://github.com/Blockstream/green_android/releases/tag/release_5.0.0">v5.0.0</a></p><ul><li><p>Nags to backup recovery phrase</p></li><li><p>Bitcoin price chart in Home</p></li><li><p>New tab based navigation</p></li><li><p>UI Refresh</p></li><li><p>Notifications for buy related events</p></li></ul></li><li><p>00:46:37 Samourai Dojo <a href="https://github.com/Dojo-Open-Source-Project/samourai-dojo/releases/tag/v1.27.0">v1.27.0</a></p><ul><li><p>Add Soroban and PandoTx functionality</p></li><li><p>Update ban script to disconnect inbound Knots nodes</p></li><li><p>Regenerate fulcrum certificate if expired</p></li><li><p>Check if transaction already exists in pushTx</p></li><li><p>Add new information to transaction API endpoint</p></li><li><p>Add txout API endpoint</p></li><li><p>Add ability to manage API keys</p></li><li><p>Add new /support/services RPC endpoint</p></li><li><p>Add an option to use blocksdir config for bitcoin blocks directory</p></li><li><p>Use prebuilt addrindexrs binaries</p></li><li><p>Add instructions to migrate blockchain/fulcrum</p></li></ul></li><li><p>00:46:49 ESP-Miner <a href="https://github.com/bitaxeorg/ESP-Miner/releases/tag/v2.8.0">v2.8.0</a></p><ul><li><p>API enhancements:</p><ul><li><p>Add expected hashrate to API</p></li><li><p>Dashboard: Get expected hash rate from API</p></li></ul></li><li><p>UI/UX improvements</p></li><li><p>Hardware and display enhancements: Add support for multiple displays</p></li><li><p>Performance and compilation</p><ul><li><p>feat: add -O2 compiling</p></li><li><p>Update version of CrC calculations</p></li></ul></li></ul></li><li><p>00:46:51 NBXplorer <a href="https://github.com/dgarage/NBXplorer/releases/tag/v2.5.27">v2.5.27</a> (NBXplorer is a minimalist UTXO tracker for HD wallets. The goal is to provide a flexible, .NET-based UTXO tracker for HD wallets. The explorer supports P2SH, P2PKH, P2WPKH, P2WSH, Taproot and multi-signature derivations.)</p><ul><li><p>Introduce policy wallet tracking support (BIP388, BIP389) enabling users to track wallets with complex spending conditions via Miniscript. Taproot trees and other output descriptors like musig (BIP390) are also supported.</p></li></ul></li><li><p>00:47:12 Mempal <a href="https://github.com/aeonBTC/Mempal/releases/tag/v1.5.3">v1.5.3</a></p><ul><li><p>Add swipe-down feature to refresh dashboard</p></li><li><p>Add custom time option for widget auto-update frequency</p></li></ul></li></ul><h4><strong>Project spotlight</strong></h4><ul><li><p>00:47:23 DahLIAS (Discrete Logarithm-Based Interactive Aggregate Signatures): Bitcoin&#8217;s first full signature aggregation scheme for secp256k1 [<a href="https://bitcoinmagazine.com/technical/not-ecdsa-not-schnorr-meet-dahlias">Bitcoin Magazine</a>]</p><ul><li><p>DahLIAS, developed by researchers from Blockstream and Ledger, introduces the first constant-size aggregate signature scheme based on discrete logarithms in pairing-free groups, offering significant space savings and verification speedups for blockchain systems.</p></li><li><p>The signing protocol requires only two rounds, with preprocessing capabilities, and verification is approximately twice as fast as batch verification of individual Schnorr signatures.</p></li></ul></li><li><p>00:48:25 <a href="https://mannabitcoin.com/">Manna Bitcoin</a>: A self-custodial spending wallet featuring merchant tools and PoS interface</p><ul><li><p>It supports on-chain Bitcoin, Lightning Network, and Liquid Bitcoin transactions</p></li></ul></li><li><p>00:48:34 <a href="https://darkwire.cyb3r17.space/">Darkwire</a>: A project that enables off-grid communication and Bitcoin transactions using LoRa technology [<a href="https://github.com/cyb3r17/darkwire">Github</a>]</p><ul><li><p>Messages are signed, fragmented, encrypted, and transmitted through mesh networks without ISPs or satellites</p></li><li><p>Currently supports Bitcoin transactions and text messages</p></li></ul></li><li><p>00:48:44 <a href="https://parasite.space/">Parasite Pool</a>: An open-source Bitcoin mining pool with zero fees that offers Lightning-native payouts with a 10-satoshi threshold for home miners</p><ul><li><p>The pool features a &#8216;pleb eat first&#8217; reward structure, giving 1 BTC to block finders while distributing remaining 2.125 BTC plus fees among all other participants via Lightning.</p></li><li><p>Small-scale miners benefit from outsized rewards relative to hashpower, making it suitable for those who need discrete operations while supporting Bitcoin&#8217;s resistance to censorship.</p></li></ul></li><li><p>00:48:55 <a href="https://allesvoorbitcoin.be/toolsguides/blockpickergame/">Blockpicker</a>: A tool to create entropy for a seed phrase by picking blocks [<a href="https://github.com/avbpodcast/blockpickergame">Github</a>]</p><ul><li><p>Blockpicker Entropy Game Blockpicker is an interactive, game-based tool for generating BIP39-compliant 24-word mnemonic seed phrases.</p></li><li><p>Players select blocks on a 12x12 grid in a turn-based game against a computer opponent, contributing entropy to create a cryptographically secure seed phrase.</p></li></ul></li><li><p>00:49:10 LOCK Protocol: A Bitcoin-based access protocol for encrypted secrets [<a href="https://github.com/bramkanstein/lock-protocol">Github</a>]</p><ul><li><p>LOCK is an open protocol that uses Bitcoin transactions as cryptographic proofs to decrypt secrets</p></li><li><p>The protocol seals secrets in encrypted vaults with specific unlock conditions (wallet signature, fee amount, and optional block height) that can only be met through valid Bitcoin transactions.</p></li></ul></li><li><p>00:49:17 <a href="https://sigbash.com/">Sigbash</a>: A tool to sign blindly after conditions are met (A project developed by <a href="https://x.com/arbedout">@Arbedout</a>)</p><ul><li><p>Sigbash provides a signing service that integrates with multisig wallets, offering signatures only under predefined conditions.</p></li><li><p>The conditions for signing include factors like hashrate, Bitcoin price, address balance, or time, and are checked using mempool.space&#8217;s API. Each xpub includes a cryptographic receipt and OpenTimestamps proof.</p></li></ul></li><li><p>00:49:38 <a href="https://arkadeos.com/">Arkade OS</a>: A virtual execution layer that transforms VTXOs and transaction trees into programmable money while maintaining security guarantees [<a href="https://github.com/arkade-os/">Github</a>]</p><ul><li><p>The open-source Arkade ecosystem includes a <a href="https://github.com/arkade-os/compiler">compiler</a> for Bitcoin-native smart contracts, a <a href="https://github.com/arkade-os/wallet">mobile wallet</a> with PassKey authentication, and a custom script interpreter featuring over 30 new opcodes.</p></li><li><p>Arkade&#8217;s implementation demonstrates how core components like VTXOs, presigned transaction trees, and batch settlements serve as building blocks for future functionality beyond payment optimization.</p></li></ul></li><li><p>00:50:09 <a href="https://swiftbitcoin.org/">Swift Bitcoin</a>: Pure-Swift Bitcoin library and full node implementation with minimal dependencies [<a href="https://github.com/swift-bitcoin/swift-bitcoin">Github</a>]</p><ul><li><p>Swift Bitcoin is a cross-platform fully-featured Bitcoin development framework for Swift projects</p></li><li><p>It includes a standalone network client daemon as well as a command line utility for on-chain and off-chain operations</p></li></ul></li><li><p>00:50:36 Pythia: Rust implementation of p2p-derivative-oracle for DLC trading [<a href="https://github.com/dlc-markets/pythia">Github</a>]</p><ul><li><p>DLC Markets open sources Pythia, its dedicated price oracle system under MIT Licence</p></li><li><p>Pythia provides real-time, reliable BTC/USD price attestations.</p></li></ul></li><li><p>00:50:45 Arcana Seed Lodge: A Bitcoin wallet experience shaped by memory, mystery, and map-based entropy [<a href="https://github.com/Arcana-Seed-Lodge/arcana-seed-lodge-core">Github</a>] (WIP/Experimental wallet)</p><ul><li><p>Arcana Seed Lodge is a location-based Bitcoin wallet generator that lets you create secure, human-friendly seeds by selecting six meaningful locations on a map.</p></li><li><p>Features</p><ul><li><p>Generate deterministic Bitcoin seeds from 6 memorable places</p></li><li><p>Optional lore-driven story mode with Freemason vibes</p></li><li><p>Supports offline PSBT signing (Sparrow-compatible)</p></li><li><p>Built for privacy-first, device-free recovery</p></li><li><p>Includes a demo wallet (not secure&#8212;just for testing)</p></li></ul></li></ul></li><li><p>00:50:54 <a href="https://pajasevi.github.io/bip47-verifier/">BIP47 Message Verifier</a>: A verifier for messages signed with BIP47 notification address [<a href="https://github.com/pajasevi/bip47-verifier">Github</a>]</p><ul><li><p>A tool to verify messages signed with a PayNym</p></li></ul></li><li><p>00:51:02 <a href="https://apps.apple.com/us/app/traxe/id6744660207">Traxe</a>: An iOS app to track your bitcoin home miners [<a href="https://github.com/reez/Traxe">Github</a>]</p><ul><li><p>Features:</p><ul><li><p>Automatically discover and manage your home miner devices on your network</p></li><li><p>Monitor miner stats and performance in real time</p></li><li><p>Support for Light and Dark mode</p></li><li><p>StandBy support for always-on at-a-glance monitoring</p></li></ul></li></ul></li><li><p>00:51:08 <a href="https://censorshipresistant.com/">Censorship Resistant</a>: A website offering an overview of Bitcoin&#8217;s security model, attack vectors economic incentives, potential attack vectors, and decentralization of mining.</p></li><li><p>00:51:21 <a href="https://www.areabitcoin.co/preview/dashboard">Bitcoin-4-All</a>: A comprehensive open-source Bitcoin course with 10 lessons in Portuguese, English and Spanish [<a href="https://github.com/areabitcoin/Bitcoin-4-All">Github</a>] (Developed by AreaBitcoin and supported by OpenSats)</p><ul><li><p>The course covers Bitcoin fundamentals, wallet setup, and Bitcoin advantages</p></li></ul></li></ul><h3><strong>Vulnerability Disclosures</strong></h3><ul><li><p>00:51:38 <a href="https://www.coinbase.com/en-pt/blog/protecting-our-customers-standing-up-to-extortionists">Coinbase data breach</a>: Rogue support agents expose KYC details of ~1 million customers [<a href="https://www.bleepingcomputer.com/news/security/coinbase-discloses-breach-faces-up-to-400-million-in-losses/">Bleeping Computer</a>]</p><ul><li><p>Cybercriminals with rogue overseas support agents steal personal data of approximately 1% of Coinbase&#8217;s user base, demanding a 20 million ransom, which has not been granted.</p></li><li><p>The stolen data includes names, addresses, government IDs and account information.</p></li><li><p>The data breach <a href="https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/f61fae18-f669-499e-9a87-f4d323d281f8.html">allegedly</a> occured on Dec 26, 2024 and discovered May 11, 2025.</p></li></ul></li><li><p>00:54:07 Ledger Donjon: Vulnerability in Tangem&#8217;s Android genuine check process [<a href="https://www.ledger.com/tangem-genuine-check-bypass-on-android-application">Disclosure</a>]</p><ul><li><p>A code flaw in Tangem&#8217;s Android app allows counterfeit hardware wallets to pass verification checks. The bug occurs when the app incorrectly checks attestation status, which allows cards with invalid signatures to appear genuine.</p></li><li><p>Exploiting this vulnerability requires obtaining a genuine card&#8217;s ID and public key, then creating a counterfeit card that sends these credentials while providing an invalid signature.</p></li><li><p>Tangem addressed the issue in version 5.18.3 by fixing the code to properly check attestation status.</p></li></ul></li><li><p>00:54:46 CVE-2023-21563: BitLocker encryption bypassed in minutes with Bitpixie vulnerability [<a href="https://cybersecuritynews.com/windows-11-bitlocker-encrypted-files-accessed/">CyberSecurity News</a>] 00:55:59 - A critical software-only vulnerability called &#8220;Bitpixie&#8221; enables attackers to bypass Microsoft&#8217;s BitLocker encryption in under five minutes without physical tampering.</p><ul><li><p>The attack exploits the Windows bootloader&#8217;s failure to clear the Volume Master Key from memory during PXE soft reboot.</p></li></ul></li></ul><h3><strong>Privacy &amp; Other Related Bitcoin Projects</strong></h3><h4><strong>Software Releases &amp; Project Updates</strong></h4><ul><li><p>00:57:14 SimpleX</p><ul><li><p><a href="https://github.com/simplex-chat/simplex-chat/releases/tag/v6.4.0-beta.0">v6.4.0-beta.0</a></p><ul><li><p>&#8220;knocking&#8221;: review members prior to admitting them to your group</p></li><li><p>Talk to your group members directly via chats between all group admins and members</p></li></ul></li><li><p><a href="https://github.com/simplex-chat/simplex-chat/releases/tag/v6.3.4">v6.3.4</a></p><ul><li><p>Recognize domain names as links (e.g., simplex.chat)</p></li><li><p>Forward compatibility with &#8220;knocking&#8221;</p></li><li><p>iOS improvements:</p><ul><li><p>Opening the links in the browser/any other apps now requires confirmation in all cases</p></li><li><p>Secrets in messages (e.g., #hidden secret#): shown on tap one by one, new design</p></li></ul></li></ul></li></ul></li><li><p>00:57:15 NomadNet <a href="https://github.com/markqvist/NomadNet/releases/tag/0.7.0">v0.7.0</a></p><ul><li><p>Add interface management and statistics</p></li><li><p>Add ability to specify page background and foreground colors to Micron parser</p></li><li><p>Add transfer speed to progress bar</p></li><li><p>Improve memory consumption when serving or downloading large files</p></li></ul></li><li><p>00:57:16 Sideband <a href="https://github.com/markqvist/Sideband/releases/tag/1.6.1">v1.6.1</a></p><ul><li><p>Update included RNS to version 0.9.6 to use AES-256 by default</p></li><li><p>Add option to configure shared instance access</p></li></ul></li><li><p>00:57:17 Mullvad introduces <a href="https://mullvad.net/en/blog/launching-mullvad-vpn-loader">Mullvad VPN Loader</a>: An application that automatically verifies integrity and authenticity of downloaded app installations on Windows and macOS systems</p><ul><li><p>The loader utilizes global third-party CDNs rather than solely Swedish servers, increasing download speed by accessing content delivery networks closer to customers.</p></li></ul></li><li><p>00:58:17 Signal Desktop <a href="https://signal.org/blog/signal-doesnt-recall/">Update</a></p><ul><li><p>Signal Desktop now implements &#8220;Screen security&#8221; setting on Windows 11 by default to prevent Microsoft Recall from capturing screenshots of private conversations.</p></li><li><p>Signal uses DRM technology to block Recall, which takes screenshots every few seconds and stores them in a searchable database.</p></li></ul></li><li><p>00:58:20 Have I Been Pwned <a href="https://www.troyhunt.com/have-i-been-pwned-2-0-is-now-live/">v2.0</a> (HIBP is a tool to check if your email address is in a data breach)</p><ul><li><p>Interface rebuild</p></li><li><p>Unify user tools into central dashboard</p></li><li><p>Remove username/phone number search from the web interface (email remains the sole supported search identifier)</p></li><li><p>Add dedicated breach pages: streamlined information and tailored post-breach advice, including future support for passkeys and localized resources</p></li><li><p>Redesign dashboard and domain search tools: introduce client-side filtering and improved domain verification</p></li></ul></li><li><p>00:58:22 KYCnot.me <a href="https://blog.kycnot.me/p/new-kycnot">Update</a> (A directory of trustworthy alternatives for buying, exchanging, trading, and using bitcoin and cryptocurrencies without having to disclose your identity)</p><ul><li><p>New features include a point system, automated ToS scraper for KYC/AML detection, full-text search functionality, and public discussions now on GitLab.</p></li><li><p>Complete rewrite in Golang after previous versions in Python/Flask and SvelteKit, now using MariaDB instead of JSON files</p></li><li><p>The website is now mostly JavaScript-free (except for request forms) and now officially available on Tor and I2P networks</p></li></ul></li></ul><h4><strong>Project spotlight</strong></h4><ul><li><p>01:00:26 Oniux: A tool that utilizes various Linux namespaces(7) in order to isolate an arbitrary application over the Tor network [<a href="https://gitlab.torproject.org/tpo/core/oniux">GitLab</a>] (A tool by the Tor Project. Considered experimental software)</p><ul><li><p>Oniux is a command-line utility that uses Linux namespaces to isolate applications over the Tor network, preventing data leaks by placing apps in their own network namespace with a custom interface. [<a href="https://blog.torproject.org/introducing-oniux-tor-isolation-using-linux-namespaces/">Blog post</a>]</p></li><li><p>Unlike torsocks, which uses SOCKS proxying through libc, oniux works on all Linux applications including static binaries and can prevent malicious applications from leaking data through direct system calls.</p></li></ul></li></ul><h3><strong>Lightning + L2+</strong></h3><h4><strong>Project spotlight</strong></h4><ul><li><p>01:00:39 <a href="https://www.routstr.com/">Routstr</a>: A decentralized LLM routing marketplace powered by Nostr and Bitcoin [<a href="https://github.com/routstr">Github</a>]</p><ul><li><p>The platform features a Smart Client SDK that finds optimal models, self-hosted proxies for OpenAI-compatible endpoints, and built-in privacy routing through SOCKS5 and Tor.</p></li><li><p>Routstr facilitates micropayments between AI Model Providers and End Users through Cashu ecash tokens and BOLT12 Lightning invoices.</p></li></ul></li><li><p>01:01:31 <a href="https://lnemail.net/">LNemail</a>: Fast anonymous email accounts powered by Bitcoin Lightning Network payments [<a href="https://github.com/lnemail/lnemail">Github</a>]</p><ul><li><p>LNemail offers anonymous email accounts for 1000 sats per year, requiring no personal information and operating on LN payments.</p></li><li><p>Service limitations: receiving only, no IMAP access (web interface or API), attachments not supported, and plain text only.</p></li><li><p>No IMAP Access: Emails can only be accessed through our web interface or API.</p></li></ul></li><li><p>01:02:22 Lightning Blinder: Trick an LSP into thinking one wallet is the sender or recipient when it&#8217;s really some other wallet [<a href="https://github.com/supertestnet/lightning_blinder">Github</a>]</p><ul><li><p>The software aims to improve privacy on the Lightning Network by enabling mobile users with intermittent connectivity to route payments</p></li></ul></li><li><p>01:02:32 Phoenixd MCP Server: Connect a phoenixd bitcoin lightning wallet to your LLM using Model Context Protocol [<a href="https://github.com/Sharmaz/phoenixd-mcp-server">Github</a>]</p><ul><li><p>This tool helps integrate LN payments and node management into your AI workflows</p></li></ul></li><li><p>01:03:27 <a href="https://amboss.tech/rails">Amboss Rails</a>: A liquidity provider service allowing Bitcoin treasuries and custodians to earn yield while maintaining self-custody of their assets [<a href="https://amboss.tech/blog/introducing-rails">Announcement</a>]</p><ul><li><p>The service generates returns through payment routing fees and liquidity leases on the Magma Marketplace.</p></li><li><p>&#8220;Amboss handles node operations with strictly limited permissions (receive lightning, open channel, close channel), using AI-driven insights derived from over five years of network data&#8221;</p></li></ul></li><li><p>01:03:48 Sixty Nuts: A NIP-60 Cashu Wallet in Python [<a href="https://github.com/shroominic/sixty-nuts">Github</a>]</p><ul><li><p>A lightweight, stateless Cashu wallet implementation following NIP-60 specification for Nostr-based wallet state management.</p></li><li><p>Features:</p><ul><li><p>NIP-60 Compliant: Full implementation of the NIP-60 specification</p></li><li><p>NIP-44 Encryption: Secure encryption using the NIP-44 v2 standard</p></li><li><p>Stateless Design: Wallet state stored on Nostr relays</p></li><li><p>Multi-Mint Support: Can work with multiple Cashu mints</p></li><li><p>Async/Await: Modern Python async implementation</p></li><li><p>LNURL Support: Send to Lightning Addresses and other LNURL formats</p></li></ul></li></ul></li><li><p>01:03:54 BTCNutServer: A Cashu plugin for BTCPayServer allowing merchants to use Cashu Ecash as payment method [<a href="https://github.com/d4rp4t/BTCNutServer">Github</a>] (This plugin is in early beta and its cryptography has not been reviewed. Cashu is still experimental and not production-ready.)</p><ul><li><p>BTCNutServer enables BTCPay Server to accept Bitcoin payments via Cashu tokens, offering two flexible payment models: &#8216;Trusted Mints&#8217; (Swap) and &#8216;Melt Immediately&#8217;</p></li></ul></li></ul><h4><strong>Software Releases &amp; Project Updates</strong></h4><ul><li><p>LND <a href="https://github.com/lightningnetwork/lnd/releases/tag/v0.19.0-beta">v0.19.0-beta</a></p><ul><li><p>New Features</p><ul><li><p>Add support for archiving channel backup in a designated folder which allows for easy referencing in the future. A new config is added disable-backup-archive, with default set to false, to determine if previous channel backups should be archived or not.</p></li></ul></li><li><p>Protocol Updates</p><ul><li><p><code>lnd</code> now supports the new RBF cooperative close flow</p></li><li><p>Add support for experimental endorsement signal relay</p></li><li><p>Add initial support for quiescence. This is a protocol gadget required for Dynamic Commitments and Splicing that will be added later.</p></li><li><p>Fixed a case where the initial historical sync may be blocked due to a race condition in handling the syncer&#8217;s internal state</p></li><li><p>The max fee rate is now respected when a coop close is initiated</p></li></ul></li><li><p>Functional Enhancements</p><ul><li><p>Add ability to paginate wallet transactions</p></li><li><p>Make <code>MaxWaitNumBlocksFundingConf</code> configurable, allowing integration/development tests to set a lower value for faster funding confirmation timeout while keeping the default of 2016 blocks for production stability</p></li><li><p>Add validation to ensure that MPP parameters are compatible with the payment amount before attempting the payment</p></li></ul></li><li><p>And more: RPC Additions, lncli Additions, Functional/RPC/lncli Updates, Code Health, and Performance Improvements</p></li></ul></li><li><p>Core Lightning <a href="https://github.com/ElementsProject/lightning/releases/tag/v25.05rc1">v25.05rc1</a></p><ul><li><p>Features for Users</p><ul><li><p>Reduced latency of commit and revoke messages</p></li><li><p>Reckless can update existing reckless-installed plugins via <code>reckless update</code></p></li><li><p>Fixed routing of AskRene via high capacity channels</p></li><li><p>More accurate anchor fees</p></li></ul></li><li><p>Features for Developers</p><ul><li><p><code>listhtlcs</code> pagination support with <code>index</code>, <code>start</code> and <code>end</code> parameters</p></li><li><p>The <code>wait</code> api now supports the <code>listhtlcs</code> subsystem</p></li><li><p>The beginnings of LSPS client and server plugins so far implementing the LSPS0 transport protocol</p></li><li><p>New <code>signmessagewithkey</code> rpc to sign input messages with our wallet keys</p></li><li><p><code>sendonion</code> is now compatible with <code>sendpay</code> with addition of <code>total_amount_msat</code> parameter</p></li></ul></li><li><p>Protocol Updates</p><ul><li><p>Peer storage graduates from experimental to default feature while bringing performance improvements</p></li><li><p>Splicing interoperability with Eclair and splice RBF capability</p></li></ul></li></ul></li><li><p>Cashu <a href="https://github.com/cashubtc/nutf/releases/tag/0.17.0">v0.17.0</a></p><ul><li><p>New Features</p><ul><li><p>Blind Authentication</p><ul><li><p>Limit mint access using Clear and Blind Authentication. Nutshell now supports NUT-21 and NUT-22, enabling the use of OAuth 2.0 identity providers like Keycloak (or any compatible provider).</p></li><li><p>NUT-22 introduces Blind Authentication, which enhances user privacy by anonymizing authentication within the set of registered users</p></li></ul></li><li><p>Improved Multi-Nut Payments</p><ul><li><p>Multi-nut payments via LND are now more reliable. Nutshell queries multiple routes before failing, significantly improving payment success rates</p></li></ul></li></ul></li><li><p>Removed Features: The wallet REST API has been removed from the project due to a low utility to maintenance cost ratio</p></li><li><p>Additional Protocol Updates</p><ul><li><p>SIG_ALL Multisig Flag: Users can now lock ecash to specific destinations (outputs)</p></li><li><p>Mint and Melt Quote Enhancements: The update to NUT-04/05 introduces new fields (amount, unit, request) to mint and melt quotes</p></li></ul></li></ul></li><li><p>CDK <a href="https://github.com/cashubtc/cdk/releases/tag/v0.9.2">v0.9.2</a></p><ul><li><p>HTLC from hash support</p></li><li><p>Optional transport and NUT-10 secret on payment request</p></li><li><p>Multi-part payments support in cdk-cli</p></li></ul></li><li><p>Phoenix Wallet <a href="https://github.com/ACINQ/phoenix/releases/tag/android-v2.6.0">v2.6.0</a></p><ul><li><p>Stateless offers with custom description: Phoenix can now generate any number of Bolt12 offers (a.k.a. reusable invoices)</p></li><li><p>Custom feerate in channel closing: It&#8217;s now possible to set a feerate when closing a channel mutually</p></li><li><p>(android) Manual import/export of the payments database: On Android a new export option is available in the Export screen</p></li><li><p>Lightning addresses in contacts: You can now associate a Lightning address to a contact. In fact, a contact can have multiple Lightning addresses or Bolt12 offers attached.</p></li></ul></li><li><p>Zeus <a href="https://github.com/ZeusLN/zeus/releases/tag/v0.11.0-beta2">v0.11.0-beta2</a></p><ul><li><p>Highlights:</p><ul><li><p>Experimental Cashu ecash wallet</p></li><li><p>Swaps: LN -&gt; on-chain, and vice versa</p></li><li><p>Import and export wallet configs</p></li><li><p>UTXO labeling</p></li><li><p>Activity: filter for keysends</p></li><li><p>CLN: support for generating Taproot addresses</p></li><li><p>CLN: view closed channels</p></li></ul></li></ul></li><li><p>LDK <a href="https://github.com/lightningdevkit/rust-lightning/releases/tag/v0.1.4">v0.1.4</a> - &#8220;Careful Validation of Bogus States&#8221;</p><ul><li><p>Security: 0.1.4 fixes a funds-theft vulnerability in exceedingly rare cases</p></li></ul></li><li><p>Breez SDK - Nodeless (Liquid Implementation) <a href="https://github.com/breez/breez-sdk-liquid/releases/tag/0.9.0">v0.9.0</a></p><ul><li><p>Receive via BOLT12 &amp; BIP353</p></li><li><p>Support LNURL-Verify</p></li><li><p>Add on-chain transaction ID when sending to a BTC address</p></li></ul></li><li><p>Misty Breez <a href="https://github.com/breez/misty-breez/releases/tag/v0.1.5">v0.1.5</a> (A hybrid Lightning and Liquid network wallet built with the Nodeless Breez SDK)</p><ul><li><p>Receive via BOLT12 &amp; BIP353</p></li><li><p>Support LNURL-Verify</p></li><li><p>Add on-chain transaction ID when sending to a BTC address</p></li></ul></li><li><p>Alby</p><ul><li><p>Hub <a href="https://github.com/getAlby/hub/releases/tag/v1.17.0">v1.17.0</a> - Sean Hastings</p><ul><li><p>Improve Friends &amp; Family</p></li><li><p>Auto-swaps</p></li><li><p>Sub wallet improvements</p></li><li><p>Verify package signatures in install/update scripts</p></li><li><p>Add onchain transactions to node page</p></li><li><p>Add update banner</p></li><li><p>Add info page to settings</p></li></ul></li><li><p>Go <a href="https://github.com/getAlby/go/releases/tag/v1.13.0">v1.13.0</a></p><ul><li><p>Payments now show more information about recipient, payer and zaps</p></li><li><p>Option to switch wallets in NWA flow</p></li><li><p>Performance improvements and fixes in Send screen</p></li></ul></li><li><p>lightning-browser-extension <a href="https://github.com/getAlby/lightning-browser-extension/releases/tag/v3.12.0">v3.12.0</a> - Herbig-Haro 24</p><ul><li><p>Better onboarding for both master key and Nostr key</p></li><li><p>&#8220;Batteries&#8221; removed from the extension</p></li><li><p>New Wallet Settings menu for easier access and configuration</p></li></ul></li><li><p>js-sdk <a href="https://github.com/getAlby/js-sdk/releases/tag/v5.1.0">v5.1.0</a></p><ul><li><p>feat: add hold invoice NWC methods and notification type</p></li><li><p>chore: add recipient_data to tx metadata</p></li><li><p>chore: add LN paywall esm example</p></li></ul></li></ul></li><li><p>LNbits <a href="https://github.com/lnbits/lnbits/releases/tag/v1.1.0">v1.1.0</a> - Alan Bits</p><ul><li><p>New Features</p><ul><li><p>i18n support for reset password messages</p></li><li><p>Fetch all payments for a user</p></li><li><p>Preimage handling for incoming payments</p></li><li><p>Add verify_preimage utility</p></li><li><p>Superuser setting no longer reset on delete</p></li></ul></li></ul></li><li><p>BlitzWallet <a href="https://github.com/BlitzWallet/BlitzWallet/releases/tag/Android-v0.4.5-beta">v0.4.5-beta</a></p><ul><li><p>Contact payments are now more private:</p><ul><li><p>Previously: One address was stored and rotated weekly</p></li><li><p>Now: 7 addresses are stored, and one is rotated out weekly</p></li><li><p>Payments randomly select one of the 7 addresses to improve privacy</p></li></ul></li><li><p>Add Items to POS Checkout: Admins can now save items and prices directly in their wallet</p></li><li><p>Liquid Payments: Reduce minimum send amount for Liquid transactions to 100 sats</p></li><li><p>Contact Experience:</p><ul><li><p>You can now share someone else&#8217;s contact directly from their profile page</p></li><li><p>Switch currency on contact page</p></li><li><p>Uploaded contact profile images now appear during search</p></li></ul></li></ul></li><li><p>BitBanana <a href="https://github.com/michaelWuensch/BitBanana/releases/tag/v0.9.5">v0.9.5</a></p><ul><li><p>Simplify UTXO consolidation</p></li><li><p>Add extended connection info via connection status indicator</p></li><li><p>Core Lightning: Channel rebalancing feature added</p></li><li><p>Core Lightning: Pick first hop on lightning payments</p></li><li><p>Core Lightning: Reserved UTXOs now displayed as locked</p></li><li><p>Improve compatibility with NWC</p></li><li><p>Log view enhancements: Add sorting and auto-scroll options</p></li><li><p>Add full Polish language support</p></li></ul></li><li><p>Aqua Wallet <a href="https://github.com/AquaWallet/aqua-wallet/releases/tag/v0.3.0">v0.3.0</a></p><ul><li><p>New Features:</p><ul><li><p>The Dolphin Card is here for beta testing</p></li><li><p>New text scanner for addresses using Optical Character Recognition (OCR)</p></li><li><p>Lower minimum peg-out amount from 0.001 to 0.00025 BTC (excluding fee)</p></li><li><p>Reduce minimum amount for sending Liquid Bitcoin to 100 sats</p></li><li><p>Addresses now have colored numbers</p></li><li><p>Improve transaction tracking and fee estimates for BTC to L-BTC swaps</p></li><li><p>Add the USDt swap order ID in the transaction detail page</p></li><li><p>Lightning refunds are now specifically marked in the transaction list</p></li></ul></li></ul></li><li><p>RGB <a href="https://github.com/RGB-WG/rgb/releases/tag/v0.12.0-rc.1.1">v0.12.0-rc.1.1</a></p><ul><li><p>The 0.12 version has brought zk-STARK readiness to the RGB, a huge performance boost, and a lot of simplification and security improvements.</p></li><li><p>The release candidate is for all developers working with RGB, so they can integrate it into their software, having guarantees of consensus and low-level API freeze</p></li><li><p>What&#8217;s new:</p><ul><li><p>The version 0.12 of RGB represents a result of 7 months of protocol re-design, aimed at the following:</p><ul><li><p>Make protocol ready for zk-STARK compression;</p></li><li><p>Simplify the protocol as much as possible, reducing any potential attack surface and helping protocol adoption;</p></li><li><p>Ensure security of the protocol with thorough unit and integration test coverage, including tests for potential attacks;</p></li><li><p>Make protocol fully production-ready by freezing consensus level changes and ensuring robustness and performance.</p></li></ul></li></ul></li></ul></li><li><p>SimLN <a href="https://github.com/bitcoin-dev-project/sim-ln/releases/tag/v0.2.4">v0.2.4</a> - Let BOSSies eat Eclairs (A payment activity generator for the Lightning Network)</p><ul><li><p>Minor release: adds support for running simulations on Eclair nodes, bringing sim-ln&#8217;s implementation support up to 3/4 major implementations.</p></li><li><p>Changes:</p><ul><li><p>Add Eclair node support</p></li><li><p>Add Scorer to SimNode</p></li><li><p>Unit tests for validate_activity and validate_node_network</p></li><li><p>Do not allow defined activity with zero amount</p></li><li><p>Parse address detecting if starts with https</p></li><li><p>Validate channel policy and enforce unique scid</p></li></ul></li></ul></li></ul><h3><strong>Nostr</strong></h3><h4><strong>Project spotlight</strong></h4><ul><li><p>Emptio P2P: A project to allow the purchase and sale of bitcoin p2p in a decentralized way through nostr [<a href="https://github.com/misesdev/emptio">Github</a>]</p><ul><li><p>The application integrates with mempool.space for Bitcoin network transactions and wallet data display</p></li></ul></li><li><p>TENEX: A context-first development tool built on Nostr [<a href="https://github.com/pablof7z/tenex">Github</a>] (A project by Pablof7z)</p><ul><li><p>TENEX stores projects and tasks as nostr events, with each project receiving its own nsec key.</p></li><li><p>It features context-first development, voice-to-code transcription, AI-powered orchestration with specialized modes, intelligent task management, project-specific nsec keys, real-time collaboration via Nostr, multi-column interface, extensible architecture, and smart context awareness.</p></li></ul></li><li><p>Compass: An ansible configuration for setting up an indexer relay [<a href="https://github.com/coracle-social/compass">Github</a>] (A project by Coracle)</p><ul><li><p>Ansible playbook to deploy a strfry nostr relay tailored to indexing kind 10002.</p></li></ul></li><li><p>Publsp: A command-line tool that enables LN nodes and LSPs to advertise their liquidity offers through Nostr using kind 39735 events [<a href="https://github.com/smallworlnd/publsp">Github</a>]</p><ul><li><p>LSPs advertise liquidity as addressable Kind 39735 events. Customers just pull and evaluate all those structured events, then NIP-17 DM an LSP of their choice to coordinate a liquidity purchase.</p></li></ul></li><li><p><a href="https://liquiditystr.space/">liquiditystr</a>: A gateway to the Nostr P2P Lightning liquidity marketplace [<a href="https://github.com/smallworlnd/liquiditystr">Github</a>]</p><ul><li><p>A single-page app that plugs into the customer-side publsp API to provide streamlined access to LSPs that advertise liquidity through Nostr</p></li></ul></li><li><p>js-eventstore-benchmark: Browser benchmarks comparing different methods for storing Nostr events in the browser [<a href="https://github.com/fiatjaf/js-eventstore-benchmark">Github</a>] (A tool by fiatjaf)</p></li><li><p>Nostratui: A terminal user interface (TUI) for browsing Nostr posts, written in Rust [<a href="https://github.com/adamm-xyz/nostratui">Github</a>]</p><ul><li><p>Nostratui is a minimalist, responsive, and highly efficient terminal client for the nostr protocol</p></li></ul></li><li><p><a href="https://nostrnips.com/">NIPs on Nostr</a>: A website for viewing official Nostr Implementation Possibilities (NIPs) and publishing custom NIPs on the Nostr network [<a href="https://gitlab.com/soapbox-pub/nostrnips">Gitlab</a>]</p></li><li><p><a href="https://shosho.live/">Shosho</a>: A mobile app that enables live streaming over RTMP with Nostr integration, similar to Facebook Live but built on the Nostr protocol [<a href="https://github.com/r0d8lsh0p/shosho-releases">Github</a>]</p><ul><li><p>Features:</p><ul><li><p>RTMP Broadcasting: High-quality live video streaming</p></li><li><p>Nostr Integration: Use your Nostr npub, announce your stream live on Nostr clients like Zap.stream and Amethyst</p></li><li><p>Live Chat: See your mentions and stream chat live and respond in the app</p></li><li><p>Zap Integration: Receive zaps from your viewers and get paid to stream</p></li></ul></li></ul></li><li><p><a href="https://yakbak.app/">YakBak</a>: Voice message social platform [<a href="https://github.com/derekross/yakbak">Github</a>]</p><ul><li><p>YakBak is a modern social platform built on the Nostr protocol that allows users to share and interact with voice messages</p></li><li><p>Features:</p><ul><li><p>Voice message recording and playback</p></li><li><p>Threaded voice message conversations</p></li><li><p>Lightning Network zaps for voice messages</p></li><li><p>Reactions and engagement tracking</p></li><li><p>Nostr protocol integration</p></li></ul></li></ul></li></ul><h4><strong>Software Releases &amp; Project Updates</strong></h4><ul><li><p>rust-nostr</p><ul><li><p><a href="https://github.com/rust-nostr/nostr/blob/master/CHANGELOG.md#v0421---20250526">v0.42.1</a></p><ul><li><p>nostr: add detailed error handling for NIP-47 response deserialization</p></li></ul></li><li><p><a href="https://github.com/rust-nostr/nostr/blob/master/CHANGELOG.md#v0420---20250520">v0.42.0</a></p><ul><li><p>Breaking changes</p><ul><li><p>nostr: rework nip46 module</p></li><li><p>pool: drop support for deprecated negentropy protocol</p></li><li><p>connect: encrypt NIP-46 events with NIP-44 instead of NIP-04</p></li><li><p>connect: drop support for NIP-46 event decryption with NIP-04</p></li></ul></li><li><p>Added</p><ul><li><p>nostr: add <code>UnsignedEvent::id</code> method</p></li><li><p>nostr: add <code>TagKind::single_letter</code> constructor</p></li><li><p>nostr: add NIP-73 blockchain address and transaction</p></li><li><p>blossom: add new crate with Blossom support</p></li><li><p>mls-storage: add new crate with traits and types for mls storage implementations</p></li><li><p>mls-memory-storage: add an in-memory implementation for MLS</p></li><li><p>mls-sqlite-storage: a sqlite implementation for MLS</p></li><li><p>mls: add new crate for implementing MLS messaging</p></li><li><p>pool: add relay monitor</p></li><li><p>sdk: add <code>Options::pool</code></p></li><li><p>relay-builder: add support for NIP-70 protected events</p></li></ul></li></ul></li></ul></li><li><p>Primal</p><ul><li><p><a href="https://github.com/PrimalHQ/primal-android-app/releases/tag/2.2.20">v2.2.20</a></p><ul><li><p>Implement Redeem Code functionality</p></li><li><p>Implement notes image gallery per latest design</p></li><li><p>Implement loading and error states in ThreadScreen</p></li><li><p>Add support for parsing BUD-08 upload responses</p></li></ul></li><li><p>Implement <a href="https://primal.net/myarticles">Primal Article Editor</a>, a long form note editor interopable with other Nostr long form apps like Highlighter, Habla and Yakihonne.</p></li></ul></li><li><p>Damus <a href="https://github.com/damus-io/damus/commit/580fa954b2d7bc4a5f18b14c8c784a0dd5f0aaa4">v1.14</a></p><ul><li><p>Add safety reminder to wallets with higher balance</p></li><li><p>Add one-click Coinos wallet setup</p></li><li><p>Add notification setting to hide hellthreads</p></li><li><p>Add separated first aid option for relay lists that does not need a contact list reset</p></li><li><p>Add NIP-65 relay list support</p></li><li><p>Add Unicode 16 emoji reactions for iOS 18.4+ by upgrading EmojiPicker</p></li><li><p>Add a search interface to the settings screen</p></li><li><p>Add view introducing users to Zaps</p></li><li><p>Add new wallet view with balance and transactions list</p></li><li><p>Add copy technical info button to user visible errors, so that users can more easily share errors with developers</p></li><li><p>Add dismiss button to wallet high balance reminders</p></li><li><p>Zap receiver information now included for outgoing zaps</p></li><li><p>Add inline note rendering of invoices to pull up wallet selector sheet</p></li><li><p>Add route to profile page from wallet tx list</p></li></ul></li><li><p>Coracle <a href="https://github.com/coracle-social/coracle/releases/tag/0.6.17">v0.6.17</a></p><ul><li><p>Show web of trust badge on DM items</p></li><li><p>Make name on messages clickable</p></li><li><p>Reduce duplicate dependencies</p></li><li><p>Add relays to note options form</p></li></ul></li><li><p>Zap.stream <a href="https://njump.me/nevent1qvzqqqqqqypzqcl7vvvdckzc8nlpdqg0smwsncvtl4m240py5qypec59dues2p8dqqsrz9gw66sknfukttur2hmlrgtuvwg22wfkmt2fkmmfv5tvdly4jccltsqyc">v0.8.0</a></p><ul><li><p>Add translations for 30 languages</p></li><li><p>Add deep linking for all zap.stream links</p></li><li><p>Add push notifications</p></li></ul></li><li><p>Futr <a href="https://github.com/futrnostr/futr/releases/tag/v0.3.0">v0.3.0</a></p><ul><li><p>Rich Media Support</p><ul><li><p>Image display and viewer: Images from URLs now display directly in posts with a dedicated image viewer</p></li><li><p>Video player with fullscreen support: Embedded video player with play/pause controls, progress bar, and fullscreen mode</p></li><li><p>Download images and videos: Save any image or video directly to your computer with a single click</p></li><li><p>Video controls: Full video playback controls including time display and seeking</p></li></ul></li><li><p>Enhanced Social Features</p><ul><li><p>Comments &amp; Conversations</p><ul><li><p>Nested comment threads: Comment on posts with full threaded conversation support</p></li><li><p>Comment trees: Visual indentation shows conversation hierarchy and reply relationships</p></li></ul></li><li><p>Reposts &amp; References</p><ul><li><p>Referenced post display: Reposts and quote reposts now show the original post content inline</p></li><li><p>Nested post references: Support for complex post reference chains</p></li><li><p>Quote repost support: Create and view quote reposts with your commentary</p></li></ul></li><li><p>Profile Integration</p><ul><li><p>Smart profile rendering: npub addresses automatically display as profile names and pictures</p></li><li><p>Clickable profile links: Click any profile reference to view that user&#8217;s feed</p></li><li><p>Profile pictures everywhere: User avatars displayed consistently across the app</p></li></ul></li></ul></li><li><p>User Experience Improvements</p><ul><li><p>Navigation &amp; Interface</p><ul><li><p>Improved scrolling: Smooth scrolling behavior across all feeds and chats</p></li><li><p>Collapsible sidebar: More screen space when you need it</p></li><li><p>Auto-scroll intelligence: Feeds automatically scroll to new content when appropriate</p></li></ul></li><li><p>Chat &amp; Messaging</p><ul><li><p>Message anyone: Send private messages without requiring a follow relationship</p></li><li><p>Better chat interface: Improved message display and input handling</p></li><li><p>Enhanced scroll behavior: Smooth chat scrolling that remembers your position</p></li></ul></li><li><p>Cross-Platform Support</p><ul><li><p>Windows support: Full Windows compatibility with native installer</p></li><li><p>Better performance: Reduced memory usage and faster loading</p></li><li><p>Improved reliability: Better connection handling and error recovery</p></li></ul></li></ul></li></ul></li><li><p>Nostr-PHP <a href="https://github.com/nostrver-se/nostr-php/releases/tag/1.8.0">v1.8.0</a></p><ul><li><p>feat: Implement NIP-05 lookups</p></li><li><p>Add extra metadata fields for profile</p></li><li><p>Finish implementing methods Relay and RelaySet</p></li><li><p>Implement NIP-17 Private Direct Messages</p></li><li><p>NIP 44 implementation fix and test improvements</p></li><li><p>Remove CLI tool from library</p></li></ul></li><li><p>Keychat <a href="https://github.com/keychat-io/keychat-app/releases/tag/1.32.6">v1.32.6</a></p><ul><li><p>[Ecash] Updated Keychat_rust_ffi library. Supports paid mint servers</p></li><li><p>[Ecash] Added mint information page</p></li><li><p>[Ecash] Added fee for Ecash billing</p></li><li><p>[Browser] Enabled viewing of image URLs in WebView</p></li><li><p>[Browser] Enabled PDF viewing on desktop</p></li><li><p>Redesign the login page</p></li></ul></li><li><p>Yumyume <a href="https://gitlab.com/digitalethicsagency/nostr/yumyume/-/tags/0.7.0">v0.7.0</a> - Mezze Platter with Labneh, Olives &amp; Spiced Lamb</p><ul><li><p>Version 0.7.0 brings together bookmark insights, URL context, smarter tagging, and improved flows for new users</p></li><li><p>Features:</p><ul><li><p>Bookmark detail page: Click on a timestamp to open the new bookmark detail page</p></li><li><p>URL detail page: Click the info icon in the feed or bookmark detail to open a dedicated page for the URL</p></li><li><p>Update Bookmarklet to Kind 39701</p></li><li><p>Nstart integration: &#8220;Create a Profile&#8221; button now supports dynamic return URLs</p></li><li><p>Tags feed: Popular tags now only reflect the last 30 days</p></li></ul></li></ul></li><li><p>Nostur <a href="https://github.com/nostur-com/nostur-ios-public/releases/tag/1.21.0">v1.21.0</a></p><ul><li><p>Support Follow Packs</p></li><li><p>Support Blossom servers (uploading and mirroring)</p></li><li><p>Post Preview for Picture-only posts</p></li><li><p>Audio-only bar</p></li><li><p>Drag unread counter anywhere, tap to go to next unread post</p></li><li><p>Show media info in iOS Now Playing control center</p></li></ul></li><li><p>0xChat App <a href="https://github.com/0xchat-app/0xchat-app-main/releases/tag/v1.4.10-release">v1.4.10</a></p><ul><li><p>Add support for creating MLS private groups</p></li></ul></li><li><p>Samiz <a href="https://github.com/KoalaSat/samiz/releases/tag/v0.0.5-alpha">v0.0.5-alpha</a> (BLE mesh for nostr notes when the internet is down)</p><ul><li><p>Add Logs view</p></li><li><p>Add Help view</p></li></ul></li><li><p>Runstr <a href="https://github.com/HealthNoteLabs/Runstr/releases/tag/new-features-0.4.5-20250530-135132">v0.4.7</a> - Bug Squashing &#128027;</p><ul><li><p>Step tracking: Improve step tracking and pedometer precision</p></li><li><p>Nostr &amp; Privacy:</p><ul><li><p>NIP-101h: Choose what fitness details to share on Nostr (intensity, cadence, heart rate)</p></li><li><p>Remove fallback to public relays when using private relays for NIP-101h and NIP-101e events</p></li></ul></li><li><p>Rewards System: Improve payouts reliability</p></li><li><p>UI &amp; OS: GrapheneOS: Enhance location tracking with better permission handling and updated manifest requirements</p></li><li><p>Countdown Controls: &#8220;Skip Start Countdown&#8221; Check Box</p></li></ul></li><li><p>Pokey <a href="https://github.com/KoalaSat/pokey/releases/tag/v0.2.1-beta">v0.2.1-beta</a></p><ul><li><p>Subscription feature: Additionally listen to all notes published by an NPUB, all notes under an NEVENT or any note including a specific #HASHTAG. Notes are fetched in user&#8217;s inbox relays.</p></li><li><p>If the note contains an image URL, it now displays</p></li></ul></li><li><p>TollGate (Enables WiFi routers to accept Bitcoin payments for internet access)</p><ul><li><p><a href="https://github.com/OpenTollGate/tollgate-os/releases/tag/v0.0.3">v0.0.3</a></p><ul><li><p>The router now automatically pays out accumulated funds to Lightning addresses</p></li><li><p>Add support for splitting payments between multiple Lightning addresses</p></li><li><p>Enhance configuration options for mints with more detailed settings for balance management and payout preferences</p></li></ul></li><li><p><a href="https://github.com/OpenTollGate/tollgate-os/releases/tag/v0.0.2">v0.0.2</a></p><ul><li><p>Streamline build process with new GitHub Actions workflows, making it easier to create and publish releases</p></li><li><p>Enhance configuration management system, allowing for more flexible and robust setup options</p></li><li><p>The system now randomizes the LAN IP address on first boot</p></li><li><p>Update first boot script to configure the network settings more effectively, including setting DNS servers to CloudFlare DNS</p></li><li><p>Introduce new release.json file to manage module versions and dependencies</p></li><li><p>Add package management files (packages_dev.json and packages_stable.json) to define external and custom packages for the OS</p></li></ul></li></ul></li></ul><h3><strong>Boosts</strong></h3><ul><li><p>01:07:13 Thanks to everyone who streamed sats, and shoutout to our top boosters:</p><ul><li><p>[&#127942; TOP BOOSTER] @AVERAGE_GARY (10,200 sats) &#8220;libbitcoinkernel maximalism&#8221; &#8220;That&#8217;s OSMU taking the bitaxe donations. Need more manufacturing implementations. Just like Core&#8221;</p></li><li><p>@hgw39 (10,000 sats) &#8220;As NVK said, we have the option to not update and run an older version. But Core encourage us to update to more recent versions for security. <strong>This sounds reasonable to me so what are the security ramifications if you run an older version?</strong> <strong>Also, could you explain more about the Lebitcoin kernel project Craig was talking about.</strong> That sounds interesting. Thanks.&#8221;</p></li><li><p>@Rod Palmer (5,000 sats) &#8220;scolding people who don&#8217;t run nodes wasn&#8217;t effective. telling people that running a specific flavor of node will make people they don&#8217;t like extremely mad may just work&#8221;</p></li><li><p>@Chris (5,000 sats) &#8220;Would still love the ability to export a Secure Note encrypted with bip85 entropy that can be decrypted at any point in the future by a coldcard running the same seed/passphrase combo. A stacker news <a href="https://stacker.news/items/853095">poll</a> showed over 50% of users would be interested in this feature.&#8221;</p></li><li><p>@Hech (1,000 sats) &#8220;Great episode&#8221;</p></li><li><p>@Bob the Cow (500 sats) &#8220;Mooooo&#8221;</p></li><li><p>@Plunger (343 sats) &#8220;Great panel, informative show.&#8221;</p></li><li><p>@Homer Hodl (120 sats) &#8220;For the block clock refresh.. <strong>how about the ability to set a threshold to update the display quicker than the default if the new value exceeds the adjustable threshold?</strong>&#8221;</p></li></ul></li></ul><h3><strong>Tech Tip of the Day</strong></h3><ul><li><p>Signallama: Signal bot to chat with your ollama instance [<a href="https://github.com/aljazceru/signallama">Github</a>]</p><ul><li><p>Signallama enables users to interact with LLMs via the Signal messaging platform</p></li><li><p>It primarily supports Ollama but is compatible with various LLM providers through LiteLLM</p></li></ul></li></ul><h3><strong>Bitcoin Optech Newsletter</strong></h3><ul><li><p>Highlights from recent Bitcoin Optech Newsletters</p><ul><li><p><a href="https://bitcoinops.org/en/newsletters/2025/05/30/">356</a></p><ul><li><p>Do attributable failures reduce LN privacy? Carla Kirk-Cohen <a href="https://delvingbitcoin.org/t/latency-and-privacy-in-lightning/1723">posted</a> to Delving Bitcoin an analysis of the possible consequences for the privacy of LN spenders and receivers if the network adopts attributable failures, particularly telling the spender the amount of time it took to forward a payment at each hop.</p></li></ul></li><li><p><a href="https://bitcoinops.org/en/newsletters/2025/05/16/">354</a></p><ul><li><p>Vulnerability disclosure affecting old versions of Bitcoin Core: Antoine Poinsot <a href="https://mailing-list.bitcoindevs.xyz/bitcoindev/EYvwAFPNEfsQ8cVwiK-8v6ovJU43Vy-ylARiDQ_1XBXAgg_ZqWIpB6m51fAIRtI-rfTmMGvGLrOe5Utl5y9uaHySELpya2ojC7yGsXnP90s=@protonmail.com/">posted</a> to the Bitcoin-Dev mailing list to announce a vulnerability affecting Bitcoin Core versions before 29.0.</p><ul><li><p>An attacker could send an excessive number of node address advertisements to force a 32-bit identifier to overflow, resulting in a node crash.</p></li></ul></li></ul></li></ul></li></ul><h3><strong>News &amp; Noteworthy</strong></h3><h4><strong>Bitcoin</strong></h4><ul><li><p>Soft-fork proposal: Dust Expiry: Clean the UTXO set from spam [<a href="https://delvingbitcoin.org/t/dust-expiry-clean-the-utxo-set-from-spam/1707/1">Delving Bitcoin</a>]</p><ul><li><p>Dust Expiry is a soft-fork proposal that prunes low-value, inactive UTXOs from the set unless the owner provides proof or pays an ongoing cost, effectively removing spam from those unwilling to maintain it.</p></li></ul></li><li><p>BIP39 Extension for Manual Seed Phrase Creation [<a href="https://gnusha.org/pi/bitcoindev/a139ee2e-473c-487b-a9b0-e68013fdb7cen@googlegroups.com/">Bitcoin Dev discussion</a>]</p><ul><li><p>The proposal uses every eighth word from existing wordlists to create 16-word phrases with 128 bits of entropy.</p></li><li><p>The system encodes derivation paths in the least significant three bits of each word, allowing for specification of up to seven different paths or 48 bits of metadata.</p></li></ul></li></ul><h4><strong>Lightning + L2+</strong></h4><ul><li><p>Wallet of Satoshi teases the upcoming launch of a fully non-custodial Lightning wallet in the U.S. market [<a href="https://x.com/walletofsatoshi/status/1923875750165479768">Twitter post</a>]</p><ul><li><p>WoS ceased its operations in the U.S. in November 2023.</p></li></ul></li></ul><h4><strong>Business &amp; Finance</strong></h4><ul><li><p>Block Inc. announces bitcoin payment integration for Square merchants, reaching all eligible sellers by 2026 [<a href="https://block.xyz/inside/block-to-roll-out-bitcoin-payments-on-square">Announcement</a>]</p><ul><li><p>Follow-up: Block reveals their LN routing node generates 9.7% annual returns with 184 BTC capacity [<a href="https://atlas21.com/lightning-routing-yields-10-annually-blocks-announcement/">Atlas21</a>]</p></li></ul></li><li><p>Breez and Spark announce a new implementation of the Breez SDK built on Spark&#8217;s Bitcoin-native Layer 2 infrastructure, enabling developers to integrate self-custodial Lightning payments into apps [<a href="https://blog.breez.technology/breez-spark-a-new-way-to-build-on-bitcoin-5abc3fb515cb">Announcement</a>]</p><ul><li><p>The implementation provides support for all major programming languages, LNURL, Lightning addresses, and mobile notifications without relying on bridges or external consensus.</p></li></ul></li><li><p>Ledn announces a strategic shift to focus solely on bitcoin-backed lending, effective July 1, 2025, as 95% of their loan clients currently use bitcoin as collateral [<a href="https://www.ledn.io/post/bitcoin-future">Announcement</a>]</p></li><li><p>Casa app now allows users to connect bank accounts and buy bitcoin directly through its Zero Hash partnership, supporting ACH and wire transfers [<a href="https://blog.casa.io/buy-and-sell-bitcoin-with-casa/">Announcement</a>]</p></li><li><p>GameStop Corp. announces the purchase of 4,710 bitcoin [<a href="https://investor.gamestop.com/news-releases/news-details/2025/GameStop-Announces-Purchase-of-Bitcoin/default.aspx">Press release</a>]</p></li></ul><h4><strong>Funding</strong></h4><ul><li><p>OpenSats announces its <a href="https://opensats.org/blog/elevent-wave-of-bitcoin-grants">Eleventh Wave of Bitcoin Grants</a> to &#8220;support a diverse set of contributors advancing Bitcoin&#8217;s infrastructure, tooling, and accessibility.&#8221;</p><ul><li><p>Three first-time projects have been choosen: BitShoka, Great Script Restoration, and 256 Foundation; alongside three renewed project grants for Payjoin, Mostro, and P2Pool v2.</p></li></ul></li><li><p>Btrust <a href="https://blog.btrust.tech/introducing-the-btrust-2025-event-and-education-grants/">awards</a> a total of $1,004,010 to 10 grant recipients, including four for developer education, two for events, and four for conferences:</p><ul><li><p>Summer of Bitcoin, Vinteum, Bitshala, Librer&#237;a de Satoshi&#8217;s B4OS, Adopting Bitcoin Cape Town 2025, Bitcoin++ Florianopolis 2025, Dakar Bitcoin Days 2025, Africa Bitcoin Conference 2025, Africa Free Routing Lightning Bootcamps, and Base58&#8217;s LARP Tutor Session in Mauritius.</p></li></ul></li><li><p>The Human Rights Foundation announces a 8 BTC donation to 22 projects and individuals working on Bitcoin and freedom tech [<a href="https://bitcoinmagazine.com/news/human-rights-foundation-donates-800-million-satoshis-to-22-worldwide-bitcoin-and-freedom-projects">Bitcoin Magazine</a>]</p><ul><li><p>The recipients are: Mostro, SudaBit, Stringer News, Prices Today, Instamouse, Seedsigner, Spacebear, Padawan Wallet, Brink, Coin Center, Bitcoin Design Foundation, EmberOne, 2025 FROST Developer Support, Ecash UX Improvement Project, Summer of Bitcoin, Entropy, Evento, Brandon Odiwuor, Satoshi Sister Circle, Bitcoin Month, Bitcoin Pidgin &amp; Bitcoin Anambra, and Bitcoin Boma.</p></li></ul></li><li><p>Bitcoin educational project My First Bitcoin receives a $1 million grant from #startsmall initiative [<a href="https://myfirstbitcoin.io/my-first-bitcoin-receives-1-million-grant-from-startsmall-to-advance-independent-bitcoin-education-around-the-world/">Press release</a>]</p></li><li><p>Maelstrom Fund announces a $100,000 open source developer year-long grant to Ben Allen for his work on the Payjoin Dev Kit [<a href="https://cointelegraph.com/news/bitcoin-payjoin-privacy-grant-maelstrom">Coin Telegraph</a>]</p></li></ul><h4><strong>Bounty</strong></h4><ul><li><p><a href="https://skibidi.cash/">Skibidi Wallet Bounty</a>: A bounty to build the first brainrot Bitcoin wallet for Gen Z and Gen Alpha</p><ul><li><p>Skibidi Cash announces a $6,500 bounty for developing a mobile-first, self-custodial Bitcoin wallet targeting Gen Z and Gen Alpha.</p></li><li><p>The wallet must feature a brutalist/meme/brainrot user experience, be open-source under the MIT license, and operate on mainnet.</p></li></ul></li></ul><h4><strong>Mining</strong></h4><ul><li><p>Bitlayer Labs partners with Antpool, F2Pool, and SpiderPool for BitVM bridge implementation [<a href="https://x.com/BitlayerLabs/status/1927187546448036216">Announcement</a>]</p><ul><li><p>Mining partners (which together represent nearly 40% of Bitcoin&#8217;s global hashrate) will provide interfaces accepting non-standard transactions.</p></li></ul></li></ul><h4><strong>Privacy</strong></h4><ul><li><p>Telegram sees sharp rise in user data sharing with authorities in Q1 2025 [<a href="https://archive.ph/E2jBE">404 Media</a>]</p><ul><li><p>Telegram provided data on 22,777 users to authorities in Q1 2025, a significant increase from 5,826 users in the same period of 2024.</p></li><li><p><a href="https://te-k.github.io/telegram-transparency/">Telegram Transparency Data</a>: A webpage of crowdsourced data on Telegram transparency, displaying how many requests were accepted by Telegram and where [<a href="https://github.com/Te-k/telegram-transparency">Github</a>]</p></li></ul></li></ul><h4><strong>Quantum</strong></h4><ul><li><p>How to factor 2048 bit RSA integers with less than a million noisy qubits [<a href="https://www.arxiv.org/abs/2505.15917#">ArXiv Research paper</a>]</p><ul><li><p>A new research reduces qubit requirements for factoring 2048-bit RSA integers from 20 million to less than a million, though increasing runtime from eight hours to less than a week.</p></li><li><p>The research maintains consistent assumptions about quantum hardware capabilities, including 0.1% gate error rate and specific timing parameters for surface code cycles.</p></li></ul></li></ul><h4><strong>Bitcoin Security Incidents</strong></h4><ul><li><p>Attempted kidnapping of Bitcoin exchange executive&#8217;s daughter in Paris, France [<a href="https://www.lemonde.fr/en/france/article/2025/05/16/french-crypto-boss-hails-heroic-duo-who-foiled-kidnap-attempt-on-his-family_6741350_7.html">Le Monde</a>]</p><ul><li><p>Four masked men attempt to kidnap the daughter of Paymium cryptocurrency exchange CEO and co-founder in Paris&#8217; 11th district.</p></li></ul></li><li><p>French police thwarts multiple kidnapping attempts targeting cryptocurrency entrepreneurs and their families [<a href="https://www.bfmtv.com/police-justice/cryptomonnaies-tentative-d-enlevement-commando-arrete-ce-que-l-on-sait-des-nouvelles-interpellations_AN-202505270839.html">BFM TV</a>]</p><ul><li><p>Ten suspects were arrested Monday in Nantes just before attempting to abduct someone linked to cryptocurrencies.</p></li><li><p>Police conducted a second raid Tuesday, arresting the commando responsible for a May 13 kidnapping attempt in Paris&#8217;s 11th district.</p></li></ul></li><li><p>Crypto investor arrested for torturing Italian businessman in NYC, U.S. extortion plot [<a href="https://www.coindesk.com/policy/2025/05/26/u-s-crypto-investor-charged-with-kidnapping-and-torturing-victim-over-bitcoin">CoinDesk</a>]</p><ul><li><p>John Woeltz is charged with kidnapping and assaulting a 28-year-old Italian businessman in a luxury SoHo apartment, attempting to extort cryptocurrency passwords through torture with electric shocks, drugs, and chainsaw threats.</p></li><li><p>The victim, held captive for two weeks, escaped on Friday 23rd May believing he would be killed.</p></li></ul></li><li><p>Man kidnapped in Sofia, Bulgaria for 14 bitcoin by fake police officers on October 7, 2024 [<a href="https://btvnovinite.bg/bulgaria/otvlichane-ot-mnimi-policai-za-14-bitkojna-razkaz-na-sluzhitel-na-sdvr-samo-pred-btv.html">BTV Novinite</a>]</p><ul><li><p>A 35-year-old man is kidnapped on October 7 by individuals posing as police officers in Lyulin district. The victim is threatened with a gun and forced to transfer 14 bitcoin.</p></li><li><p>Searches reveal fake police credentials, a CDCOC badge, an airsoft pistol, and a blue police lamp</p></li></ul></li><li><p>U.S. tourist loses $123K in crypto after being drugged by fake Uber driver in London, UK following a night out [<a href="https://decrypt.co/321243/us-tourist-bitcoin-xrp-123k-stolen-ride-fake-uber-london">Decrypt</a>]</p><ul><li><p>The driver offers a cigarette believed to contain scopolamine, causing the victim to unwittingly reveal his phone passcode, which allowed the attacker to access his Revolut account, stealing $72k in XRP tokens and $50k in bitcoin.</p></li></ul></li><li><p>Russian entrepreneurs running a cryptocurrency business kidnapped in Palermo, Argentina [<a href="https://archive.is/2EHz4">TN</a>]</p><ul><li><p>The victims, found tied up by police, paid a $43,000 cryptocurrency ransom through a friend. The suspects flee Argentina to the United Arab Emirates and are now subject to an Interpol red alert.</p></li></ul></li><li><p>South Korean police arrest a Russian suspect following an attempted $730,000 crypto robbery at a Seoul hotel [<a href="https://archive.is/2kDp5">CoinTelegraph</a>]</p><ul><li><p>Two other suspects fled the country before authorities could prevent their departure.</p></li><li><p>The three Russians posed as crypto traders, luring 10 Korean investors to a hotel room where they ambushed victims with replica weapons and cable ties. One victim escaped, alerting police and causing the suspects to flee empty-handed.</p></li></ul></li><li><p>Ugandan crypto founder abducted and robbed of $500,000 by armed men impersonating military officers [<a href="https://archive.is/UfCv4">Decrypt</a>]</p><ul><li><p>Attackers forced him to transfer half a million USD in cryptocurrency and sell portions of his holdings under duress.</p></li><li><p>The victim&#8217;s company reports this incident as part of a larger trend, claiming over 48 similar crypto-related attacks have occurred in Uganda.</p></li></ul></li><li><p>Three Chinese nationals are expelled from Paraguay after an attempted assault on a crypto-mining company that led to a police chase and shooting [<a href="https://archive.is/rm7nw">Monumental</a>]</p><ul><li><p>The prosecutor confirmed the foreigners entered Paraguay illegally through Bolivia and Brazil, stating that &#8220;They came as programmers to work at the company&#8221;.</p></li></ul></li></ul><h4><strong>Protocol</strong></h4><ul><li><p>Bitcoin Core #31622: psbt: add non-default sighash types to PSBTs and unify sighash type match checking [<a href="https://github.com/bitcoin/bitcoin/pull/31622">Merged</a>]</p></li><li><p>Bitcoin Core #32155: miner: timelock the coinbase to the mined block&#8217;s height [<a href="https://github.com/bitcoin/bitcoin/pull/32155">Merged</a>]</p></li><li><p>Bitcoin Core #31444: cluster mempool: add txgraph diagrams/mining/eviction [<a href="https://github.com/bitcoin/bitcoin/pull/31444">Merged</a>]</p></li><li><p>Core Lightning #8140: Peer storage enable [<a href="https://github.com/ElementsProject/lightning/pull/8140">Merged</a>]</p></li><li><p>Core Lightning #8021: Splice: Interop Final (probably) with Eclair [<a href="https://github.com/ElementsProject/lightning/pull/8021">Merged</a>]</p></li><li><p>Core Lightning #8226: Signmessage: Add a new rpc called signmessagewithkey that can be used to sign messages using any key from our wallet [<a href="https://github.com/ElementsProject/lightning/pull/8226">Merged</a>]</p></li><li><p>LDK #3796: Do not dip into the funder&#8217;s reserve to cover the two anchors [<a href="https://github.com/lightningdevkit/rust-lightning/issues/3796">Merged</a>]</p></li><li><p>NIPs #1919: NIP-79: Passkey-Wrapped Keys a.k.a. Nosskey [<a href="https://github.com/nostr-protocol/nips/pull/1919">Open</a>]</p></li><li><p>NIPs #1934: Add NIP-XX: Static Payment Addresses [<a href="https://github.com/nostr-protocol/nips/pull/1934">Open</a>]</p></li><li><p>NIPs #1923: Create NIP-XX.md: Voice Messages [<a href="https://github.com/nostr-protocol/nips/pull/1923">Open</a>]</p></li></ul><h4><strong>Government &amp; Political</strong></h4><ul><li><p>Bipartisan Blockchain Regulatory Certainty Act reintroduced in U.S. Congress [<a href="https://www.coincenter.org/torres-and-emmer-reintroduce-the-blockchain-regulatory-certainty-act/">Coin Center</a>]</p><ul><li><p>The bill aims to provide clarity for non-custodial crypto infrastructure developers and protect crypto developers from undue regulation and misapplication of licensing laws that have impeded privacy tech development in the U.S.</p></li></ul></li><li><p>UK&#8217;s new strict crypto reporting requirements raise data security concerns [<a href="https://lightning.news/uk-to-require-crypto-report-every-transaction/">Lightning News</a>]</p><ul><li><p>Starting January 2026, UK implements extensive reporting requirements for all crypto firms serving UK customers, requiring collection of personal data and transaction details as part of OECD&#8217;s CARF initiative.</p></li></ul></li><li><p>Pakistan announces creation of government-led Bitcoin Strategic Reserve, allocates 2,000 megawatts of excess energy to mining and establishes a Digital Asset Authority [<a href="https://cointelegraph.com/news/blockchain-explorers-embed-security-insights-to-protect-users-from-onchain-scams">Coin Telegraph</a>]</p></li></ul><h4><strong>Legal</strong></h4><ul><li><p>Samourai Wallet&#8217;s defense releases its <a href="https://storage.courtlistener.com/recap/gov.uscourts.nysd.615997/gov.uscourts.nysd.615997.95.0.pdf">motion to dismiss</a></p></li><li><p>Roman Sterlingov&#8217;s defense requests the DOJ to drop charges, citing Todd Blanche&#8217;s memo against &#8220;victimless cryptocurrency regulatory prosecutions&#8221; [<a href="https://www.therage.co/sterlingov-defense-asks-doj-to-drop-charges-following-blanche-memo/">The Rage</a>]</p><ul><li><p>Defense argues prosecution lacks victims or eyewitnesses, noting &#8220;no victims testified at Mr. Sterlingov&#8217;s trial or sentencing&#8221; and jury was instructed to disregard awareness of illicit activity.</p></li></ul></li><li><p>Roman Storm&#8217;s defense re-petitions court to compel FinCEN communications, claiming government &#8220;misled this Court with regard to the scope of Section 1960 under relevant FinCEN guidance&#8221; [<a href="https://www.therage.co/roman-storm-re-petitions-court-to-compel-fincen-communications/">The Rage</a>]</p><ul><li><p>Motion follows revelations in Samourai Wallet case where FinCEN officials indicated cryptocurrency mixing services without control are &#8220;NOT&#8221; money transmitting businesses, contradicting prosecution&#8217;s arguments.</p></li><li><p><a href="https://www.therage.co/tornado-cash-sdny-abandons-financial-institution-theory/">Follow-up</a>: SDNY abandons the theory that Tornado Cash was a financial institution, dropping unlicensed money transmission charges but continues to pursue charges under the Patriot Act.</p></li><li><p><a href="https://www.therage.co/failla-custody-issue-not-important-to-storms-defense/">Follow-up</a>: Judge Failla rejects Roman Storm&#8217;s defense argument that non-custodial status matters, stating &#8220;You haven&#8217;t persuaded me that the custody issue is as important as you say.&#8221;</p></li></ul></li><li><p>The SEC formally dismisses its lawsuit against Binance and Changpeng Zhao, ending one of the last remaining crypto enforcement actions [<a href="https://www.cnbc.com/2025/05/29/sec-drops-binance-lawsuit-ending-one-of-last-remaining-crypto-actions.html">CNBC</a>]</p><ul><li><p>Binance forges ties with World Liberty Financial, which funnels 75% of profits to Trump family-linked entities and receives a $2 billion investment from MGX.</p></li></ul></li></ul><h4><strong>Events</strong></h4><ul><li><p><a href="https://www.glasgowbitcoin.co.uk/">Scottish Bitcoin Conference</a>: Glasgow is hosting Scotland&#8217;s very own Bitcoin Conference</p><ul><li><p>August 23rd, 2025 in Glasgow, Scotland</p></li></ul></li></ul><h3><strong>Reads</strong></h3><ul><li><p>Here&#8217;s a list of our top recently published reads:</p><ul><li><p>UTXO Set Report, by orangesurf [<a href="https://research.mempool.space/utxo-set-report/">Mempool Research</a>]</p></li><li><p>The 2015 Spam Attacks, by BitMEX Research [<a href="https://blog.bitmex.com/the-2015-spam-attacks/">Blog post</a>]</p></li><li><p>Low Time Preference or Self-Neglect?, by Bitcoin Park [<a href="https://x.com/bitcoinpark_/status/1927022084267331801">Blog post</a>]</p></li><li><p>Seedless is safer, by Jonathan Pollack [<a href="https://bitkey.build/seedless-is-safer/">Bitkey</a>]</p></li><li><p>Nerd of the Month #3: Working on Longevity, by Nick Johnson [<a href="https://spiralbtc.substack.com/p/nerd-of-the-month-3-working-on-longevity">Spiral</a>]</p></li></ul></li></ul><h3><strong>Episode submission ideas</strong></h3><ul><li><p>We&#8217;re looking for ideas for interesting panel conversations. To send Bitcoin related questions, just go to <a href="https://bitcoin.review/">bitcoin.review</a> and follow the contact links at the bottom of the page.</p></li></ul><h3><strong>Get in touch with the pod</strong></h3><ul><li><p><a href="https://twitter.com/bitcoinreviewhq">Podcast Twitter</a></p></li><li><p><a href="https://primal.net/p/npub1qdcakl75gd7wv0nqmmwrz09ddm5tzl7xj8lq2gclng2qzd8up5yqjpzclt">Podcast Nostr</a></p></li><li><p><a href="https://twitter.com/nvk">NVK Twitter</a></p></li><li><p><a href="https://t.me/BitcoinReviewPod">Telegram</a></p></li><li><p><a href="mailto:producer@coinkite.com">Email</a></p></li><li><p>Nostr &amp; LN &#9889;nvk@nvk.org (not an email!)</p></li></ul>]]></content:encoded></item><item><title><![CDATA[BR096 - OP_RETURN Debate, Core Governance, Alternative Implementations, Future Soft Forks, CTV Prospects, Core Vulnerabilities, COLDCARD Hardware Design, Testnet vs Signet + MORE ft. Rob, Odell, Craig]]></title><description><![CDATA[I&#8217;m joined by guests Rob Hamilton, Craig Raw & Matt Odell to go through the list.]]></description><link>https://substack.bitcoin.review/p/br096-op_return-debate-core-governance</link><guid isPermaLink="false">https://substack.bitcoin.review/p/br096-op_return-debate-core-governance</guid><dc:creator><![CDATA[STACK TO THE FUTURE]]></dc:creator><pubDate>Thu, 15 May 2025 17:54:45 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a95ac75-ac77-4167-9383-9930a48690bb_1080x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I&#8217;m joined by guests <a href="https://twitter.com/Rob1Ham">Rob Hamilton</a>, <a href="https://twitter.com/craigraw">Craig Raw</a> &amp; <a href="https://primal.net/odell">Matt Odell</a> to go through the list.</p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://bitcoin.review/podcast/episode-56/&quot;,&quot;text&quot;:&quot;Listen on your favorite podcast app&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://bitcoin.review/podcast/episode-56/"><span>Listen on your favorite podcast app</span></a></p><div><hr></div><h3><strong>Housekeeping</strong></h3><ul><li><p>New Coldcard Q tutorial: How to use the COLDCARD key teleport function on the Coldcard Q [<a href="https://www.youtube.com/watch?v=Bg0r0DQVcDg">YouTube</a>]</p></li></ul><h3><strong>OP_RETURN Drama</strong></h3><ul><li><p>00:00:52 Odell&#8217;s thoughts</p></li><li><p>00:04:29 Craig&#8217;s thoughts</p></li><li><p>00:05:59 NVK&#8217;s thoughts</p></li><li><p>00:07:47 Rob&#8217;s thoughts</p></li></ul><h3><strong>Bitcoin</strong></h3><h4><strong>Software Releases &amp; Project Updates</strong></h4><ul><li><p>00:22:10 COLDCARD</p><ul><li><p>Shared Improvements - Both Mk4 and Q</p><ul><li><p>Enhancement: Text word-wrap done more carefully so never cuts off any text, and yet doesn&#8217;t waste space.</p></li><li><p>Bugfix: Add current tmp option, which could be shown in Seed Vault menu under specific circumstances, would corrupt master settings if selected.</p></li><li><p>Bugfix: PUSHDATA2 in bitcoin script caused yikes.</p></li><li><p>Bugfix: Warning for unknown scripts was not shown at the top of the signing story.</p></li></ul></li><li><p>Mk4 Specific Changes</p><ul><li><p>5.4.3 - 2025-05-14</p><ul><li><p>Bugfix: With both NFC &amp; Virtual Disk OFF, user cannot exit Export Wallet menu. Gets stuck in export loop and needs reboot to escape.</p></li><li><p>Bugfix: Part of extended keys in stories were not always visible.</p></li></ul></li></ul></li><li><p>Q Specific Changes</p><ul><li><p>1.3.3Q - 2025-05-14</p><ul><li><p>Bugfix: Do not allow to teleport PSBTs from SD card when CC has no secrets. Bugfix: Calculator login mode: added &#8220;rand()&#8221; command, removed support for variables/assignments.</p></li></ul></li></ul></li></ul></li><li><p>00:22:21 BDK <a href="https://github.com/bitcoindevkit/bdk/releases/tag/chain-0.22.0">v0.22.0</a> - Release chain</p><ul><li><p>Improve syncing experience for electrum and esplora</p></li><li><p>Relevant transactions that are missing can now be evicted with the help of <code>SyncRequestBuilder</code></p></li><li><p><code>CanonicalizationParams</code> can be used to modify the behavior of <code>CanonicalIter</code> for a given query</p></li><li><p>Update dependency on miniscript to 12.3.1 along with various fixes and improvements</p></li></ul></li><li><p>00:22:35 Cove Wallet <a href="https://github.com/bitcoinppl/cove/releases/tag/v0.4.0">v0.4.0</a></p><ul><li><p>Support for importing hardware wallets with <a href="https://github.com/bitcoin/bips/blob/master/bip-0380.mediawiki#key-expressions">Key Expressions</a>: adds support for using Cove with Krux</p></li><li><p>Create a CSV file of your transactions with fiat values for each transaction at the time of the transaction: useful for tax reporting</p></li><li><p>Send flow improvements and bug fixes</p><ul><li><p>Show proper formatting as you type</p></li><li><p>Default to entering the amount in before the address</p></li></ul></li><li><p>Testnet4 support</p></li></ul></li><li><p>00:24:03 BTCPay Server <a href="https://github.com/btcpayserver/btcpayserver/releases/tag/v2.1.1">v2.1.1</a></p><ul><li><p>Add support for a subset of wallet policy output descriptors (BIP388, BIP389)</p></li><li><p>Add support for hardware wallet taproot signing (BIP86)</p></li><li><p>Enables linking payment requests to external invoices (e.g., QuickBooks, Xero) via a Reference Id</p></li><li><p>Allows searching Payment Requests Reference Id</p></li><li><p>Introduces a webhook triggered when a Payment Request is fully paid, useful for automating emails or other actions</p></li></ul></li><li><p>00:24:06 Nunchuk Android <a href="https://github.com/nunchuk-io/nunchuk-android/releases/tag/android.1.68">v1.68</a></p><ul><li><p>Custom blockchain explorer</p></li><li><p>Ability to archive wallets</p></li><li><p>Ability to long-press &amp; reorder wallets on Home</p></li><li><p>Anti-fee sniping setting</p></li></ul></li><li><p>00:24:12 Bitcoin Keeper <a href="https://github.com/bithyve/bitcoin-keeper/releases/tag/v2.2.0">v2.2.0</a></p><ul><li><p>New Bitcoin Keeper branding</p></li><li><p>New Keeper Private tier</p></li><li><p>Add testnet support</p></li><li><p>Allow using Server Key with multiple users</p></li><li><p>Support import and export of BIP329 labels</p></li></ul></li><li><p>00:24:14 Bitcoin Safe <a href="https://github.com/andreasgriffin/bitcoin-safe/releases/tag/1.3.0">v1.3.0</a></p><ul><li><p>Redesign of Chart, Quick Receive, Icons, and Mempool Preview</p></li><li><p>Interactive chart (clicking jumps to transaction and selected transactions are highlighted)</p></li><li><p>Receive faster (CPFP)</p></li><li><p>BDK 1.2 (upgraded from 0.32)</p></li><li><p>Testnet4 support</p></li><li><p>Preconfigured Testnet demo wallets</p></li></ul></li><li><p>00:24:18 Wasabi Wallet <a href="https://github.com/WalletWasabi/WalletWasabi/releases/tag/v2.6.0">v2.6.0</a> - Prometheus</p><ul><li><p>Support for Standard BIP 158 Block Filters: Wasabi can now synchronize using BIP 158 filters without requiring a backend/indexer</p></li><li><p>Full Node Integration Rework: The previous integration was replaced with a simpler, more flexible system which is not limited to a specific Bitcoin node fork and doesn&#8217;t depend on the node running on the same machine as Wasabi, or require modifications to the node&#8217;s configuration.</p></li><li><p>Create &amp; Recover SLIP 39 Shares: Create and recover wallets with multiple share backups using SLIP 39.</p></li><li><p>Nostr Update Manager: Use the Nostr network to receive update information and download locations instead of relying on GitHub&#8217;s goodwill</p></li><li><p>And more&#8230;</p><ul><li><p>Add a configurable third-party fallback for broadcasting transactions if other methods fail</p></li><li><p>Change Windows Code Signing Certificate, now using Azure Trusted Signing</p></li><li><p>Provide the option to avoid using any third-party Exchange Rate and Fee Rate providers (Wasabi can work without them)</p></li><li><p>Rebuild all JSON Serialization mechanisms avoiding default .NET converters. Serialization is now stricter</p></li></ul></li></ul></li><li><p>00:25:43 RoboSats <a href="https://github.com/RoboSats/robosats/releases/tag/v0.7.7-alpha">v0.7.7</a></p><ul><li><p>For Users</p><ul><li><p>New coordinators view</p></li><li><p>Available coordinator reviews signed by both the robot and the coordinator</p></li><li><p>Coordinators now display in their profiles market price sources</p></li><li><p>Users are now warned if they try to cancel a non taken order after a payment attempt</p></li><li><p>Uzbekistani sum currency now available</p></li></ul></li><li><p>For Coordinators</p><ul><li><p>Library updates</p></li></ul></li></ul></li><li><p>00:25:46 Umbrel <a href="https://github.com/getumbrel/umbrel/releases/tag/1.4.1">v1.4.1</a></p><ul><li><p>File search: Search within the Files UI or from anywhere in umbrelOS with the global &#8984;/Ctrl + K search</p></li><li><p>Files widgets: Two new widgets - Favorites lets you open your pinned favorite folders, and Recents surfaces your recently modified files</p></li><li><p>File transfers: Keep an eye on speed and ETA while copying or moving files in real-time</p></li></ul></li><li><p>00:25:57 Zaprite</p><ul><li><p><a href="https://help.zaprite.com/en/articles/11364054-zaprite-release-notes-2025-05-12">v2025-05-12</a></p><ul><li><p>Taproot: Add Taproot support for our Bitcoin (Wallet) connection</p></li><li><p>Payment Profiles: Add the ability for Customers to manage saved Payment Methods at merchant accounts</p></li></ul></li><li><p><a href="https://help.zaprite.com/en/articles/11154677-zaprite-release-notes-2025-04-28">v2025-04-28</a></p><ul><li><p>Orders Export: add CSV export feature for Orders</p></li><li><p>Unchained SegWit Vaults: add support for Unchained&#8217;s new SegWit vaults</p></li></ul></li></ul></li><li><p>00:26:22 Blockstream Satellite <a href="https://github.com/Blockstream/satellite/blob/master/CHANGELOG.md#251">v2.5.1</a></p><ul><li><p>Added</p><ul><li><p>Installation of gr-dvbs2rx on Debian Bookworm (12)</p></li><li><p>User addition to video group when configuring a TBS USB receiver</p></li></ul></li><li><p>Changed</p><ul><li><p>Telstar 18V C-band downlink frequency</p></li><li><p>Rename blockstream-satellite systemd service to blocksatd</p></li><li><p>Add Lightning invoice payment status to GUI payment dialog</p></li></ul></li></ul></li><li><p>00:26:45 Stratum Work</p><ul><li><p><a href="https://github.com/bboerst/stratum-work/pull/45">PR #45</a>: Add a page that displays full block template data as parsed from the mining.notify message for each pool</p></li><li><p><a href="https://github.com/bboerst/stratum-work/pull/47">PR #47</a>: Add a hover tooltip to coinbase output field so that it&#8217;s easier to see a breakdown of &gt; 0 value outputs</p></li></ul></li><li><p>00:26:58 SeedHammer II</p><ul><li><p>Open sources the hardware design files for the SeedHammer II machine [<a href="https://github.com/seedhammer/hardware">Github</a>]</p></li><li><p>&#8220;This includes the CAD STEP files as well as PCB schematics and layout in KiCad format.&#8221; [[Announcement](https://x.com/SeedHammer/status/1920496724042199121</p></li></ul></li><li><p>00:27:11 ESP-Miner <a href="https://github.com/bitaxeorg/ESP-Miner/releases/tag/v2.7.0">v2.7.0</a></p><ul><li><p>Improve AP mode stability by stopping unnecessary Wi-Fi reconnections</p></li><li><p>PID Fan Control</p></li><li><p>Quicklink service init</p></li><li><p>Remove under power failure</p></li><li><p>Make &#8220;Latest Release&#8221; into a link for the changelog</p></li><li><p>Share reject reasons tooltips</p></li><li><p>Simplify share rejection explanations</p></li><li><p>Track rejection reasons to avoid flickering</p></li><li><p>Set <code>GAMMATURBO_POWER_OFFSET</code> to 10W</p></li><li><p>Add default to supra model</p></li><li><p>Use latest LTS release of Node</p></li></ul></li></ul><h4><strong>Project spotlight</strong></h4><ul><li><p>00:27:34 <a href="https://bitcoinops.org/en/matrix/">Bitcoin Feature Matrix</a>: A tool to track interoperability of Bitcoin products &amp; services</p><ul><li><p>&#8220;Bitcoin Optech&#8217;s new &#8216;Bitcoin Feature Matrix&#8217; is now live in production&#8221;</p></li></ul></li><li><p>00:27:41 secp256k1lab: An INSECURE implementation of the secp256k1 elliptic curve and related cryptographic schemes written in Python, intended for prototyping, experimentation and education [<a href="https://github.com/secp256k1lab/secp256k1lab">Github</a>]</p><ul><li><p>Contributors include Tim Ruffing, Sebastian Falbesoner, and Jonas Nick</p></li><li><p>Features:</p><ul><li><p>Low-level secp256k1 field and group arithmetic</p></li><li><p>Schnorr signing/verification and key generation according to BIP-340</p></li><li><p>ECDH key exchange</p></li></ul></li></ul></li><li><p>00:28:00 GPGap: Air-gapped GPG signing Bitcoin-style [<a href="https://github.com/odudex/gpgap">Github</a>]</p><ul><li><p>A project by Odudex, Krux contributor.</p></li><li><p>GPGap is an experimental Python application that lets you perform GPG signatures on an air-gapped device.</p></li><li><p>It leverages a modified version of PGPy to offload the signing operation to an external hardware signer.</p></li></ul></li><li><p>00:28:16 NVK Validation Tweet: A quick cooked demo response for a Bitcoin (Rust) Script for testing data on Signet [<a href="https://github.com/portlandhodl/nvk-validation-tweet">Github</a>]</p><ul><li><p>In response to <a href="https://x.com/nvk/status/1915213562844242421">NVK&#8217;s Twitter post</a> by @PortlandHODL</p></li><li><p>The script is setup as the following:</p><ul><li><p>Xpub A has 10,000 txns at different block heights</p></li><li><p>Xpub B has 100 utxos made from the 10k above at different block heights</p></li><li><p>Then 20 txns out of xpub B to random addresses at different block heights</p></li><li><p>Ideally all with a good amount of distance in height so its over a few months</p></li><li><p>Don&#8217;t need PSBTs</p></li></ul></li></ul></li><li><p>00:28:54 BriberBrother: An &#8216;alternative mempool&#8217; to help Bitcoin miners identify and include non-standard transactions that follow consensus rules but aren&#8217;t typically relayed through the P2P network [<a href="https://github.com/aoengin/BriberBrother">Github</a>]</p><ul><li><p>&#8220;Briber Brother addresses this challenge by introducing a system that:</p><ul><li><p>Allows miners to efficiently detect and process non-standard transactions.</p></li><li><p>Enables users to provide incentives on another blockchain to encourage miners to include their transactions.</p></li><li><p>Ensures proper verification of incentivized transactions once they are successfully mined.&#8221;</p></li></ul></li></ul></li><li><p>00:29:11 <a href="https://stackmath.xyz/">Stack Math</a>: The Bitcoin Modeling Engine [<a href="https://github.com/gildedpleb/ergodic-drawdown">Github</a>]</p><ul><li><p>Stack Math is an open-source Monte Carlo framework that combines ergodic walk strategies with traditional Bitcoin pricing models to generate probabilistic financial planning scenarios.</p></li></ul></li><li><p>emberOne/00: A 100W open source ASIC Bitcoin mining hashboard [<a href="https://github.com/256-Foundation/emberone00-pcb">Github</a>]</p><ul><li><p>The 256 Foundation releases the KiCAD design files for the emberOne/00 hashboard, a 12-chip modular Bitcoin mining hashboard that consumes only 100 watts of power.</p></li></ul></li><li><p><a href="https://mainnet.observer/">mainnet-observer</a>: Bitcoin Blockchain Statistics [<a href="https://github.com/0xB10C/mainnet-observer">Github</a>] (Hosted by 0xB10C)</p><ul><li><p>This tool and website provides protocol-level statistics and insights about Bitcoin: blocks, transactions, script usage and more. Powered by a Rust backend and Hugo-based frontend.</p></li></ul></li><li><p>NomadBuild: Self-sovereign Bitaxe firmware builder &amp; flasher [<a href="https://github.com/marsmensch/nomadbuild">Github</a>]</p><ul><li><p>NomadBuild provides a tool for Bitaxe users to compile firmware directly from source rather than relying on pre-compiled binaries with trust assumptions.</p></li><li><p>NomadBuild focuses on internally reproducible builds by pinning all dependency versions and controlling build timestamps within its environment.</p></li></ul></li><li><p>00:30:11 HashCommand: An Electron application for controlling Bitcoin miners on your local network, mainly Bitaxes and esp-miner devices [<a href="https://github.com/bitaxeorg/hash-command">Github</a>]</p><ul><li><p>&#8220;It sits between a stratum server and miner, decoding and possibly manipulating traffic. Stratum messages from closed source pools/miners are hidden most of the time, this will let you view both.&#8221; [<a href="https://x.com/Public_Pool_BTC/status/1921736748867940457">Announcement</a>]</p></li></ul></li><li><p>P2Pool v2: Rebooting P2Pool for Bitcoin [<a href="https://github.com/pool2win/p2pool-v2">Github</a>]</p><ul><li><p>Features:</p><ul><li><p>Share chain with uncles: all your work is accounted for</p></li><li><p>Pay large miners in coinbase: non custodial solution for top N miners</p></li><li><p>Support transactions: pay all miners with atomic swaps by market makers</p></li><li><p>Market makers buy shares from smaller miners: earning virgin coins</p></li></ul></li></ul></li><li><p><a href="https://p2p.band/">P2P Band</a>: P2P Bitcoin exchanges decentralized aggregator [<a href="https://github.com/KoalaSat/p2pband">Github</a>]</p></li><li><p><a href="https://bitraffle.sats4.life/">bitRaffle</a>: A trustless and verifiable Bitcoin-based raffle system [<a href="https://github.com/eddieoz/bitRaffle">Github</a>]</p><ul><li><p>bitRaffle is a trustless, automated, Bitcoin-based raffle system that uses Bitcoin&#8217;s blockchain to provide transparent and verifiable raffle drawings that cannot be manipulated.</p></li></ul></li><li><p><a href="https://www.bitcointravel.com/">BitcoinTravel</a>: A bitcoin-only Online Travel Agency, offering flights, hotels, and travel experiences exclusively payable in Bitcoin</p><ul><li><p>Bitcoin Travel operates under dual legal structures: registered in El Salvador as S.A. de C.V. to leverage Bitcoin-friendly regulations, and in the U.S. as Airlines Travel LLC based in Texas for supplier partnerships.</p></li></ul></li><li><p><a href="https://www.bitcoinisforcriminals.com/">Bitcoin is for criminals</a>: A list of case studies of real life examples of the ways criminals have used bitcoin across the globe [<a href="https://github.com/ttooccooll/bitcoinisforcriminals">Github</a>]</p></li></ul><h3><strong>Vulnerability Disclosures</strong></h3><ul><li><p>00:30:23 CVE-2024-52919: Remote crash due to addr message spam (part 2) [<a href="https://bitcoincore.org/en/2025/04/28/disclose-cve-2024-52919/">Disclosure</a>]</p><ul><li><p>The vulnerability allows remote crashes by spamming addr messages until a 32-bit identifier overflows, rated as Low severity.</p></li><li><p>Bitcoin Core v22.0 implemented rate-limiting (1 address per peer every 10 seconds) in 2021, making the attack more expensive but not impossible.</p></li><li><p>The vulnerability is fully addressed in Bitcoin Core v29.0 by changing to a 64-bit identifier, preventing overflow attacks.</p></li></ul></li><li><p>00:33:02 CVE-2025-43707: Critical bug in rust-miniscript library causes transaction signing crashes [<a href="https://antoinep.com/posts/cve-2025-43707/">Blog post</a>]</p><ul><li><p>Bug found by @Pythcoiner from the WizardSardine team, communicated by Antoine Poinsot to rust-miniscript maintainers Andrew Poelstra and Sanket Kanjalkar</p></li><li><p>A vulnerability in rust-miniscript allows attackers to crash applications by crafting special descriptors, potentially creating denial-of-service for server applications.</p></li><li><p>The bug involves an out-of-bounds read in the Satisfaction::thresh() function when threshold k equals the number of sub-fragments.</p></li></ul></li><li><p>Coinos service disruption due to database loss and outage [<a href="https://njump.me/nevent1qqsd2wlx3wq94sqgh66u9hfsevym55mse87efunrc8qpr0syr8mfezqpzemhxue69uhhyetvv9ujucm0d9hx7uewd9hj7q3qh2qfjpnxau9k7ja9qkf50043xfpfy8j5v60xsqryef64y44puwnqxpqqqqqqzxxr7dv">Note</a>]</p><ul><li><p>Coinos is back online but withdrawals remain frozen following complete database loss, with the latest backup being 24 hours old.</p></li><li><p>The service also experienced a 4-hour outage yesterday related to data center internet connection upgrades, though connection to database loss is unclear.</p></li></ul></li><li><p>00:34:46 Hackers breach LockBit ransomware gang&#8217;s dark web affiliate panels, exposing nearly 60,000 bitcoin wallet addresses and 4,400 negotiation messages between attackers and victims [<a href="https://www.forbes.com/sites/daveywinder/2025/05/08/60000-bitcoin-wallets-leaked-as-lockbit-ransomware-hackers-get-hacked/">Forbes</a>]</p><ul><li><p>Database leak includes admin and affiliate actor information with plaintext passwords, though LockBitSupp claims private ransomware keys remain secure.</p></li></ul></li><li><p>Signalgate (continued): TeleMessage&#8217;s modified Signal app exposes Trump officials&#8217; chat logs after <a href="https://www.reutersconnect.com/item/us-national-security-advisor-mike-waltz-attends-a-cabinet-meeting-held-by-president-trump-at-the-white-house-in-washington/dGFnOnJldXRlcnMuY29tLDIwMjU6bmV3c21sX1JDMkg4RUFEOEtGRw%3D%3D">Reuters photo</a> emerges [<a href="https://micahflee.com/despite-misleading-marketing-israeli-company-telemessage-used-by-trump-officials-can-access-plaintext-chat-logs/">Micah Lee&#8217;s Analysis</a>] [<a href="https://www.heise.de/en/news/Signal-affair-Modified-messenger-ceases-operation-after-second-break-in-10372673.html">Heise</a>]</p><ul><li><p>TeleMessage creates TM SGNL, a modified Signal app used by Trump officials that sends plaintext chat logs to their archive server despite claiming E2EE encryption.</p></li><li><p>TM SGNL appears identical to regular Signal but archives every message to destinations like Microsoft 365, email servers, or file servers based on user archive plans. The archive server runs on public AWS cloud in Northern Virginia and was recently hacked.</p></li></ul></li><li><p>AirBorne: Oligo Security discovers 23 vulnerabilities in Apple&#8217;s AirPlay protocol and SDK that enable various attacks including zero-click remote code execution on Apple and third-party devices [<a href="https://www.oligo.security/blog/airborne">Vulnerability analysis</a>]</p><ul><li><p>Two vulnerabilities (CVE-2025-24252 and CVE-2025-24132) allow attackers to create wormable exploits that can spread malware across networks without user interaction, potentially affecting 2.35 billion Apple devices.</p></li><li><p>MacOS devices with AirPlay receiver enabled, CarPlay systems, and third-party speakers are particularly vulnerable to attacks that could enable eavesdropping, tracking, and malware deployment.</p></li><li><p>Apple has released software updates addressing the 17 CVEs issued from Oligo&#8217;s disclosures, following a responsible disclosure process from Oligo.</p></li></ul></li><li><p>LLMs: ANSI terminal codes enable hidden malicious instructions in MCP [<a href="https://blog.trailofbits.com/2025/04/29/deceiving-users-with-ansi-terminal-codes-in-mcp/">Trail of Bits</a>]</p><ul><li><p>Researchers discover ANSI escape sequences can be used to hide malicious payloads in MCP tool descriptions, making them invisible to users while still processed by LLMs</p></li><li><p>Claude Code version 0.2.76 lacks filtering for ANSI codes, allowing attackers to create invisible instructions that could lead to supply chain attacks through manipulated dependencies.</p></li></ul></li><li><p>XRP Ledger SDK compromised in supply chain attack [<a href="https://www.aikido.dev/blog/xrp-supplychain-attack-official-npm-package-infected-with-crypto-stealing-backdoor">Aikido&#8217;s Technical breakdown</a>]</p><ul><li><p>Official XPRL (Ripple) NPM package infected with backdoor that steals cryptocurrency private keys through a suspicious function called <code>checkValidityOfSeed</code> that sends data to domain &#8220;0x9c[.]xyz&#8221;.</p></li><li><p>Attackers released five unauthorized versions (4.2.1-4.2.4, 2.14.2) of the popular package with over 140,000 weekly downloads, progressively refining their malicious code injection techniques.</p></li></ul></li></ul><h3><strong>Audience Questions</strong></h3><ul><li><p>Thanks to everyone who sent in questions. Remember to send yours to questions@bitcoin.review.</p><ul><li><p>00:35:12 What&#8217;s the difference between test net and signet? And what are the benefits of each?</p></li><li><p>00:37:15 Can you explain, in simple terms, what OP_CHECKCONTRACTVERIFY does?</p></li><li><p>There&#8217;s been a lot of talk about the difference between using OP_RETURN and witness data. Specifically that OP_RETURN is prunable and witness data ends up in the chain. Can you explain in normie terms how this works?</p></li></ul></li></ul><h3><strong>Privacy &amp; Other Related Bitcoin Projects</strong></h3><h4><strong>Software Releases &amp; Project Updates</strong></h4><ul><li><p>Sideband <a href="https://github.com/markqvist/Sideband/releases/tag/1.6.0">v1.6.0</a></p><ul><li><p>Add compatibility with new AES-256 modes in RNS</p></li><li><p>Add transfer speed display to outgoing messages</p></li><li><p>Add ability to exclude objects from telemetry collector responses</p></li><li><p>Add interactive console option to daemon mode</p></li><li><p>Add option to specify RNS config path</p></li><li><p>Add Windows location plugin example</p></li><li><p>Sideband now uses abstract domain sockets for IPC on supported platforms</p></li><li><p>Improve memory consumption</p></li><li><p>Improve I/O performance</p></li></ul></li><li><p>SimpleX <a href="https://github.com/simplex-chat/simplex-chat/releases/tag/v6.3.3">v6.3.3</a></p><ul><li><p>Add support for connecting via short connection links.</p><ul><li><p>To create short connection links:</p><ul><li><p>Enable Dev Tools</p></li><li><p>Enable short links in Privacy &amp; Security settings</p></li></ul></li></ul></li></ul></li></ul><h4><strong>Project spotlight</strong></h4><ul><li><p><a href="https://berty.tech/">Berty</a>: An open, secure, offline-first, peer-to-peer and zero trust messaging app [<a href="https://github.com/berty/berty">Github</a>]</p><ul><li><p>Berty is a decentralized messaging app with end-to-end encryption that requires no phone number or email, works without internet connection, and remains functional on adversarial networks.</p></li><li><p>Developed by Berty Technologies, a French nonprofit, Berty aims to serve users needing secure communication while traveling, wanting anonymity, avoiding third-party servers, or living under censorship.</p></li></ul></li><li><p><a href="https://filekey.app/">Filekey</a>: Encrypt and share files securely with passkeys. Fully offline, easy-to-use, and zero-knowledge for ultimate file protection [<a href="https://github.com/RockwellShah/filekey">Github</a>]</p><ul><li><p>&#8220;FileKey is an offline web app that lets you quickly encrypt and share files using passkeys. No accounts, no tracking, no backend servers. Just local, offline security powered by passkeys.&#8221;</p></li></ul></li><li><p><a href="https://stefan-oltmann.de/pixelsafe/">PixelSafe</a>: A steganography tool for PNG images that uses the Least Significant Bit (LSB) algorithm [<a href="https://github.com/StefanOltmann/pixelsafe">Github</a>]</p><ul><li><p>&#8220;It lets you embed hidden data inside PNG files - for example, storing a KeePass database inside a screenshot. You can use it to hide backup files, send private messages, embed digital signatures, or attach invisible metadata to your images.&#8221;</p></li></ul></li><li><p>TorVPN Android app: A WIP from the Tor Project to replace Orbot [<a href="https://gitlab.torproject.org/tpo/applications/vpn">Gitlab</a>]</p><ul><li><p>TorVPN project develops whole-device and app-specific anonymous communication [<a href="https://gitlab.torproject.org/tpo/applications/vpn/-/wikis/home">Wiki</a>]</p></li><li><p>The initiative involves cross-team coordination with Arti, TPO teams for user experience, network health, and focuses initially on Android implementation with future platform expansion.</p></li></ul></li></ul><h3><strong>Lightning + L2+</strong></h3><h4><strong>Project spotlight</strong></h4><ul><li><p>NodeGuard: A treasury management solution for Lightning nodes [<a href="https://github.com/Elenpay/NodeGuard">Github</a>]</p><ul><li><p>NodeGuard is an open-source technology stack developed to simplify treasury operations for lightning nodes, focusing on both Security and UX.</p></li><li><p>Features include asynchronous channel funding with multisig wallets, liquidity automation, remote signing, automatic fund sweeping, and hardware wallet support for transaction signing.</p></li></ul></li><li><p><a href="https://0commons.com/">0Commons</a>: A V4V platform where creators can share digital files (photos, graphics, videos, fonts, 3D printing files) under CC0 license with unrestricted commercial use.</p><ul><li><p>The platform operates on a Value-for-Value model, allowing users to download content for free and zap creators directly, with creators receiving 100% of the contributions.</p></li></ul></li><li><p><a href="https://lightningnetworkprofitability.com/">Bitcoin Lightning Network Profitability Calculator</a>: An interactive tool designed to help users estimate their earnings from operating a Bitcoin Lightning Network node</p><ul><li><p>It allows users to input various parameters to simulate different scenarios and assess the profitability of their investment.</p></li></ul></li><li><p><a href="https://zapback.ekzy.is/">Zapback</a>: Last Pay Wins for Friends: A friend-based zap game with 24-Hour timer [<a href="https://github.com/ekzyis/zapback">Github</a>]</p><ul><li><p>A project inspired by <a href="https://bitcoin.review/podcast/episode-96/www.lastpaywins.com">lastpaywins.com</a></p></li><li><p>Players must zap back within 24 hours to stay in the game. The pool grows over time until one player forgets to respond, with the last player winning everything.</p></li></ul></li><li><p>Coinbase launches x402, a protocol enabling instant stablecoin payments over HTTP that allows APIs, apps, and AI agents to transact within the internet economy [<a href="https://www.coinbase.com/en-gb/developer-platform/discover/launches/x402">Announcement</a>]</p><ul><li><p>The protocol addresses limitations of traditional payment systems by leveraging the HTTP &#8220;402 Payment Required&#8221; status code, making stablecoin payments a native web function with minimal coding required. [<a href="https://www.x402.org/x402-whitepaper.pdf">White paper</a>]</p></li></ul></li></ul><h4><strong>Software Releases &amp; Project Updates</strong></h4><ul><li><p>LND <a href="https://github.com/lightningnetwork/lnd/blob/master/docs/release-notes/release-notes-0.19.0.md">v0.19.0</a></p><ul><li><p>New Features</p><ul><li><p>Add support for archiving channel backup in a designated folder which allows for easy referencing in the future. A new config is added disable-backup-archive, with default set to false, to determine if previous channel backups should be archived or not.</p></li><li><p>Protocol Updates</p><ul><li><p><code>lnd</code> now supports the new RBF cooperative close flow</p></li><li><p>Add support for experimental endorsement signal relay</p></li><li><p>Add initial support for quiescence</p></li><li><p>The max fee rate is now respected when a coop close is initiated</p></li></ul></li><li><p>Functional Enhancements</p><ul><li><p>Add ability to paginate wallet transactions</p></li><li><p>Make <code>MaxWaitNumBlocksFundingConf</code> configurable, allowing integration/development tests to set a lower value for faster funding confirmation timeout while keeping the default of 2016 blocks for production stability.</p></li><li><p>Previously when sweeping inputs, the sweeper will wait until the specified budget can be covered by the inputs, which could cause the sweep to be delayed, and the sweeping tx ends up using large fees. This is now changed so the sweeper will always attempt the sweep as long as the budget can be partially covered.</p></li><li><p>Add validation to ensure that MPP parameters are compatible with the payment amount before attempting the payment</p></li></ul></li></ul></li></ul></li><li><p>LDK</p><ul><li><p>ldk-node <a href="https://github.com/lightningdevkit/ldk-node/releases/tag/v0.5.0">v0.5.0</a></p><ul><li><p>The <code>PaymentSuccessful</code> event now exposes a <code>payment_preimage</code> field</p></li><li><p>The node now emits <code>PaymentForwarded</code> events for forwarded payments</p></li><li><p>Add ability to send custom TLVs as part of spontaneous payments</p></li><li><p>Add ability to override the used fee rates for on-chain sending</p></li><li><p>Add ability to set a description hash when creating a BOLT11 invoice</p></li><li><p>Add ability to export pathfinding scores</p></li><li><p>Add ability to request inbound channels from an LSP via the bLIP-51 / LSPS1 protocol</p></li><li><p>The ChannelDetails returned by <code>Node::list_channels</code> now exposes fields for the channel&#8217;s SCIDs</p></li><li><p>Lightning peer-to-peer gossip data is now being verified when syncing from a Bitcoin Core RPC backend</p></li><li><p>The logging sub-system was reworked to allow logging to backends using the Rust log facade, as well as via a custom logger trait</p></li><li><p>On-chain transactions are now added to the internal payment store and exposed via <code>Node::list_payments</code></p></li><li><p>Inbound announced channels are now rejected if not all requirements for operating as a forwarding node have been met</p></li><li><p>Add initial support for operating as an bLIP-52 / LSPS2 service</p></li><li><p>The <code>Builder::set_entropy_seed_bytes</code> method now takes an array rather than a Vec</p></li><li><p>The builder will now return a NetworkMismatch error in case of network switching</p></li><li><p>The <code>Bolt11Jit</code> payment variant now exposes a field telling how much fee the LSP withheld</p></li><li><p>Add ability to disable syncing Lightning and on-chain wallets in the background</p></li><li><p>Add ability to configure the node&#8217;s announcement addresses independently from the listening addresses</p></li><li><p>Add ability to choose whether to honor the Anchor reserves when calling <code>send_all_to_address</code></p></li><li><p>Add ability to sync the node via an Electrum backend</p></li></ul></li><li><p>rust-lightning <a href="https://github.com/lightningdevkit/rust-lightning/releases/tag/v0.1.3">v0.1.3</a> - &#8220;Routing Unicode in 2025&#8221;</p><ul><li><p>Bug Fixes</p><ul><li><p><code>Event::InvoiceReceived</code> is now only generated once for each <code>Bolt12Invoice</code> received matching a pending outbound payment.</p></li><li><p>LDK&#8217;s router now more fully saturates paths which are subject to HTLC maximum restrictions after the first hop.</p></li></ul></li><li><p>Security</p><ul><li><p>v0.1.3 fixes a denial-of-service vulnerability which cause a crash of an LDK-based node if an attacker has access to a valid <code>Bolt12Offer</code> which the LDK-based node created.</p></li><li><p>A malicious payer which requests a BOLT 12 Invoice from an LDK-based node (via the <code>Bolt12InvoiceRequest</code> message) can cause the panic of the LDK-based node due to the way <code>String::truncate</code> handles UTF-8 codepoints.</p></li></ul></li></ul></li></ul></li><li><p>Ark <a href="https://github.com/ark-network/ark/releases/tag/v0.6.0">v0.6.0</a> - Indexer, RegisterIntent+BIP-322 support &amp; SDK SQLite db</p><ul><li><p>Features:</p><ul><li><p>[Server] Make round failed if there&#8217;s not enough liquidity</p></li><li><p>[SDK] Retry settlement</p></li><li><p>Return utxo/vtxo amount limits in <code>GetInfo</code></p></li><li><p>Return updated <code>spentVtxos</code> list in <code>transactionEventsCh</code></p></li><li><p>[SDK] Disable onchain features if server doesn&#8217;t allow them</p></li><li><p>Add RegisterIntent + BIP0322 Proof of Funds &amp; Drop covenant &amp; SDK SQLite db</p></li></ul></li><li><p><a href="https://docs.arklabs.xyz/ark/">Ark</a> partners with Austrian educational institution TU Wien on a formal specification of the Ark protocol [<a href="https://docs.arklabs.xyz/ark.pdf">Litepaper</a>]</p><ul><li><p>&#8220;Ark Litepaper formalizes Ark&#8217;s technical foundation and provides additional clarity for researchers &amp; developers interested in contributing to its implementations.&#8221;</p></li></ul></li></ul></li><li><p>Fountain <a href="https://blog.fountain.fm/p/1-2-1">v1.2</a></p><ul><li><p>Library design update:</p><ul><li><p>Add new content-type filters at the top of the page</p></li><li><p>Recently Played is now the default view in your library</p></li><li><p>Music filter now makes it easier to find saved tracks and albums</p></li></ul></li><li><p>Content pages design update: Redesign shows, episodes, artists, albums, tracks, clips and playlists pages</p></li><li><p>Episode summaries:</p><ul><li><p>Add Summary button above show notes</p></li><li><p>Summaries and transcripts now come as a bundle</p></li></ul></li><li><p>Playback improvements: Rebuilt the audio engine from the ground up</p><ul><li><p>Tracks now load and play instantly when tapped</p></li><li><p>Faster skipping in-between collection of tracks</p></li><li><p>Replace scrollable player page with full-screen modals</p></li></ul></li><li><p>Other bug fixes &amp; improvements:</p><ul><li><p>Rebuilt payment stats for more complete and reliable transaction records</p></li><li><p>Add new episode notification preferences in Settings</p></li></ul></li></ul></li><li><p>Phoenixd <a href="https://github.com/ACINQ/phoenixd/releases/tag/v0.6.0">v0.6.0</a></p><ul><li><p>Support simple close</p></li><li><p>Add support for linux arm64 target</p></li><li><p>Update Dockerfile - fix casing warnings</p></li><li><p>Support stateless offers with optional custom description and amount</p></li><li><p>Upgrade to lightning-kmp 1.10.2</p></li></ul></li><li><p>BoltzExchange boltz-client <a href="https://github.com/BoltzExchange/boltz-client/releases/tag/v2.6.0">v2.6.0</a> - Tiny</p><ul><li><p>Allows lower swap limits for submarine swaps</p><ul><li><p>Add support for a new minimal threshold (&#8220;MinimalBatched&#8221;) for batched swaps, allowing swaps below a certain amount to be handled differently.</p></li></ul></li></ul></li><li><p>Breez SDK</p><ul><li><p>Nodeless <a href="https://github.com/breez/breez-sdk-liquid/releases/tag/0.8.2">v0.8.2</a></p><ul><li><p>Faster Lightning payment reception</p></li><li><p>Critical fix to Bitcoin transaction fee calculation</p></li></ul></li><li><p>Greenlight <a href="https://github.com/breez/breez-sdk-greenlight/releases/tag/0.7.1">v0.7.1</a></p><ul><li><p>Implement version 2 of Taproot swaps by unifying the swap execution interface under BTCReceiveSwap and extending support for taproot-specific logic</p></li></ul></li></ul></li><li><p>Lightning Loop</p><ul><li><p><a href="https://github.com/lightninglabs/loop/releases/tag/v0.31.1-beta">v0.31.1</a></p><ul><li><p>Autoloop now defaults to a slow publication deadline (30 minutes after initiation) to reduce fees. To revert to the previous behavior, users can run <code>loop setparams --fast</code>, which causes swap HTLCs to be published immediately after initiation.</p></li></ul></li><li><p><a href="https://github.com/lightninglabs/loop/releases/tag/v0.31.0-beta">v0.31.0</a></p><ul><li><p>Enhance the <code>loop listswaps</code> command by improving the ability to filter the response</p></li></ul></li></ul></li><li><p>lightning-kmp <a href="https://github.com/ACINQ/lightning-kmp/releases/tag/v1.10.0">v1.10.0</a></p><ul><li><p>Implement option_simple_close</p></li><li><p>Remove amount-based confirmation scaling</p></li><li><p>Bolt11 invoices: do not re-encode amounts</p></li><li><p>Add more force-close tests for HTLC settlement</p></li><li><p>Send normal failures for Bolt12 payments</p></li><li><p>Add test for Bolt11 features minimal encoding</p></li><li><p>Peer storage</p></li><li><p>Stateless offers</p></li><li><p>Use the offer description as default payer note</p></li><li><p>Add support for linux arm64 target</p></li></ul></li><li><p>BlitzWallet <a href="https://github.com/BlitzWallet/BlitzWallet/releases/tag/Android-v0.4.4-beta">v0.4.4-beta</a></p><ul><li><p>eCash Improvements</p><ul><li><p>Prevention of Duplicate eCash Payments: eCash transactions can no longer be paid twice</p></li><li><p>Fix Background eCash Invoice Handling: When a user creates an eCash quote but fails to pay before the quote expires, the app no longer attempts to claim it with an incorrect proof index during the next wallet load</p></li></ul></li><li><p>Payment Experience</p><ul><li><p>Bolt12 Payments from Liquid: Users can now send payments to BOLT12 invoices directly from their Liquid balance</p></li><li><p>Support for Blink QR Codes: Blink QR codes now open directly inside the Blitz native UI with LNURL-pay support</p></li><li><p>Lower Minimum for Lightning-to-Liquid Payments: The minimum receive amount for Lightning-to-Liquid swaps has been reduced to 100 sats</p></li></ul></li><li><p>App Enhancements</p><ul><li><p>Manual Sync via Swipe Gesture</p></li><li><p>Crash Reporting with User Control</p></li><li><p>Blitz Social Tracking: A new section in settings shows how many users have downloaded Blitz and tracks its growth over time</p></li><li><p>Half-modal Popups: Popups can now be dismissed</p></li></ul></li></ul></li><li><p>Nutshell <a href="https://github.com/cashubtc/nutshell/releases/tag/0.16.6-rc1">v0.16.6-rc1</a></p><ul><li><p>New Features</p><ul><li><p>Blind Authentication</p><ul><li><p>Limit mint access using Clear and Blind Authentication. Nutshell now supports NUT-21 and NUT-22, enabling the use of OAuth 2.0 identity providers like Keycloak (or any compatible provider)</p></li><li><p>NUT-22 introduces Blind Authentication, which enhances user privacy by anonymizing authentication within the set of registered users.</p></li></ul></li></ul></li><li><p>Improved Multi-Nut Payments</p><ul><li><p>Multi-nut payments via LND are now more reliable</p></li></ul></li><li><p>Additional Protocol Updates</p><ul><li><p>SIG_ALL Multisig Flag: Users can now lock ecash to specific destinations (outputs)</p></li><li><p>Mint and Melt Quote Enhancements: The update to NUT-04/05 introduces new fields (amount, unit, request) to mint and melt quotes</p></li><li><p>ToS URL: Mints now have the option to enter a Terms of Service (ToS) URL in the mint info settings</p></li></ul></li><li><p>Fixes and Improvements</p><ul><li><p>Wallet Un-reservation: Nutshell wallet now un-reserves ecash after a failed Lightning payment more reliably</p></li><li><p>Improved Keyset Rotation: Enhanced keyset rotation process for mints</p></li><li><p>Pending Melt Quotes: Mints now check pending melt quotes in the background every hour</p></li><li><p>Balance Tracking for Keysets: Mints can now track balances for each keyset separately</p></li></ul></li></ul></li><li><p>Cashu-ts <a href="https://github.com/cashubtc/cashu-ts/releases/tag/v2.5.0">v2.5.0</a></p><ul><li><p>Cashu-TS 2.5 is out, adding NUT-22 Blinded Authentication and plenty of DX improvements.</p><ul><li><p>Replace Enums with Const Objects</p></li><li><p>Add getDecodedToken example in the README and an example of firebase API to receive cashu payments</p></li><li><p>Support for proof witness field in token serialization</p></li><li><p>Fix P2PK refund to reflect NUT-11 format</p></li><li><p>Add NUT-22 BlindedAuth</p></li><li><p>Melt: made blank output amount equal split length</p></li><li><p>Bringing back cashu-crypto-ts code into cashu-ts</p></li><li><p>Run format check on PR</p></li><li><p>Make sure to always stringify URL object for WebSockets</p></li><li><p>nut18: optional transport and add nut10 option</p></li><li><p>Add API-Extractor to project and CI</p></li></ul></li></ul></li><li><p>Minibits is now expanding to iOS <a href="https://bitcoin.review/podcast/episode-96/testflight.apple.com/join/defJQgTD">TestFlight</a> [<a href="https://x.com/MinibitsCash/status/1915371935279595850">Announcement</a>]</p></li><li><p>Geyser launches Bitcoin <a href="https://geyser.fund/launchpad">Launchpad</a>: A visibility platform for early-stage projects [<a href="http://njump.me/nevent1qvzqqqqqqypzpdkumh0cve6jslg6f6rzpkf24yzuykxc2zlcejfr6wwlrm07uhh8qythwumn8ghj7un9d3shjtnswf5k6ctv9ehx2ap0qqsp65slze7463xmlefganue0wg4nlryeyem8cpd090rxm0qnfjk4ggqzjl8u">Announcement</a>]</p><ul><li><p>Launchpad introduces a system requiring Bitcoin projects to gather 21 followers within 30 days to officially launch, addressing the issue that &#8220;projects don&#8217;t fail because they lack funds&#8221; but because &#8220;no one knew they existed.&#8221;</p></li><li><p>Each project receives a dedicated section for 30 days, with followers receiving email updates upon reaching the threshold of 21 followers; projects can alternatively launch manually for $21.</p></li><li><p>The platform aims to &#8220;separate signal from noise&#8221; by creating a small challenge that may trigger momentum, giving visibility to meaningful projects before they go live.</p></li></ul></li></ul><h3><strong>Nostr</strong></h3><h4><strong>Project spotlight</strong></h4><ul><li><p><a href="https://following.space/">Nostr Follow List</a>: A minimalistic Nostr application for creating, sharing, and discovering Nostr Follow Packs [<a href="https://github.com/callebtc/nostr-follow-packs">Github</a>] by callebtc</p></li><li><p><a href="https://relays.land/">Relays.land</a>: A customizable relay management tool for Nostr [<a href="https://git.fiatjaf.com/relays.land">Code repository</a>] by fiatjaf</p><ul><li><p>Relays.land is a platform that enables users to create and manage custom Nostr relays with specific content curation and moderation rules. It offers three types of relays: curated, programmable, and moderated.</p></li></ul></li><li><p><a href="https://castr.me/">(Pub)Caster</a>: Effortlessly turn your npub into a podcast feed [<a href="https://github.com/dergigi/pubcaster">Github</a>] by dergigi</p><ul><li><p>&#8220;(Pub)Castr is a service that automatically generates podcast feeds from Nostr profiles. It converts kind1 events containing audio (and video) file links into a valid Podcasting 2.0 feed.&#8221;</p></li></ul></li><li><p><a href="https://camelus.app/">Camelus</a>: A nostr client for Android and iOS (beta TestFlight) [<a href="https://github.com/leo-lox/">Github</a>] (WIP)</p><ul><li><p>Features:</p><ul><li><p>Nostr Protocol for Decentralized Data Storage: Ensures user data privacy and control</p></li><li><p>Clean Architecture: Uses Dart and Flutter</p></li><li><p>Dart_NDK Integration: Optimized for mobile battery</p></li><li><p>In-Box and Out-Box Messaging: Optimized for gossip and database performance</p></li><li><p>Open-Source Development: Community-driven project</p></li><li><p>Riverpod for State Management: Efficient and testable state management</p></li></ul></li></ul></li><li><p>nparrot-chat: Integrate any command line tool with Nostr relays-as-groups [<a href="https://github.com/Leaf-Computer/nparrot">Github</a>]</p><ul><li><p>Nostr Parrot Chat is a convenient CLI tool that facilitates messaging over Nostr relay chat rooms</p></li><li><p>Use cases:</p><ul><li><p>Talk to your Goose AI agent via DMs from your phone by using any Nostr client compatible with NIP-17</p></li><li><p>Easily integrate almost any other command line tool with Nostr DMs</p></li><li><p>Send yourself notifications easily from any environment that can run shell commands</p></li><li><p>Use this as a test or troubleshooting tool for NIP-17 messages</p></li></ul></li></ul></li><li><p><a href="https://anchor.coracle.social/#!/alerts">Anchor Alerts</a>: A notification and syncing server for flotilla.social [<a href="https://github.com/coracle-social/anchor">Github</a>]</p><ul><li><p>The tool bridges nostr to email, offering notifications without requiring users to install additional software.</p></li></ul></li><li><p><a href="https://chronostr.pages.dev/">Chronostr</a>: A scheduling adjustment and RSVP tool working on the Nostr [<a href="https://github.com/studiokaiji/chronostr">Github</a>]</p></li><li><p>Nostash: A nostr signing extension for Safari [<a href="https://github.com/tyiu/nostash">Github</a>]</p><ul><li><p>This is a NIP-07 compatible extension for signing nostr events, forked from (the no longer supported project) <a href="https://github.com/ursuscamp/nostore">nostore</a></p></li></ul></li><li><p><a href="https://kinostr.com/">Kinostr</a>: A nostr client that renders kind 1 nostr notes and their attachments</p><ul><li><p>Kinostr is a YouTube-like interface for Nostr videos using the #kinostr tag</p></li></ul></li><li><p><a href="https://swae.live/">Swae</a>: A live streaming application built on the Nostr protocol, aiming to provide a censorship-resistant platform for content creators and viewers [<a href="https://github.com/suhailsaqan/swae">Github</a>] (WIP)</p><ul><li><p>&#8220;Users are able to send bitcoin to streamers and other users over the lightning protocol.&#8221;</p></li></ul></li><li><p><a href="https://team.trustroots.org/nostr.html">Nostroots</a>: An initiative to seamlessly transition <a href="https://www.trustroots.org/">Trustroots</a>, the platform for sharing, hosting, and community building, onto the nostr network [<a href="https://github.com/Trustroots/nostroots">Github</a>]</p><ul><li><p>&#8220;Trustroots is a social network of travelers and hosts that offer couches. Founded in 2014, 112k+ members now.&#8221;</p></li></ul></li><li><p><a href="https://sobrkey.vercel.app/">Sobrkey</a>: A decentralized sobriety tracking and community support application built on Nostr [<a href="https://github.com/spe1020/Sobrkey">Github</a>]</p><ul><li><p>Features include: 12-step journey tracking, public community support, emergency resources, zap-based donations, and Decentralized identity.</p></li></ul></li><li><p><a href="https://www.nostrly.com/">Nostrly</a>: A web-based service that allows users to register a verified Nostr address</p><ul><li><p>Nostrly also provides various tools for Nostr and Cashu, including: NIP-09 Note Deleter, NIP-19 Decoder, and NIP-57 Web Zap</p></li><li><p>Cashu tools: Cache, Gather, NutLock, Witness, and Redeem</p></li></ul></li><li><p><a href="https://nostream.pub/">Nostream</a>: A media-only Nostr firehose stream, unfiltered (A project by @jack)</p></li></ul><h4><strong>Software Releases &amp; Project Updates</strong></h4><ul><li><p>00:46:55 Nostr Messaging Layer Security (MLS) <a href="https://github.com/rust-nostr/nostr/commits/master/crates/nostr-mls">Update</a> [<a href="https://njump.me/naddr1qvzqqqr4gupzq9eemymaerqvwdc25f6ctyuvzx0zt3qld3zp5hf5cmfc2qlrzdh0qqxnzde5xccryve3xuurxv3eply303">Note</a>]</p><ul><li><p>Libraries released: nostr_mls_storage, nostr_mls_memory_storage, nostr_mls_sqlite_storage, and nostr_mls</p></li><li><p>White Noise refactor</p></li><li><p>Encrypted media with Blossom: Media in groups is encrypted using an MLS secret and uploaded to Blossom with a one-time use keypair</p></li><li><p>Damn mobile: beta version coming live on Zapstore in a few weeks</p></li></ul></li><li><p>00:48:42 Primal <a href="https://github.com/PrimalHQ/primal-android-app/releases/tag/2.2.13">v2.2.13</a></p><ul><li><p>Login with public key</p></li><li><p>Amber support</p></li><li><p>Blossom media uploads &amp; settings</p></li><li><p>Push notifications for Google builds (not available in Github APKs)</p></li><li><p>Notifications revamp</p></li><li><p>Image gallery in article details</p></li><li><p>Muting words, hashtags &amp; threads</p></li><li><p>New gallery rendering for media attachments in notes</p></li><li><p>&#8220;Share note as image&#8221; option in note context menu</p></li><li><p>Copy Url &amp; Copy Image in media gallery screen</p></li><li><p>Copy to clipboard when tapping on bitcoin or lightning address in wallet</p></li><li><p>Topological sort for FeedPost on threads</p></li><li><p>Request Delete action for notes &amp; articles</p></li><li><p>Simplified note context menu</p></li></ul></li><li><p>00:48:43 Damus <a href="https://njump.me/nevent1qqsda4jympxet9p8mf6jl538mg5f89j6s39mnl9jcjcq2crvstwnc9szyql0mt4mrkyj867enj084n3mgx22k3239c4708qm045djfp7p5ngzqcyqqqqqqgxynqvd">v1.14</a> - TestFlight for Purple users</p><ul><li><p>Introduce new one-click wallet setup, powered by Coinos</p></li><li><p>Revamp wallet experience with balance and transactions view for your NWC wallet</p></li><li><p>New notification setting to hide hellthreads</p></li><li><p>Add NIP-65 relay list support</p></li><li><p>Add Unicode 16 emoji reactions (only for iOS 18.4+)</p></li><li><p>Blurred images now show some more information</p></li></ul></li><li><p>Damus Notedeck <a href="https://cdn.jb55.com/hls/notedeck-beta-release/master.m3u8">Beta Release</a> [<a href="https://njump.me/nevent1qqs2dseuw3d4sqkyt97pzq3vg5ncx6zv2fk6ummejf88ezesa2exkrc8y4zm9">Announcement</a>]</p><ul><li><p>New in Notedeck Beta:</p><ul><li><p>Dave nostr AI assistant app</p></li><li><p>GIFs</p></li><li><p>Fulltext note search</p></li><li><p>Zaps (NWC/ Wallet UI)</p></li><li><p>Introduce last note per pubkey feed (experimental)</p></li><li><p>Allow multiple media uploads per selection</p></li><li><p>Major Android improvements (still wip)</p></li><li><p>Add notedeck app sidebar</p></li><li><p>User Tagging</p></li><li><p>Note truncation</p></li><li><p>Local network note broadcast, broadcast notes to other notedeck notes while you&#8217;re offline</p></li><li><p>Mute list support (reading)</p></li><li><p>Relay list support</p></li></ul></li></ul></li><li><p>Coracle</p><ul><li><p><a href="https://github.com/coracle-social/coracle/releases/tag/0.6.16">v0.6.16</a></p><ul><li><p>Add support for editing WOT feeds</p></li><li><p>Change default blossom servers</p></li><li><p>Add support for custom emojis</p></li></ul></li><li><p><a href="https://github.com/coracle-social/coracle/releases/tag/0.6.15">v0.6.15</a></p><ul><li><p>Improve remote signing</p></li><li><p>Drop nip 96 support</p></li><li><p>Use user blossom servers</p></li><li><p>Avoid duplicate notes in feeds</p></li></ul></li><li><p><a href="https://github.com/coracle-social/coracle/releases/tag/0.6.13">v0.6.13</a></p><ul><li><p>Add safe areas for phones</p></li></ul></li><li><p><a href="https://github.com/coracle-social/coracle/releases/tag/0.6.12">v0.6.12</a></p><ul><li><p>Upgrade capacitor</p></li><li><p>Allow use of ws:// relays on android</p></li></ul></li><li><p><a href="https://github.com/coracle-social/coracle/releases/tag/0.6.10">v0.6.10</a></p><ul><li><p>Use new version of network library</p></li><li><p>Re-work storage adapter to minimize storage and improve performance</p></li><li><p>Improve initial page load times</p></li><li><p>Upgrade welshman</p></li><li><p>Remove platform relay</p></li><li><p>Show PoW</p></li><li><p>Don&#8217;t fetch messages until decryption is enabled</p></li></ul></li></ul></li><li><p>Flotilla</p><ul><li><p><a href="https://github.com/coracle-social/flotilla/releases/tag/1.0.3">v1.0.3</a></p><ul><li><p>Add light theme</p></li><li><p>Use correct alerts server</p></li><li><p>Ignore relay errors for claims</p></li><li><p>Add custom emoji parsing and display</p></li></ul></li><li><p><a href="https://github.com/coracle-social/flotilla/releases/tag/1.0.0">v1.0.0</a></p><ul><li><p>Add alerts via Anchor</p></li><li><p>Allow use of cleartext relays on native builds</p></li><li><p>Detect blossom support on community relays</p></li><li><p>Use user blossom server list in settings</p></li><li><p>Improve thunk indicator</p></li><li><p>Update storage adapters</p></li><li><p>Switch to pnpm</p></li></ul></li></ul></li><li><p>ndk-cache-sqlite-wasm <a href="https://github.com/nostr-dev-kit/ndk/commit/4682bcbe27737050521b45093456e1f594abf74e">v0.2.0</a> - Introduces the Sqlite WASM cache adapter package (feat: add SQLite WASM cache adapter with support for decrypted and unpublished events, including schema updates and migration logic)</p><ul><li><p>Implements the full NDKCacheAdapter interface, including:</p><ul><li><p>Event caching (setEvent, getEvent, etc.)</p></li><li><p>Profile caching (fetchProfile, saveProfile, etc.)</p></li><li><p>Synchronous and asynchronous APIs</p></li><li><p>Relay status management</p></li><li><p>Decrypted event cache (getDecryptedEvent, addDecryptedEvent)</p></li><li><p>Unpublished event management (addUnpublishedEvent, getUnpublishedEvents, discardUnpublishedEvent)</p></li></ul></li><li><p>Database schema and migration logic mirrors ndk-mobile&#8217;s implementation</p></li><li><p>Uses sql.js (WASM) for cross-platform SQLite support in browsers and JS environments</p></li><li><p>Database is persisted automatically to IndexedDB with debounced saves for performance</p></li><li><p>Example page included for browser testing and benchmarking</p></li><li><p>Documentation is symlinked into the main docs/cache directory</p></li></ul></li><li><p>Amber</p><ul><li><p><a href="https://github.com/greenart7c3/Amber/releases/tag/v3.4.1">v3.4.1</a></p><ul><li><p>Move from deprecated Autofill api</p></li><li><p>Move from deprecated ClipboardManager api</p></li><li><p>Move from encrypted shared preferences to DataStore and normal shared preferences</p></li><li><p>Add more event translations</p></li><li><p>Bigger qrcodes, increase brightness when showing the qrcode</p></li><li><p>Add a option to accept/reject a permission temporarily</p></li><li><p>Better connection handling when switching networks</p></li></ul></li><li><p><a href="https://github.com/greenart7c3/Amber/releases/tag/v3.2.8">v3.2.8</a></p><ul><li><p>Use bunker response from quartz</p></li><li><p>Include zapstore in the new bunker and initial message</p></li><li><p>Add search to the activity screen</p></li><li><p>Show option to never close the app when using bunker url</p></li><li><p>Separate general prefs and account prefs keys</p></li><li><p>Add loading indicator when trying to fetch profile picture</p></li></ul></li></ul></li><li><p>0xChat App <a href="https://github.com/0xchat-app/0xchat-app-main/releases/tag/v1.4.9-release">v1.4.9</a></p><ul><li><p>Implement updated NIP-29 group logic with support for group admin roles</p></li><li><p>Add support for Aegis URL scheme login on iOS</p></li></ul></li><li><p>Kyoto</p><ul><li><p><a href="https://github.com/rustaceanrob/kyoto/commit/322d81a0e0c0f5a2205606b14d3357302822447b">v0.11.0</a></p><ul><li><p>Fetch the Network from the node builder</p></li><li><p>Configure the initial TCP connection timeout when trying new peers</p></li><li><p>Add BDK integration links to the README</p></li><li><p>Update resource usage and profiling in DETAILS.md</p></li></ul></li><li><p><a href="https://github.com/rustaceanrob/kyoto/commit/6bffae6e5ee69aaf0b9f851952fe5784f2082e13">v0.10.0</a></p><ul><li><p>Template issue for bugs, enhancement requests, releases</p></li><li><p>Mainnet, signet, testnet4 checkpoints</p></li><li><p>Testnet4 DNS seeds</p></li><li><p>Socks5 proxy connections supported</p></li><li><p><code>justfile</code> improvements</p></li></ul></li></ul></li><li><p>Nostrmo <a href="https://github.com/haorendashu/nostrmo/releases/tag/3.0.0">v3.0.0</a></p><ul><li><p>Add support to nesigner (Windows, Linux and MacOS)</p></li><li><p>Using ISar to recode local relay&#8217;s database</p></li><li><p>Upgrade flutter versions</p></li><li><p>Show comment event (kind: 1111)</p></li><li><p>Add Relay Group Naddr and Follow Set Naddr str decode</p></li></ul></li><li><p>Citrine <a href="https://github.com/greenart7c3/Citrine/releases/tag/v0.8.0">v0.8.0</a></p><ul><li><p>Support for protected events</p></li><li><p>Support for auth</p></li><li><p>Option to disable listening to pokey broadcasts</p></li><li><p>Option to disable start on boot</p></li><li><p>Change how the last backup time is calculated</p></li></ul></li><li><p>Keychat <a href="https://github.com/keychat-io/keychat-app/releases/tag/1.31.13%2B6370">v1.31.13</a></p><ul><li><p>browser: Save the status of the tab unless it is closed manually</p></li><li><p>browser: Remove btcnav.org from mini app</p></li><li><p>message: Automatically refresh the homepage when a new message is added</p></li><li><p>desktop: Support packaging exe for windows platform. Optimize cmd+shift line break operation</p></li><li><p>mls: Cache state for uploading mls key package</p></li><li><p>android: The minimum supported Android version is now 12 (API level 31)</p></li></ul></li><li><p>Nowser <a href="https://github.com/haorendashu/nowser/releases/tag/1.1.0">v1.1.0</a></p><ul><li><p>Add hardware signer (nesigner) support</p></li><li><p>Android Signer package name method change</p></li><li><p>Image and link add long press support</p></li><li><p>Incognito Mode</p></li><li><p>Add download support</p></li><li><p>Url https check</p></li></ul></li><li><p>YakiHonne - iOS/Android/Web/Zap.Store</p><ul><li><p>Web <a href="https://njump.me/note1k35xzku6xmp3eswj400ax4n8qqnt6d20neylvqn2quvd6ujw5utss8gglu">v4.6.0</a></p><ul><li><p>Introducing Smart Widgets v2</p></li><li><p>New Tools Smart Widgets section in note creation for advanced content editing</p></li><li><p>Curations, videos, and polls are now Tools Smart Widgets, enabling quick creation and seamless embedding in notes</p></li><li><p>Zap advertisements added&#8212;top zappers can now appear below notes</p></li><li><p>Note translation button has been relocated next to the note options for easier access</p></li><li><p>Follower and following lists are now visible directly on the dashboard home page</p></li></ul></li><li><p>Mobile <a href="https://njump.me/note1k35xzku6xmp3eswj400ax4n8qqnt6d20neylvqn2quvd6ujw5utss8gglu">v1.7.0</a></p><ul><li><p>Introducing the fully upgraded smart widget with its expanded set of functionalities</p></li><li><p>A set of tools to enhance content editing</p></li><li><p>Curations, videos, and polls are now Tools Smart Widgets, enabling quick creation and seamless embedding in notes</p></li><li><p>Shortened URLs for a better user experience</p></li><li><p>Highest zappers in notes will be highlighted</p></li><li><p>Zapper list now includes zaps messages</p></li><li><p>Gossip model can be enabled and disabled</p></li></ul></li></ul></li><li><p>Yumyume <a href="https://gitlab.com/digitalethicsagency/nostr/yumyume/-/releases/0.6.0">v0.6.0</a> - Biryani with Pickled Onion &amp; Raita</p><ul><li><p>Optimized &amp; Interactive Tag Cloud: The tag cloud is now fully visualized with tag density and colors.</p></li><li><p>Bookmark Cards Now Ordered by Publishing Time: Update the global feed to sort and display bookmarks based on their original publishing timestamp, rather than the last edit.</p></li><li><p>Saving Client Info: Yumyume now saves the client name (&#8220;Yumyume&#8221;) in the background when publishing a bookmark.</p></li></ul></li><li><p>Samiz <a href="https://github.com/KoalaSat/samiz/releases/tag/v0.0.4-alpha">v0.0.4</a></p><ul><li><p>Now Samiz will broadcast:</p><ul><li><p>Notes of any Kind created up to 1 hour before the session started.</p></li><li><p>User Metadata created at any time</p></li></ul></li></ul></li><li><p>Shopstr <a href="https://njump.me/nevent1qqsfn40k6ham6vkpr76xslsmv76p6r8x8jvlgm2vg9r5qltuwv8e5ygpp4mhxue69uhkummn9ekx7mqzyz3hzx9y3z8q955wsanupr927ua5n276cwg66ll33gcy3y0yzmwrx3haavn">v0.4.2</a></p><ul><li><p>Add Blossom media support for image uploads with metadata stripping</p></li><li><p>Add a terms of service and privacy policy</p></li><li><p>Add pagination for product viewing</p></li></ul></li><li><p>Nostur <a href="https://nostur.com/testflight">Update (TestFlight)</a></p><ul><li><p>Add blossom media server support</p></li><li><p>Support multiple blossom servers as mirror</p></li></ul></li></ul><h3><strong>Boosts</strong></h3><ul><li><p>01:01:58 Thanks to everyone who streamed sats, and shoutout to our top boosters:</p><ul><li><p>[&#127942; TOP BOOSTER] @Rod Palmer (5000 sats) &#8220;PODCONF Disapproved &#10060;(due to Rijndael)&#8221;</p></li><li><p>@AVERAGE_GARY (1100 sats) &#8220;OpNext was great. Run your testnet4 CTV + CSFS client. [<a href="https://github.com/average-gary/bitcoin">Code repository</a>] Has Sv2 enabled branch too.&#8221; &#8220;dB near zero &#9889;&#8221;</p></li><li><p>@pink money (500 sats) &#8220;&#128293;&#128293;&#128293;&#8221;</p></li><li><p>@user4 (500 sats) &#8220;&#128293;&#128293;&#128293;&#8221;</p></li><li><p>@Wartime (333 sats) &#8220;Mon a not &#129300;&#129315;&#8221;</p></li><li><p>@btconboard (300 sats) &#8220;&#128077;&#127995;&#9889;&#65039;&#129761;&#8221;</p></li></ul></li></ul><h3><strong>Tech Tip of the Day</strong></h3><ul><li><p>01:03:51 <a href="https://cryptography101.ca/">Cryptography 101</a>: A free online cryptography course repository, by Alfred Menezes</p><ul><li><p>Includes &#8220;videos, slides, exercises and solutions, and news items.&#8221; [<a href="https://stacker.news/items/966634">Koob&#8217;s SN post</a>]</p></li></ul></li></ul><h3><strong>Bitcoin Optech Newsletter</strong></h3><ul><li><p>Highlights from recent Bitcoin Optech Newsletters</p><ul><li><p><a href="https://bitcoinops.org/en/newsletters/2025/05/09/">353</a></p><ul><li><p>BIP30 consensus failure vulnerability: Ruben Somsen <a href="https://mailing-list.bitcoindevs.xyz/bitcoindev/CAPv7TjZTWhgzzdps3vb0YoU3EYJwThDFhNLkf4XmmdfhbORTaw@mail.gmail.com/">posted</a> to the Bitcoin-Dev mailing list about a theoretical consensus failure that could occur now that checkpoints have been removed from Bitcoin Core.</p></li><li><p>Avoiding BIP32 path reuse: Kevin Loaec <a href="https://delvingbitcoin.org/t/avoiding-xpub-derivation-reuse-across-wallets-in-a-ux-friendly-manner/1644">posted</a> to Delving Bitcoin to discuss options for preventing the same BIP32 wallet path from being used with different wallets, which could lead to a loss of privacy due to output linking and a theoretical loss of security.</p></li></ul></li><li><p><a href="https://bitcoinops.org/en/newsletters/2025/05/02/">352</a></p><ul><li><p>Comparison of cluster linearization techniques: Pieter Wuille <a href="https://delvingbitcoin.org/t/how-to-linearize-your-cluster/303/68">posted</a> to Delving Bitcoin about some of the fundamental tradeoffs between three different cluster linearization techniques.</p></li><li><p>Increasing or removing Bitcoin Core&#8217;s <code>OP_RETURN</code> size limit: in a thread on Bitcoin-Dev, several developers discussed changing or removing Bitcoin Core&#8217;s default limit for OP_RETURN data carrier outputs.</p></li></ul></li><li><p><a href="https://bitcoinops.org/en/newsletters/2025/04/25/">351</a></p><ul><li><p>Interactive aggregate signatures compatible with secp256k1: Jonas Nick, Tim Ruffing, Yannick Seurin <a href="https://mailing-list.bitcoindevs.xyz/bitcoindev/be3813bf-467d-4880-9383-2a0b0223e7e5@gmail.com/">posted</a> to the Bitcoin-Dev mailing list to announce a paper they&#8217;ve written about creating 64-byte aggregate signatures compatible with the cryptographic primitives already used by Bitcoin.</p></li><li><p>Standardized backup for wallet descriptors: Salvatore Ingala <a href="https://delvingbitcoin.org/t/a-simple-backup-scheme-for-wallet-accounts/1607">posted</a> to Delving Bitcoin a summary of various tradeoffs related to backing up wallet descriptors and a proposed scheme that should be useful for many different types of wallets, including those using complex scripts.</p></li></ul></li></ul></li></ul><h3><strong>News &amp; Noteworthy</strong></h3><h4><strong>Bitcoin</strong></h4><ul><li><p>Elliptic&#8217;s new <a href="https://www.elliptic.co/blog/sanctions-and-terrorism-how-the-cartels-use-crypto-to-launder-the-proceeds-of-narcotics-trafficking">report</a> shows cartels deposit cash into banks before converting to stablecoins, challenging the narrative that &#8220;unhosted wallets&#8221; are the primary problem [<a href="https://www.therage.co/new-elliptic-report-are-unhosted-wallets-really-the-problem/">The Rage</a>]</p><ul><li><p>The report cautions lawmakers against relying on blockchain surveillance firm reports, noting these companies have &#8220;clear profit incentive to expand their services&#8221; into the non-custodial sector.</p></li></ul></li></ul><h4><strong>Lightning + L2+</strong></h4><ul><li><p>Aqua Wallet to introduce Dolphin Card: A KYC-free VISA card for spending [<a href="https://jan3.zendesk.com/hc/en-us/sections/36037146197019-Dolphin-Card-AQUA-Visa-Card">Blog post</a>]</p><ul><li><p>Aqua Wallet&#8217;s upcoming Dolphin Card allows spending Bitcoin, Liquid Bitcoin, and Tether at VISA merchants without identity verification, with a monthly limit of $4,000.</p></li><li><p>Initially launching as a virtual card with physical version to follow, the Dolphin Card will be available in most countries except the U.S. and Canada.</p></li></ul></li></ul><h4><strong>Nostr</strong></h4><ul><li><p>Bitcoin-focused news desk No Bullshit Bitcoin integrates zapthreads-based Nostr comments [<a href="https://njump.me/nevent1qqsp38gkgrl8ascuxu9zmgn665886ttkmz8ct68mhc8xfl4676ek23spp4mhxue69uhkummn9ekx7mqzyzu62d6j8wazlndws47epk98vr0y7gfee8usmxr0w37w058vp5tn64xl3ze">Note</a>]</p><ul><li><p>&#8220;Comments you leave under the original (quoted) post below should appear on our site, and comments you leave on our site should be visible under the post on Nostr.&#8221;</p></li></ul></li><li><p><a href="https://njump.me/npub1jp3776ujdul56rfkkrv8rxxgrslqr07rz83xpmz3ndl74lg7ngys320eg2">Guide</a>: Self-hosted NIP-05 as a Lightning Zap Address for Nostr, by Avren [<a href="https://njump.me/naddr1qvzqqqr4gupzpyrraa4eymelf5xndvxcwxvvs8p7qxluxy0zvrk9rxmlat73axsfqq2hw4rkwsmxun2nv98rsv3dvem42mthfdpkunz6gn9">Note</a>]</p></li></ul><h4><strong>Business &amp; Finance</strong></h4><ul><li><p>Bitcoin-native holding company Nakamoto merges with KindlyMD to build Bitcoin treasury [<a href="https://bitcoinmagazine.com/news/david-bailey-and-bitcoin-native-holding-company-nakamoto-announce-merger-with-kindlymd-to-establish-bitcoin-treasury">Bitcoin Magazine</a>]</p><ul><li><p>KindlyMD and Nakamoto Holdings announce $710 million merger deal with David Bailey becoming CEO of the combined entity while Tim Pickett continues managing healthcare operations.</p></li></ul></li><li><p>Tether, SoftBank Group, and Jack Mallers launch Twenty One, a Bitcoin-native company, through a business combination with Cantor Equity Partners [<a href="https://www.businesswire.com/news/home/20250423962305/en/Tether-SoftBank-Group-and-Jack-Mallers-Launch-Twenty-One-a-Bitcoin-native-Company-Through-a-Business-Combination-With-Cantor-Equity-Partners">Business Wire</a>]</p><ul><li><p>Twenty One Capital is launching with over 42,000 BTC in its treasury and plans to go public through a SPAC merger with Cantor Equity Partners.</p></li></ul></li><li><p>Strike launches Strike Lending: Bitcoin-backed loans for individuals and businesses []</p><ul><li><p>Strike introduces bitcoin-backed loans allowing eligible customers to borrow $75k to 2m for up to 12 months at 12% APR.</p></li></ul></li><li><p>Bull Bitcoin introduces brand new platform for Canadian customer base, following its extension in Costa Rica, Europe, and Mexico [<a href="https://www.bullbitcoin.com/blog/introducing-the-new-bull-bitcoin-platform">Blog post</a>]</p><ul><li><p>New features include instant e-transfers, transparent price spreads instead of fees, and enhanced Bitcoin transaction options including Lightning Network support, with automatic data deletion for inactive accounts.</p></li><li><p>Future developments include recurring buys over Lightning and Liquid networks, auto-buy/sell functions, Payjoin technology for privacy, and limit orders, all built on self-hosted infrastructure.</p></li></ul></li><li><p>Relai brings Bitcoin-collateralized lending to the European market [<a href="https://relai.app/blog/relai-private-sygnum-bitcoin-loans/">Announcement</a>]</p><ul><li><p>The service requires qualified investors under Swiss FinSA regulations, with minimum financial assets of CHF 500,000 and initial deposit of CHF 100,000, offering loans with 12-month minimum terms and up to 40% LTV ratios.</p></li></ul></li><li><p>Coinbase agrees to purchase Dubai-based Deribit for $2.9bn, paying 700mn in cash and the remainder in shares, marking the digital market&#8217;s largest ever acquisition [<a href="https://www.ft.com/content/3c6dcb79-44a3-465d-9c15-9816fe85944a">FT</a>]</p><ul><li><p>Deribit, the world&#8217;s largest cryptocurrency derivatives market, handled over $1tn in trading volumes last year as the industry prepares for anticipated demand from banks and asset managers.</p></li></ul></li><li><p>Coinbase Asset Management launches the Coinbase Bitcoin Yield Fund (CBYF), aiming to generate 4-8% net returns in bitcoin annually [<a href="https://www.coinbase.com/en-fr/blog/coinbase-asset-management-launches-the-coinbase-bitcoin-yield-fund">Press release</a>]</p><ul><li><p>Multiple investors including Abu Dhabi-based Aspen Digital have seeded the fund, which launched on May 1, 2025 with Aspen serving as initial distribution partner across UAE and Asia.</p></li></ul></li><li><p>Lightspark announces partnership with Revolut to implement Bitcoin network payment infrastructure in the UK and select EEA countries, offering lower fees and faster transactions [<a href="https://www.lightspark.com/blog/news/revolut-lightspark-announcement">Press release</a>]</p></li><li><p>Ruya bank partners with Fuze to become the first Islamic bank globally to offer Shari&#8217;ah-compliant virtual asset investments [<a href="https://bitcoinmagazine.com/news/ruya-becomes-first-islamic-bank-to-offer-bitcoin-and-virtual-asset-investments">Bitcoin Magazine</a>]</p></li><li><p>Meta explores stablecoin integration three years after Diem project collapse [<a href="https://fortune.com/crypto/2025/05/08/meta-stablecoins-exploration-usdc-circle-diem-libra/">Fortune</a>]</p><ul><li><p>Meta initiates talks with crypto infrastructure companies to potentially deploy stablecoins for cross-border payments to content creators</p></li></ul></li><li><p>Spar now accepts Bitcoin payments at its Zug supermarket via LNURL, implemented by DFX Swiss through OpenCryptoPay solution that enables QR code transactions [<a href="https://bitcoinnews.com/adoption/spar-supermarket-switzerland-bitcoin/">Bitcoin News</a>]</p></li><li><p>Citrea deploys Clementine Bridge on Bitcoin testnet using BitVM2 programming language to overcome the &#8220;bottleneck for using BTC in a programmable environment.&#8221; [<a href="https://www.coindesk.com/tech/2025/04/23/bitcoin-rollup-citrea-deploys-bridge-to-tackle-collateral-bottleneck-of-using-btc-in-defi">CoinDesk</a>]</p></li><li><p>Apple changes U.S. App Store guidelines to allow apps to link users to their websites for purchases after losing court battle against Epic Games [<a href="https://techcrunch.com/2025/05/02/apple-changes-us-app-store-rules-to-let-apps-redirect-users-to-their-own-websites-for-payments/">TechCrunch</a>]</p><ul><li><p>The ruling requires Apple to stop using &#8220;scare screens&#8221; and remove restrictive language guidelines, though the company states they will appeal the decision.s</p></li></ul></li></ul><h4><strong>Funding</strong></h4><ul><li><p>Tether renews $100,000 grant to the BTCPay Server Foundation for the second consecutive year [<a href="https://tether.io/news/tether-awards-another-100000-grant-to-btcpay-server-foundation-reaffirming-its-commitment-to-free-and-open-source-software-development/">Announcement</a>]</p></li><li><p>Spiral renews grant to <a href="https://x.com/spiralbtc/status/1920110108484173980">Dan Gould</a> (@bitgould) for his work on the Payjoin Dev Kit, and to <a href="https://x.com/spiralbtc/status/1914363508126515567">@joschisanbtc</a>, for &#8220;simplifying federations, allowing anyone to run Fedimint guardians on laptops, Start9s, whatever&#8221;.</p></li><li><p>Btrust awards grant to Africa Free Routing to support five Bitcoin Lightning-focused developer bootcamps across Africa in 2025 [<a href="https://bitcoiners.africa/btrust-partners-with-africa-freee-routing/">Press Release</a>]</p><ul><li><p>The bootcamps aim to onboard non-Bitcoin developers into the ecosystem, providing training, mentorship, and pathways to open-source contribution.</p></li><li><p>The initiative seeks to build local developer communities, increase participation in global Bitcoin projects, and expand technical capacity across the continent.</p></li><li><p>Participants will be funneled into long-term mentorship networks like Btrust Builders for continued growth.</p></li></ul></li></ul><h4><strong>Privacy</strong></h4><ul><li><p>France bans mixers and privacy coins [<a href="https://x.com/laurentmt/status/1917728418864435269">Twitter post</a>]</p><ul><li><p>A new law adopted in France now considers mixers and privacy coins as an indicator of suspicious activity by default [<a href="https://www.assemblee-nationale.fr/dyn/17/textes/l17t0102_texte-adopte-provisoire.pdf">Adopted Law proposal</a>]</p></li></ul></li><li><p>Jury orders NSO Group to pay WhatsApp $167 million in punitive damages for hacking 1,400 users in 2019 [<a href="https://techcrunch.com/2025/05/06/nso-group-must-pay-more-than-167-million-in-damages-to-whatsapp-for-spyware-campaign/">TechCrunch</a>]</p><ul><li><p>Judge previously ruled NSO Group violated federal and California hacking laws, with researcher John Scott-Railton stating: &#8220;NSO makes many millions of dollars helping dictators hack people.&#8221;</p></li></ul></li></ul><h4><strong>Bitcoin Security Incidents</strong></h4><ul><li><p>Elderly US citizen falls victim to 3,520 bitcoin social engineering theft [<a href="https://cointelegraph.com/news/elderly-us-victim-loses-330m-bitcoin-in-social-engineering-theft">Coin Telegraph</a>]</p><ul><li><p>An elderly US investor loses $330 million worth of Bitcoin in a sophisticated social engineering attack, ranking as the fifth-largest crypto hack in history, as reported by <a href="https://x.com/zachxbt/status/1916756932763046273">ZachXBT</a></p></li><li><p>The attacker then laundered the 3,520 stolen bitcoin through over six exchanges using peel chain methods and swapped significant portions into Monero, which spiked its price by 45% and lead to estimated slippage losses reaching $66 million.</p></li></ul></li><li><p>Five dollar wrench attacks: (Credit goes to Jameson Lopp&#8217;s physical bitcoin attacks <a href="https://github.com/jlopp/physical-bitcoin-attacks">repository</a>)</p><ul><li><p>Philippine National Police arrest three suspects for the kidnapping and murder of businessman and his driver [<a href="https://globalnation.inquirer.net/273226/3-suspects-arrested-in-tan-kidnap-slay">Global Nation</a>]</p><ul><li><p>The victims were lured to a house on March 29, 2025 and held captive for 10 days. The group demanded a $20m ransom, then killed their victim despite receiving a sum totalling $3m paid in cryptocurrency.</p></li></ul></li><li><p>Pakistani Counter-Terrorism Department arrests four individuals in Karachi for conducting short-term kidnappings while impersonating various law enforcement offices [<a href="https://archive.is/fpCPj">Ary News</a>]</p><ul><li><p>The suspects used fake government number plates on their car, abducted citizens to a remote area, and extracted ransoms including bitcoin secrets and cash from ATMs before releasing victims. The event took place on April 13, 2025.</p></li></ul></li><li><p>Father of crypto firm boss rescued in French police raid [<a href="https://www.lemonde.fr/en/france/article/2025/05/04/abducted-dad-of-crypto-firm-boss-freed-in-french-police-raid_6740891_7.html">Le Monde</a>]</p><ul><li><p>French police free a kidnapped man during a weekend raid in Paris, arresting five suspects in their 20s. The victim&#8217;s finger was mutilated, with kidnappers demanding a &#8364;5-7 million ransom from his cryptocurrency-wealthy son. The event took place on May 1, 2025.</p></li></ul></li><li><p>Three Florida teenagers kidnap Las Vegas business man at gunpoint, drive him to remote Arizona desert, and steal $4 million in cryptocurrency and other digital assets [<a href="https://www.8newsnow.com/investigators/florida-teens-kidnap-las-vegas-man-drive-him-to-arizona-desert-steal-4m-in-cryptocurrency-police/">8News Now</a>]</p><ul><li><p>The victim, who was the organizer of a cryptocurrency-related event in downtown Las Vegas, was forced to reveal the passwords of his financial accounts. The event took place in November 2024.</p></li></ul></li><li><p>Montreal police arrest three men for kidnapping and stealing $15,000 in cryptocurrency from a Verdun businessman [<a href="https://www.ctvnews.ca/montreal/article/3-men-facing-kidnapping-robbery-and-other-charges-in-crypto-theft-montreal-police/">CTV News</a>]</p><ul><li><p>The suspects allegedly tied up the victim, a man in his 30s who ran his own cryptocurrency business and tortured him for hours before obtaining transfer details and fleeing the scene. The event took place on August 15, 2024</p></li></ul></li></ul></li></ul><h4><strong>Protocol</strong></h4><ul><li><p>Bitcoin Core #31250: wallet: Disable creating and loading legacy wallets [<a href="https://github.com/bitcoin/bitcoin/pull/31250">Merged</a>]</p></li><li><p>Bitcoin Core #31247: psbt: MuSig2 Fields [<a href="https://github.com/bitcoin/bitcoin/pull/31247">Merged</a>] (Implements un/serialization of MuSig2 PSBT fields and prepares PSBT to be able to sign for MuSig2 inputs.)</p></li><li><p>BIPs #1835: BIP48: Add p2tr script type derivation [<a href="https://github.com/bitcoin/bips/pull/1835">Merged</a>]</p></li><li><p>BIPs #1555: BIP&#8239;321: URI Scheme (Replace BIP 21 with a new BIP containing information about more modern usage of it) [<a href="https://github.com/bitcoin/bips/pull/1555">Merged</a>]</p></li><li><p>BTCPay Server #6684: Add support for wallet policy descriptors (BIP388) [<a href="https://github.com/btcpayserver/btcpayserver/pull/6684">Merged</a>]</p></li><li><p>Eclair #3064: Simplify channel keys management [<a href="https://github.com/ACINQ/eclair/pull/3064">Merged</a>]</p></li><li><p>NIPs #1890: Adds optional nip60.signSecret() and kind 10019 filter tag [<a href="https://github.com/nostr-protocol/nips/pull/1890">Open</a>] (The PR clarifies and improves Nostr &lt;-&gt; Cashu interoperability)</p></li></ul><h4><strong>Government &amp; Political</strong></h4><ul><li><p>Spain&#8217;s new banking regulations clarified: no pre-approval needed for cash withdrawals [<a href="https://cryptoslate.com/spain-demands-tighter-bank-oversight-fuels-bitcoin-appeal/">Cryptoslate</a>]</p><ul><li><p>Spain&#8217;s Royal Decree 253/2025 requires financial institutions, not individuals, to report cash transactions over &#8364;3,000 monthly to tax authorities.</p></li><li><p>Financial institutions must now report all cash movements over &#8364;3,000 to tax authorities in monthly reports, offering the tax agency &#8220;granular, near&#8209;real&#8209;time data on every sizable cash movement and virtually every card transaction.&#8221;</p></li></ul></li><li><p>European Union plans to ban anonymous crypto accounts and privacy-preserving coins by 2027 under new AML regulation [<a href="https://cointelegraph.com/news/eu-crypto-ban-anonymous-privacy-tokens-2027">Coin Telegraph</a>]</p><ul><li><p>Credit institutions, financial institutions, and crypto asset service providers will be prohibited from maintaining any anonymous accounts or handling privacy-enhancing cryptocurrencies.</p></li><li><p>Customer due diligence will be mandatory for transactions above &#8364;1,000 as part of the EU&#8217;s expanded regulatory framework building on the Markets in Crypto-Assets Regulation.</p></li></ul></li><li><p>German prosecutors confiscate Bitcoin, Ether, Litecoin, and Dash worth $38.2 million from privacy-focused crypto platform eXch, which operated without AML protocols [<a href="https://www.theblock.co/post/353782/german-authorities-seize-38-million-worth-of-crypto-from-exch-exchange">The Block</a>] [<a href="https://www.presseportal.de/blaulicht/pm/7/6029813">Presse Portal</a>]</p><ul><li><p>Authorities claim approximately 1.9bn in crypto moved through eXch since 2014, with some funds originating from criminal sources, including part of 1.4 billion stolen from Bybit.</p></li><li><p>eXch operators, who announced shutdown on May 1, argue privacy is not a crime and that their &#8220;privacy-centered goals were being misinterpreted&#8221; by authorities. (See BR095 for added context on their planned shutdown after announcing a 50 BTC open-source fund to support privacy-enhancing projects: &#8220;eXch is shutting down operations and changing owners on May 1st, 2025 after learning they are the target of a transatlantic operation aiming to prosecute them for money laundering and terrorism.&#8221;)</p></li></ul></li><li><p>France now allows crypto-backed Lombard credit [<a href="https://www.bfmtv.com/crypto/bitcoin/la-france-autorise-desormais-le-credit-lombard-adosse-a-des-cryptomonnaies_AN-202505100225.html">BFMTV</a>]</p><ul><li><p>France legalizes using cryptocurrencies as collateral for euro loans starting April 30, 2025, enabling investors to access liquidity without selling their digital assets.</p></li></ul></li><li><p>U.S.: Florida lobbyist Brian Ballard faces Trump&#8217;s ire regarding the Truth Social post promoting a &#8220;Crypto Strategic Reserve&#8221; [<a href="https://www.politico.com/news/2025/05/08/ballard-trump-wiles-lobbyist-00333953">Politico</a>]</p><ul><li><p>The Truth Social incident involved a Ballard employee at Mar-a-Lago persuading Trump to promote cryptocurrency, providing him with text to post, which promoted Ripple Labs, a Ballard client.</p></li></ul></li><li><p>U.S.: Arizona Governor Katie Hobbs signs House Bill 2749 allowing the state to claim ownership of digital assets abandoned for three years and create a Bitcoin Reserve Fund [<a href="https://cointelegraph.com/news/arizona-governor-signs-bitcoin-reserve-keep-unclaimed-crypto">Coin Telegraph</a>]</p><ul><li><p>The new law follows Hobbs&#8217; veto of a similar bill citing concerns over &#8220;untested assets,&#8221; while another pending bill would allow investment of up to 10% of state funds into Bitcoin [<a href="https://cointelegraph.com/news/arizona-bitcoin-reserve-bill-vetoed-by-governor">Coin Telegraph</a>]</p></li></ul></li><li><p>U.S.: Missouri House Bill 594 passes state House vote, proposing 100% income tax deduction for capital gains as the state tax code doesn&#8217;t distinguish between capital gains and income tax [<a href="https://cointelegraph.com/news/missouri-could-become-first-state-eliminate-capital-gains">Coin Telegraph</a>]</p></li><li><p>Bhutan introduces its nation-wide digital currency tourism payment system in partnership with Binance Pay and DK Bank [<a href="https://www.binance.com/en/blog/payments/one-wallet-one-journey-bhutan-and-binance-pay-launch-worlds-first-national-tourism-payment-system-5232649784122488038">Blog post</a>]</p><ul><li><p>Over 100 local merchants accept crypto payments for services from flights and visas to street market goods, with instant settlement in local currency.</p></li></ul></li><li><p>Nigerian Government signs Investment and Securities Act 2025, bringing regulatory clarity to digital assets in Nigeria, recognizes Bitcoin as Security [<a href="https://www.forbes.com/sites/digital-assets/2025/04/30/nigerian-gov-passes-law-recognizing-bitcoin-as-a-security/">Forbes</a>]</p><ul><li><p>The new law classifies all virtual assets as securities under SEC oversight, with penalties of &#8358;20 million ($12,430) and up to 10 years imprisonment for Ponzi schemes.</p></li></ul></li></ul><h3><strong>Prosecution</strong></h3><ul><li><p>FinCEN told prosecutors Samourai Wallet developers likely didn&#8217;t need MSB license [<a href="https://www.therage.co/fincen-to-sdny-samourai-wallet-did-not-need-msb-license/">The Rage</a>]</p><ul><li><p>Recent court filing reveals FinCEN informed SDNY prosecutors that Samourai Wallet &#8220;would not qualify as a &#8216;Money Services Business&#8217; requiring a FinCEN license&#8221; six months before developers were charged.</p></li><li><p>Defense attorneys claim prosecutors &#8220;suppressed this information for over a year,&#8221; only disclosing it on April 1, 2025, after a specific Brady request for exculpatory evidence.</p></li><li><p>Update: SDNY prosecutors refuse to grant hearing requested by Samourai Wallet developers after FinCEN opinions suggesting non-custodial wallets might not need MSB licenses were withheld for nearly a year [<a href="https://www.therage.co/sdny-petitions-court-to-deny-samourai-wallet-hearing-seeking-remedy-for-withheld-evidence/">The Rage</a>]</p><ul><li><p>Prosecutors claim the withheld FinCEN statements were merely &#8220;informal, individual opinions&#8221; and &#8220;not Brady material,&#8221; while maintaining the case focuses on alleged money laundering conduct.</p></li></ul></li></ul></li><li><p>Related: New Jersey District Court dismisses charges against Christopher James Scalon, citing the DOJ&#8217;s April 7 &#8220;Ending Regulation by Prosecution&#8221; memo that discourages prosecution where &#8220;ambiguity exists.&#8221; [<a href="https://www.therage.co/districts-dropping-blanche-memo-cases-sdny-still-wont-comply/">The Rage</a>]</p><ul><li><p>Scanlon is a businessman who founded and operated Aurae Lifestyle and Club Swann, providing financial services to high-net-worth clients through various entities that allegedly functioned as an unlicensed money transmitting business between 2015 and 2019, resulting in criminal charges that have now been dismissed.</p></li><li><p>Indiana court previously dropped charges against AurumXchange operator Maximiliano Pilipis, ruling he couldn&#8217;t be held accountable for regulations that were ambiguous or non-existent at the time.</p></li></ul></li><li><p>Texas District Court rules against Treasury&#8217;s attempt to retain power to re-list Tornado Cash on sanctions list after its removal last month [<a href="https://www.therage.co/court-bans-treasury-from-sanctioning-tornado-cash/">The Rage</a>]</p><ul><li><p>Court rejects Treasury&#8217;s argument that final ruling was unnecessary, noting they &#8220;do not suggest they will not sanction Tornado Cash again.&#8221;</p></li><li><p>Fifth Circuit previously determined Treasury overstepped authority by sanctioning immutable smart contract software, stating Treasury would need Congress to amend the IEEPA.</p></li></ul></li><li><p>The DeFi Education Fund launches a <a href="https://section1960.defieducationfund.org/">petition</a> urging Trump administration to end prosecution of software developers [<a href="https://x.com/fund_defi/status/1916814129395871818">Announcement</a>]</p><ul><li><p>&#8220;The SDNY is attempting to hold software developers criminally liable for how others use their code,&#8221; contradicting previous FinCEN guidance that developers of self-custodial protocols are not money transmitters.</p></li><li><p>The petition argues this prosecution &#8220;sets a precedent that potentially chills all crypto development in the United States&#8221; and threatens technological innovation.</p></li></ul></li></ul><h4><strong>Events</strong></h4><ul><li><p><a href="https://freerouting.africa/kaduna-bootcamp/">Kaduna Lightning Developer Bootcamp</a>: A 4-day hands-on Bitcoin Lightning Developer Bootcamp</p><ul><li><p>Organized by Africa Free Routing, in partnership with Btrust, Tether, and African Bitcoiners.</p></li><li><p>14-17 May, 2025 in Kaduna, Nigeria</p></li></ul></li><li><p><a href="https://x.com/BitcoinforAI">Bitcoin for AI Conference</a>: One-day virtual conference exploring how Bitcoin meets AI</p><ul><li><p>June 21, 2025</p></li></ul></li></ul><h3><strong>Reads</strong></h3><ul><li><p>Here&#8217;s a list of our top recently published reads:</p><ul><li><p>Removing Bitcoin&#8217;s Guardrails, by BitMEX Research [<a href="https://blog.bitmex.com/removing-bitcoins-guardrails/">Blog post</a>]</p></li><li><p>Relay policy drama, by Antoine Poinsot [<a href="https://antoinep.com/posts/relay_policy_drama/">Blog post</a>]</p></li><li><p>The MEVil of Relay Policy, by Matt Corallo [<a href="https://spiralbtc.substack.com/p/the-mevil-of-relay-policy">Spiral</a>]</p></li><li><p>When Prosecutors Ignore the Regulators, by Peter Van Valkenburgh [<a href="https://www.coincenter.org/when-prosecutors-ignore-the-regulators/">Coin Center</a>]</p></li><li><p>Taplocks, Policy-Signer Wallets &amp; the Anchor Era, by Murray Rudd [<a href="https://www.murrayrudd.pro/taplocks-policy-signer-wallets-the-anchor-era/">Blog post</a>]</p></li><li><p>Decentralized Media Hosting via Blossom, by Miljan [<a href="https://njump.me/naddr1qvzqqqr4gupzp4sl80zm866yqrha4esknfwp0j4lxfrt29pkrh5nnnj2rgx6dm62qqnkgetrv4h8gunpd35h5ety94kk2erfvysxsmmnw35kueeqwe5kzgrzd3hhxum0d5aphqvq">Note</a>]</p></li></ul></li></ul><h3><strong>Episode submission ideas</strong></h3><ul><li><p>We&#8217;re looking for ideas for interesting panel conversations. To send Bitcoin related questions, just go to <a href="https://bitcoin.review/">bitcoin.review</a> and follow the contact links at the bottom of the page.</p></li></ul><h3><strong>Get in touch with the pod</strong></h3><ul><li><p><a href="https://twitter.com/bitcoinreviewhq">Podcast Twitter</a></p></li><li><p><a href="https://twitter.com/nvk">NVK Twitter</a></p></li><li><p><a href="https://t.me/BitcoinReviewPod">Telegram</a></p></li><li><p><a href="mailto:producer@coinkite.com">Email</a></p></li><li><p>Nostr &amp; LN &#9889;nvk@nvk.org (not an email!)</p></li></ul>]]></content:encoded></item><item><title><![CDATA[BR095 - OP_NEXT Recap, COLDCARD, Bitcoin Core, Ephemeral Dust, Ephemeral Anchors, Pay-to-Anchor outputs, Taplocks, Electrum, Cove Wallet, Mempool.space, Liana, ESP32.Review + MORE ft. Rob & Rijndael]]></title><description><![CDATA[I&#8217;m joined by guests Rob Hamilton & Rijndael to go through the list.]]></description><link>https://substack.bitcoin.review/p/bitcoin-review-podcast-br095-op_next</link><guid isPermaLink="false">https://substack.bitcoin.review/p/bitcoin-review-podcast-br095-op_next</guid><dc:creator><![CDATA[STACK TO THE FUTURE]]></dc:creator><pubDate>Wed, 23 Apr 2025 18:29:30 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a95ac75-ac77-4167-9383-9930a48690bb_1080x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I&#8217;m joined by guests <a href="https://twitter.com/Rob1Ham">Rob Hamilton</a> &amp; <a href="https://twitter.com/rot13maxi">Rijndael</a> to go through the list.</p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://bitcoin.review/podcast/episode-56/&quot;,&quot;text&quot;:&quot;Listen on your favorite podcast app&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://bitcoin.review/podcast/episode-56/"><span>Listen on your favorite podcast app</span></a></p><div><hr></div><h3><strong>Housekeeping</strong></h3><ul><li><p>00:01:09 OP_Next recap</p></li></ul><h3><strong>Bitcoin</strong></h3><h4><strong>Software Releases &amp; Project Updates</strong></h4><ul><li><p>00:15:18 Coldcard</p><ul><li><p>Shared Improvements - Both Mk4 <a href="https://github.com/Coldcard/firmware/releases/tag/2025-04-16T1908-v5.4.2">v5.4.2</a> and Q <a href="https://github.com/Coldcard/firmware/releases/tag/2025-04-16T1906-v1.3.2Q">v1.3.2Q</a></p><ul><li><p>New Feature: Multisig transactions are finalized when sufficiently signed. Allows use of PushTX with multisig wallets</p></li><li><p>New Feature: Signing artifacts re-export to various media. Now you have the option of exporting the signing products (transaction/PSBT) to different media than the original source. Incoming PSBT over QR can be signed and saved to SD card if desired.</p></li><li><p>New Feature: Multisig export files are signed now</p></li><li><p>Enhancement: NFC export usability upgrade: NFC keeps exporting until CANCEL/X is pressed</p></li><li><p>Enhancement: Add Bitcoin Safe option to Export Wallet</p></li><li><p>Enhancement: 10% performance improvement in USB upload speed for large files</p></li><li><p>(Q only) Enhancement: Always choose the biggest possible display size for QR</p></li></ul></li><li><p>Two New Heavyweight Features</p><ul><li><p>CCC: COLDCARD can now Co-sign like collaborative multisig HSMs, no centralized servers needed</p></li><li><p>KeyTeleport: Send secrets on a video call to other COLDCARD! Securely move seeds, secure notes/passwords, multisig PSBTs, even full backups (full clone), between two Q using QR or NFC</p></li></ul></li></ul></li><li><p>00:42:53 Bitcoin Core <a href="https://github.com/bitcoin/bitcoin/releases/tag/v29.0">v29.0</a></p><ul><li><p>Notable changes</p><ul><li><p>P2P and Network Changes</p><ul><li><p>Support for UPnP was dropped</p></li><li><p>libnatpmp was replaced with a built-in implementation of PCP and NAT-PMP</p></li><li><p>When the -port configuration option is used, the default onion listening port will now be derived to be that port + 1 instead of being set to a fixed value</p></li><li><p>Upon receiving an orphan transaction, the node will attempt to download missing parents from all peers who announced the orphan</p></li></ul></li><li><p>Mempool Policy and Mining Changes</p><ul><li><p>Ephemeral dust is a new concept that allows a single dust output in a transaction, provided the transaction is zero fee</p></li></ul></li><li><p>Updated RPCs</p><ul><li><p>The RPC <code>testmempoolaccept</code> response now includes a <code>reject-details</code> field in some cases, similar to the complete error messages returned by <code>sendrawtransaction</code></p></li><li><p>Duplicate blocks submitted with <code>submitblock</code> will now persist their block data even if it was previously pruned</p></li><li><p><code>getmininginfo</code> now returns <code>nBits</code> and the current target in the <code>target</code> field. It also returns a <code>next</code> object which specifies the <code>height</code>, <code>nBits</code>, <code>difficulty</code>, and <code>target</code> for the next block</p></li><li><p><code>getblock</code> and <code>getblockheader</code> now return the current target in the <code>target</code> field</p></li><li><p><code>getblockchaininfo</code> and <code>getchainstates</code> now return <code>nBits</code> and the current target in the <code>target</code> field</p></li><li><p>the <code>getblocktemplate</code> RPC <code>curtime</code> (BIP22) and <code>mintime</code> (BIP23) fields now account for the timewarp fix proposed in BIP94 on all networks</p></li></ul></li><li><p>New RPCs</p><ul><li><p><code>getdescriptoractivity</code> can be used to find all spend/receive activity relevant to a given set of descriptors within a set of specified blocks</p></li></ul></li><li><p>Updated Settings</p><ul><li><p>The maximum allowed value for the <code>-dbcache</code> configuration option has been dropped due to recent UTXO set growth</p></li><li><p>Starting with v28.0, the <code>-mempoolfullrbf</code> startup option was set to default to <code>1</code>. With widespread adoption of this policy, users no longer benefit from disabling it, so the option has been removed, making full replace-by-fee the standard behavior</p></li><li><p>Setting <code>-upnp</code> will now log a warning and be interpreted as <code>-natpmp</code>. Consider using <code>-natpmp</code> directly instead</p></li><li><p>As a safety check, Bitcoin core will <strong>fail to start</strong> when <code>-blockreservedweight</code> init parameter value is lower than <code>2000</code> weight units. Bitcoin Core will also <strong>fail to start</strong> if the <code>-blockmaxweight</code> or <code>-blockreservedweight</code> init parameter exceeds consensus limit of <code>4,000,000 WU</code></p></li></ul></li><li><p>Build System</p><ul><li><p>The build system has been migrated from Autotools to CMake</p></li></ul></li></ul></li></ul></li><li><p>00:47:21 BDK <a href="https://github.com/bitcoindevkit/bdk/releases/tag/wallet-1.2.0">v1.2.0</a></p><ul><li><p>TxBuilder <code>add_recipient</code> function now accepts anything that implements <code>Into&lt;ScriptBuf&gt;</code></p></li><li><p>The wallet considers a coinbase output eligible for selection if it will mature in the next block</p></li><li><p>Wallets persisted with a <code>rusqlite::Connection</code> are checked to be thread-safe</p></li><li><p>The <code>bdk_chain</code> dependency is updated to version 0.21.1, plus a number of internal cleanups</p></li></ul></li><li><p>00:48:12 Coinswap <a href="https://github.com/citadel-tech/coinswap/releases/tag/v0.1.1">v0.1.1</a></p><ul><li><p>Core Protocol &amp; Performance Improvements</p><ul><li><p>UTXO Management: A major source of latency due to frequent Core RPC calls have been removed by having custom in-memory UTXO indexes. These maps are also persisted in the disk, reducing wallet sync time.</p></li><li><p>Coin Selection: State of art coin-selection algorithms, similar to Bitcoin Core, is integrated, making various kind of tx creation more efficient.</p></li><li><p>Fidelity Management: Fidelity bond management tasks, like bond expiry checks, redemtion, recreation, is now automated in the maker servers. Reducing user responsibilities of managing Fidelity Bonds.</p></li><li><p>Taker Liveness: A new message WaitingFundingConfirmation have been introduced to mainatin swap connections between Takers and Makers to handle variable block confirmation delay</p></li></ul></li><li><p>User Experience &amp; Compatibility</p><ul><li><p>Compatibility: The crate and the apps are now fully compatible with Mac</p></li><li><p>Tor: Tor operation is streamlined providing faster and more resilient tor connections. Tor addresses are now deterministically linked with the wallet seed, ensuring constant onion address across system reboots</p></li><li><p>UI/UX: Improved display of various user facing structures like, balances, utxos, offer data, fidelity bonds and overall improvements in system logs. Making the apps more fun to play with</p></li><li><p>API Design: Streamlined various transaction creation routines to use a single common API. Reducing technical debts and removing redundant code</p></li><li><p>Protocol Spec Documentation: Details how CoinSwap breaks the transaction graph and improves privacy through routed swaps and amount splitting. Includes diagrams for clarity</p></li></ul></li></ul></li><li><p>00:48:56 Electrum Wallet</p><ul><li><p><a href="https://github.com/spesmilo/electrum/pull/9675">NIP47 plugin</a></p><ul><li><p>Implements Nostr Wallet Connect (NIP47) plugin, which supports remote control of Electrum lightning wallet through Nostr protocol as a plugin with CLI and QT gui compatibility.</p></li><li><p>Users can set a 24-hour budget and connection expiry date when connecting Electrum as a funding source for clients like Amethyst, Alby, Bitbanana, and lnbits.</p></li></ul></li><li><p><a href="https://github.com/spesmilo/electrum/pull/9718">Userspace plugins</a></p><ul><li><p>The next release of Electrum Wallet will make it possible to install plugins developed and distributed by third-parties.</p></li></ul></li></ul></li><li><p>00:52:45 BTCPay Server <a href="https://github.com/btcpayserver/btcpayserver/releases/tag/v2.1.0">v2.1.0</a></p><ul><li><p>Add better MultiSig flow when all users are using BTCPay Server</p></li><li><p>Remove ZCash and Monero from core code</p></li><li><p>Disable cold wallet creation by default</p></li><li><p>Add support for RBF and improve UX for CPFP</p></li><li><p>Greenfield: Add <code>refundBOLT11Expiration</code> to Get/Update store endpoint</p></li><li><p>Greenfield: Add <code>invitationLink</code> and <code>disabled</code> properties to user APIs</p></li></ul></li><li><p>00:53:33 Nunchuk Android</p><ul><li><p><a href="https://github.com/nunchuk-io/nunchuk-android/releases/tag/android.1.67">v1.9.67</a></p><ul><li><p>Option to disable key path spending in Taproot/MuSig2 multisig wallets</p></li><li><p>Fee estimates for key path spend versus script path spend</p></li><li><p>Option to export transaction history to CSV file</p></li><li><p>Option to create a Software key now and back up later</p></li><li><p>Fee settings</p></li></ul></li><li><p><a href="https://github.com/nunchuk-io/nunchuk-android/releases/tag/android.1.9.66">v1.9.66</a></p><ul><li><p>New and improved encrypted group wallet</p></li></ul></li></ul></li><li><p>00:54:04 Liana <a href="https://github.com/wizardsardine/liana/releases/tag/v10.0">v10.0</a></p><ul><li><p>This version does not introduce any breaking changes in the database schema</p></li><li><p>Two new features are implemented: Backup and Third party keys fetching during the install</p></li><li><p>Liana GUI</p><ul><li><p>During the install process, the xpub of a key provider can be fetch from a Wizardsardine service by entering a token</p></li><li><p>This Xpub can be used as a &#8220;Safety Net&#8221;, a paid product where a third party keeps a recovery key for you in case you lose your access to your funds</p></li><li><p>We changed the default value of the &#8220;standard&#8221; recovery paths to ~1y, so the safety net can be quickly set with the maximum timelock without conflicting with an other recovery path</p></li><li><p>Due to rust-miniscript compiler changes, for the same keys setup the output descriptor may differ from one generated by a v9 Liana. Both descriptors are supported by Liana v9 and v10 versions</p></li><li><p>A new backup system for wallet configurations, including descriptors, has been introduced</p></li><li><p>Users can now back up their wallet configurations by downloading a file during the wallet creation process</p></li><li><p>They can also update their backup (for changes in labels, aliases, etc.) by downloading it from the Wallet settings</p></li><li><p>This backup file can be used to restore the wallet or keep it synchronized across different devices</p></li><li><p>This backup does not include hot keys (computer generated mnemonics)</p></li><li><p>A new &#8220;Export/Import&#8221; section will be available in the settings, consolidating all export and import options</p></li><li><p>This section will include the backup and restore wallet functions, as well as new features like &#8220;Export Labels&#8221; and &#8220;Export Descriptor.&#8221;</p></li><li><p>The export of labels adheres to the BIP329 standard, both in the wallet backup and the &#8220;Export Labels&#8221; function</p></li><li><p>Replace by fee action can now be executed on transactions without any related PSBT in the database</p></li></ul></li></ul></li><li><p>00:54:51 The Mempool Open Source Project <a href="https://github.com/mempool/mempool/releases/tag/v3.2.0">v3.2.0</a></p><ul><li><p>Highlights:</p><ul><li><p>Support for v3 transactions</p></li><li><p>Support for anchor outputs</p></li><li><p>New UTXO bubble chart on the address page</p></li><li><p>DATUM miner tags</p></li><li><p>Tags to identify runestone messages and inscriptions</p></li><li><p>Package broadcast</p></li><li><p>Stratum job data visualizations</p></li><li><p>Taproot multisig labels</p></li><li><p>Transaction &amp; PSBT preview feature</p></li><li><p>Address poisoning detection</p></li><li><p>And more</p></li></ul></li></ul></li><li><p>Cove <a href="https://github.com/bitcoinppl/cove/releases/tag/v0.3.0">v0.3.0</a></p><ul><li><p>Upgrade BIP329</p></li><li><p>Check for the next 30 addresses for txns even if not revealed</p></li><li><p>TAPSIGNER setup initial pin</p></li><li><p>TAPSIGNER import already initialized card</p></li><li><p>TAPSIGNER change PIN</p></li><li><p>TAPSIGNER create download backup</p></li><li><p>Readable card ident</p></li><li><p>Sign PSBT using TAPSIGNER</p></li><li><p>Watch for changes on unconfirmed txns</p></li></ul></li><li><p>00:57:01 BoltzExchange boltz-web-app <a href="https://github.com/BoltzExchange/boltz-web-app/releases/tag/v1.7.3">v1.7.3</a></p><ul><li><p>Include rescue key in backup</p></li><li><p>Add Portuguese translations</p></li><li><p>Improve UX for copying address/invoice on click</p></li></ul></li><li><p>00:57:16 RoboSats <a href="https://github.com/RoboSats/robosats/releases/tag/v0.7.6-alpha">v0.7.6</a></p><ul><li><p>For Users</p><ul><li><p>Dispute statement now requires a contact method to be submitted</p></li><li><p>Coordinator rating over nostr (BETA)</p></li><li><p>Token input now clears up blank spaces</p></li><li><p>Add some messages to the trade workflow to answer the most common questions</p></li></ul></li><li><p>For Coordinators</p><ul><li><p>Add cancel_status param to the cancel order action</p></li></ul></li></ul></li><li><p>00:57:21 Bitcoin Safe</p><ul><li><p><a href="https://github.com/andreasgriffin/bitcoin-safe/releases/tag/1.2.3">v1.2.3</a></p><ul><li><p>Expand QR SignMessage Compatibility: SignMessage now supports all QR-UR-compatible hardware signers, including SpecterDIY, KeyStone, Passport, and Jade (additional to previous supported Coldcard Q)</p></li><li><p>Wallet Import via QR: Add the ability to import wallet-export-files via QR code, ensuring compatibility with Keystone&#8217;s latest firmware</p></li></ul></li><li><p><a href="https://github.com/andreasgriffin/bitcoin-safe/releases/tag/1.2.2">v1.2.2</a></p><ul><li><p>Add Address poisoning detection and warning</p></li><li><p>Nostr sync&amp;chat alias now also appears in share menu of the TX/PSBT</p></li></ul></li></ul></li><li><p>00:57:58 Blockstream Green</p><ul><li><p>Android <a href="https://github.com/Blockstream/green_android/releases/tag/release_4.1.8">v4.1.8</a></p><ul><li><p>Add Language preference in App Settings</p></li><li><p>Enable Android data backup for disaster recovery</p></li><li><p>Allow setting custom Electrum gap limit with default server</p></li></ul></li><li><p>iOS <a href="https://github.com/Blockstream/green_ios/releases/tag/release_4.1.8">v4.1.8</a></p><ul><li><p>Rename L-BTC to LBTC</p></li><li><p>Improve notifications translations</p></li><li><p>Persist wallet list across app reinstallation</p></li><li><p>Reduce login time</p></li><li><p>Improve background lightning payments</p></li></ul></li></ul></li><li><p>00:58:08 Rust Payjoin <a href="https://github.com/payjoin/rust-payjoin/releases/tag/payjoin-0.23.0">v0.23.0</a></p><ul><li><p>This release features a first-class persistence abstraction, wire protocol changes for RFC 9540 support, and better compliance with the BIP78 specification. It also pays back a whole bunch of tech debt including enhanced error handling, expanded functionality with new modules and additive features, and improved test infrastructure. There are breaking API and protocol changes as a result.</p></li><li><p>Changelog</p><ul><li><p>Make features additive</p></li><li><p>Make receiver errors replyable to the sender</p></li><li><p>Introduce &#8220;directory&#8221; feature module</p></li><li><p>Accomodate updated BIP78 spec</p></li><li><p>Introduce experimental multiparty sender behind the &#8220;_multiparty&#8221; feature flag</p></li><li><p>Add support for RFC 9540</p></li><li><p>Add first-class persistence abstraction</p></li><li><p>Add many more tests, significantly improving test coverage</p></li></ul></li></ul></li><li><p>01:01:15 Zaprite <a href="https://help.zaprite.com/en/articles/11080992-zaprite-release-notes-2025-04-14">v2025.04.14</a></p><ul><li><p>Added</p><ul><li><p>Client Updates: Add new messaging in the browser to alert users when a new version of Zaprite is available</p></li><li><p>API: Add a new disablePaymentNotifs option to our API Order creation fields</p></li></ul></li><li><p>Changed</p><ul><li><p>New Organizations: Add the Organization Name field to the New Organization form to make it easier to identify Organizations after being created</p></li></ul></li></ul></li><li><p>01:01:41 ESP Miner <a href="https://github.com/bitaxeorg/ESP-Miner/releases/tag/v2.6.1">v2.6.1</a></p><ul><li><p>New Features</p><ul><li><p>Wi-Fi</p><ul><li><p>SSID WiFi lookup</p></li><li><p>Expose Wifi RSSI to API endpoint</p></li><li><p>Init AxeOS AP mode</p></li></ul></li><li><p>User Interface (UI)/Display</p><ul><li><p>feat: add tooltip for pwm invert and flip screen by @WantClue (#709)</p></li><li><p>Add sorting switch to swarm page for hostname and ip</p></li><li><p>Show share reject reasons</p></li><li><p>Add asic failure status screen</p></li></ul></li><li><p>Mining/Pool/Stratum</p><ul><li><p>Keep old pool config synchronized until reboot</p></li><li><p>Add support for extranonce2_len&lt;4</p></li><li><p>Improve pool fallback code</p></li><li><p>Update confusing connect to pool log message</p></li><li><p>Refactor Stratum code for Seamless Failover</p></li></ul></li><li><p>Hardware/Power/Overclocking</p><ul><li><p>Use url params to unlock overclock</p></li><li><p>Overclock url params</p></li><li><p>GammaTurbo support and HW abstraction</p></li><li><p>Create TPS546 VCORE alerts</p></li><li><p>Get combined current (power) for multi-phase TPS546</p></li></ul></li><li><p>And more: API/Backend, Development/Build/Testing, Configuration/System, Documentation/Miscellaneous, and Fan Control.</p></li></ul></li></ul></li><li><p>01:01:48 Krux <a href="https://x.com/odudex/status/1910020450555408558">Update</a></p><ul><li><p>Krux achieves first air-gapped PGP signature using secp256r1 NIST P256 curve, which requires a coordinator for metadata support.</p></li><li><p>The developer chose secp256r1 for &#8220;size and efficiency for running on microcontrollers&#8221; after abandoning RSA due to processing-intensive steps.</p></li></ul></li><li><p>01:02:29 Iris Wallet Desktop <a href="https://github.com/RGB-Tools/iris-wallet-desktop/releases/tag/0.2.0">v0.2.0</a></p><ul><li><p>RLN Node Compatibility: The app now checks if the RLN node version is compatible at startup</p></li><li><p>Backup and Restore Improvements: Backup and restore now use a temporary folder, which gets deleted automatically after the process finishes</p></li><li><p>Error Reporting: Add an error dialog to report issues when unlocking the node</p></li><li><p>Data Directory Separation: Separate data storage paths for the application and the RLN node</p></li><li><p>Logs Cleanup: Remove unnecessary QProcess logs of the RLN node to reduce logs</p></li><li><p>GitHub Actions Update: Update GitHub Actions workflow to build the RLN node using a specific commit ID</p></li></ul></li><li><p>01:02:46 Bitcoin Core Config Generator <a href="https://jlopp.github.io/bitcoin-core-config-generator/">Update</a></p><ul><li><p>Now compatible with Bitcoin Core v29.0</p></li></ul></li><li><p>01:02:52 UTXOracle is <a href="https://x.com/stevesimple/status/1909982476895715802">Now live</a></p></li></ul><h4><strong>Project spotlight</strong></h4><ul><li><p>01:04:14 <a href="https://gist.github.com/RubenSomsen/a61a37d14182ccd78760e477c78133cd">SwiftSync</a>: Smarter synchronization with hints [<a href="https://groups.google.com/g/bitcoindev/c/FpSWUxItXQs">Discussion</a>]</p><ul><li><p>SwiftSync provides near-stateless, fully parallelizable validation of the Bitcoin blockchain using hints about unspent outputs (&lt;100MB total), verifying validity through a hash aggregate that equals zero when successful.</p></li><li><p>Unlike traditional Bitcoin Core validation, SwiftSync eliminates database lookups, reduces memory usage, and enables parallel processing.</p></li></ul></li><li><p>01:04:43 PrivatePond: A Bitcoin Payjoin application to optimize transaction rails for services, such as deposits, withdrawals, and automated wallet rebalancing [<a href="https://github.com/Kukks/PrivatePond">Github</a>]</p><ul><li><p>Private Pond optimizes Bitcoin transactions by queuing withdrawals and processing them at fixed intervals, enabling batching while user deposits can fund withdrawals through Meta Payjoin, reducing hot wallet liquidity requirements.</p></li></ul></li><li><p>01:05:00 <a href="https://m0wer.github.io/joinmarket-fidelity-bond-simulator/">JoinMarket Fidelity Bond Simulator</a>: A tool for JoinMarket makers to evaluate their competitive position in the market based on fidelity bonds [<a href="https://github.com/m0wer/joinmarket-fidelity-bond-simulator">Github</a>]</p><ul><li><p>Features include simulating maker selection probability using real orderbook data, calculating bond values based on amount and lock time, and comparing different bond strategies.</p></li></ul></li><li><p>01:05:52 DahLIAS: Discrete Logarithm-Based Interactive Aggregate Signatures [<a href="https://eprint.iacr.org/2025/692.pdf">Research paper</a>]</p><ul><li><p>DahLIAS allows multiple signers to produce a single constant-size signature that verifies all messages simultaneously.</p></li><li><p>The scheme features a two-round signing protocol with possible preprocessing and verification that is asymptotically twice as fast as batch verification of individual Schnorr signatures.</p></li><li><p>DahLIAS supports key tweaking for Bitcoin applications and is proven secure under the algebraic one-more discrete logarithm assumption in the random oracle model.</p></li></ul></li><li><p>01:06:00 <a href="https://scrow.exchange/">Satoshi Escrow (scrow)</a>: A Bitcoin non-custodial peer-to-peer dispute resolution using only Nostr keys [<a href="https://github.com/storopoli/scrow">Github</a>]</p><ul><li><p>Satoshi Escrow offers Bitcoin transactions through 2-of-2 multisig addresses where buyers and sellers lock BTC using only their Nostr keys (nsec/npub)</p></li><li><p>The system utilizes Pay-to-Taproot multisig technology and can be used offline on air-gapped computers</p></li></ul></li><li><p>01:06:12 Taplocks: Verifiable but Unspendable Tapleafs via Hashlock Mechanism</p><ul><li><p>A recent proposal introduces Taplocks, a method to enforce unspendability of Taproot script paths containing OP_SUCCESS before opcode activation. The technique prevents premature spending while allowing smooth migration to new opcodes (e.g., CAT, CTV, or OP_WASM).</p></li><li><p>Key Mechanism:</p><ul><li><p>Problem: Post-Taproot, OP_SUCCESS makes any script containing it immediately spendable, even before intended opcode activation.</p></li><li><p>Solution: A hashlock-like construct is applied over the script (not within it) using SHA-256 length extension.</p></li></ul></li><li><p>The oracle pre-images a secret, which must be revealed to construct a valid spending script.</p></li><li><p>A ZKP (e.g., STARK) proves the script header contains only a data push and padding, ensuring no hidden malicious logic.</p></li><li><p>Benefits:</p><ul><li><p>Eliminates manual UTXO migration post-activation.</p></li><li><p>Maintains security under the same trust assumptions as signing oracles.</p></li></ul></li><li><p><a href="https://x.com/rot13maxi/status/1909252898170564621">Rijndael Explainer</a></p></li><li><p>Full technical details available on <a href="https://github.com/taproot-wizards/taplocks/blob/main/README.md">Github</a>.</p></li></ul></li><li><p><a href="https://censorshipresistant.com/">Censorship Resistance Threshold</a>: A calculator estimating how many guerrilla miners are required to secure Bitcoin against censorship</p><ul><li><p>The tool factors in existing guerrilla hashrate and calculates additional miners needed to reach the critical 51% threshold for censorship resistance.</p></li></ul></li><li><p>01:15:48 <a href="https://bitcoin.softforks.org/">bitcoin.softforks.org</a>: Easily compare various features, facts, and figures for the many soft fork proposals under consideration [<a href="https://github.com/john-light/bitcoin.softforks.org">Github</a>]</p><ul><li><p>The website serves as a research database educating the Bitcoin community about active soft fork proposals and helping evaluate them comparatively.</p></li></ul></li><li><p>01:15:52 CTV and CSFS Enabled Bitcoin Node: Mutiny Signet Docker Setup [<a href="https://github.com/arshbot/ctv-csfs-signet-docker">Github</a>]</p><ul><li><p>&#8220;A Docker-based Bitcoin node configured with CheckTemplateVerify (CTV) and CheckSigFromStack (CSFS) capabilities enabled.&#8221;</p></li><li><p>&#8220;This node runs on a special signet (MutinyNet) that allows developers to test and build applications using these proposed Bitcoin protocol upgrades.&#8221;</p></li></ul></li><li><p>01:16:03 UTXOscope: A text-only BTC price heatmap built only from UTXOs, inspired by UTXOracle [<a href="https://github.com/Drew72-ita/UTXOscope">Github</a>]</p><ul><li><p>UTXOscope analyzes newly created UTXOs to visualize Bitcoin price trends without relying on external exchanges or price feeds.</p></li></ul></li><li><p>01:16:13 <a href="https://bitcoin.block.xyz/">Block Bitcoin Treasury</a>: A visualization of Block&#8217;s Bitcoin treasury holdings [<a href="https://github.com/block/bitcoin-treasury">Github</a>]</p><ul><li><p>Block <a href="https://block.xyz/inside/block-releases-open-source-tools-for-bitcoin-treasury-management">launches</a> a bitcoin corporate holdings dashboard with BTC-to-USD real-time price quote API on GitHub, enabling companies to track bitcoin treasury assets.</p></li></ul></li><li><p>01:16:47 <a href="https://www.waye.dev/">Waye</a>: A website to discover tools, programs, and support systems designed to help open-source developers thrive. Waye empowers builders to stay clear-headed, motivated, and aligned for long-term impact [<a href="https://github.com/waye-dev/website">Github</a>]</p><ul><li><p>The OS Waye Foundation operates as a 501(c)(3) nonprofit providing tools, research, and frameworks to support open-source developers in the decentralized ecosystem.</p></li></ul></li><li><p>01:17:08 <a href="https://sovereigncraft.com/">Sovereign Craft</a>: A bitcoin-based Minecraft server offering an educational gaming experience</p><ul><li><p>Sovereign Craft is a Minecraft server integrating Bitcoin as in-game currency that functions in the real world through custom wallets powered by LNBits</p></li></ul></li></ul><h3><strong>(Not) a Vulnerability Disclosure</strong></h3><ul><li><p>01:17:17 Pay-to-Anchor outputs now exploited for blockchain spam [<a href="https://x.com/mononautical/status/1911572337436336341">Twitter post</a>]</p><ul><li><p>Pay-to-Anchor outputs in Bitcoin&#8217;s Lightning Network, designed to allow fee adjustments for channel closures, are being used to spam the blockchain with low-value transactions.</p></li></ul></li></ul><h3><strong>Vulnerability Disclosures</strong></h3><ul><li><p>01:18:10 CVE-2025-27840: New ESP32 vulnerability threatens Bitcoin security? [<a href="https://securityonline.info/cve-2025-27840-how-a-tiny-esp32-chip-could-crack-open-bitcoin-wallets-worldwide/">Daily CyberSecurity</a>]</p><ul><li><p>Researchers at Crypto Deep Tech discover a cryptographic vulnerability in ESP32 microcontrollers that could put of IoT devices and Bitcoin-related hardware at risk.</p></li><li><p>Six major flaws are identified, including invalid private key acceptance, weak random number generation, and signature forgery capabilities, with researchers demonstrating a successful attack recovering a private key from a wallet.</p></li></ul></li><li><p>01:20:49 Breaking ECDSA with two affinely related nonces [<a href="https://eprint.iacr.org/2025/705">Research paper</a>]</p><ul><li><p>Researchers demonstrate a new vulnerability in ECDSA where private keys can be compromised when two nonces have an affine relationship, even if they are distinct and used for the same message.</p></li><li><p>The attack method requires only two signatures and uses algebraic techniques without needing lattice reduction or brute-force searches when the relationship between nonces is known.</p></li><li><p>Additional resource: Why Schnorr signatures should be preferred over ECDSA [<a href="https://alinush.github.io/schnorr-vs-ecdsa">Schnorr vs. ECDSA</a>]</p></li></ul></li><li><p>01:21:02 Chinese SHOWJI phones contain pre-installed malware targeting cryptocurrency users [<a href="https://thehackernews.com/2025/04/chinese-android-phones-shipped-with.html">The Hacker News</a>]</p><ul><li><p>Cheap Chinese Android phones, particularly SHOWJI brand models, ship with pre-installed trojanized apps disguised as WhatsApp and Telegram that swap cryptocurrency wallet addresses during conversations.</p></li><li><p>The malware campaign has stolen approximately $1.6 million in cryptocurrency over two years, with attackers using about 30 domains and 60 command-and-control servers to manage the operation.</p></li></ul></li><li><p>01:21:44 X users discover hidden data access beyond official API [<a href="https://securityexpress.info/hidden-twitter-data-users-uncover-access-to-dms-and-more/">Security Express</a>]</p><ul><li><p>Users access hidden X data through browser developer tools by filtering network requests for &#8220;UserByScreenName&#8221; responses, revealing comprehensive datasets for public accounts.</p></li><li><p>The technique exposes sensitive metadata including NSFW flags, regional restrictions, and &#8220;protected&#8221; account status, plus access to direct messages including from blocked or deleted users.</p></li></ul></li></ul><h3><strong>Audience Questions</strong></h3><ul><li><p>Thanks to everyone who sent in questions. Remember to send yours to questions@bitcoin.review.</p><ul><li><p>01:23:46 &#8220;How do we use open time stamps for transfer of assets using two party integrity between holders?&#8221; -@AVERAGE_GARY</p></li><li><p>01:24:50 &#8220;Does Cove have testnet4?&#8221; -@AVERAGE_GARY</p></li><li><p>01:25:15 &#8220;Can you explain like I&#8217;m 5 what opcodes are, how they are used on the network, and the level of optionality that applies to them?&#8221; -@anon</p></li><li><p>01:26:49 &#8220;Please discuss this idea: Block-based TOTP for bitcoin wallet passphrase validation [<a href="https://njump.me/nevent1qvzqqqqqqypzpyrraa4eymelf5xndvxcwxvvs8p7qxluxy0zvrk9rxmlat73axsfqyt8wumn8ghj7etyv4hzumn0wd68ytnvv9hxgtcprpmhxue69uhkv6tvw3jhytnwdaehgu3wwa5kuef0qqsf3fx3wfzv58t87e6yjcp8hseh0t5crgwvaqtkc3zd5cwr6fctdnscncwqy">Note</a>]&#8221; -@anon</p></li></ul></li></ul><h3><strong>Privacy &amp; Other Related Bitcoin Projects</strong></h3><h4><strong>Software Releases &amp; Project Updates</strong></h4><ul><li><p>01:28:48 Tor Browser <a href="https://blog.torproject.org/new-release-tor-browser-145/">v14.5</a></p><ul><li><p>Connection Assist now on Android</p></li><li><p>Add Belarusian, Bulgarian &amp; Portuguese</p></li><li><p>Improve log readability</p></li><li><p>Better performance when quitting the app</p></li></ul></li><li><p>01:28:51 TailsOS</p><ul><li><p><a href="https://tails.net/news/version_6.14.2/">v6.14.2</a></p><ul><li><p>Update Linux to 6.1.133, which fixes multiple security vulnerabilities that may lead to a privilege escalation or information leaks.</p></li><li><p>Update perl to 5.36.0-7+deb12u2, which fixes a heap-based buffer overflow vulnerability, which may result in denial of service, or potentially the execution of arbitrary code.</p></li></ul></li><li><p><a href="https://tails.net/news/version_6.14.1/">v6.14.1</a></p><ul><li><p>Improve confinement technology used to protect files from possible security vulnerabilities in Tor Browser.</p><ul><li><p>With Tails 6.14.1, you can safely access any folder in your Home folder or Persistent Storage from Tor Browser.</p></li></ul></li></ul></li></ul></li><li><p>01:28:53 NymVPN <a href="https://nym.com/blog/nymvpn-v2025.6">v2025.6</a> - Rhubarb release</p><ul><li><p>Connection</p><ul><li><p>Connection times have been reduced by registering Wireguard keys entry and exit gateways in parallel to improve NymVPN connection times</p></li><li><p>An always-on kill switch toggle has been added to settings so you can be sure unprotected traffic is blocked</p></li><li><p>NymVPN for Linux, macOS and Windows will launch without network connectivity to improve connection time by using available networks and caching the network environment between app run times</p></li></ul></li><li><p>Improve in-app assistance</p></li><li><p>Improvements to existing features</p><ul><li><p>Linux and Windows: Auto-start for NymVPN and nym-vpnd at device startup</p></li><li><p>Mixnet mode enhancements: New changes to ensure privacy and improve performance in Anonymous Mode (e.g., with fixes to Poisson delays, backpressure, SURBs)</p></li></ul></li></ul></li><li><p>01:28:55 MapleAI [<a href="https://blog.trymaple.ai/maple-ai-desktop-apps-now-available-for-macos-and-linux/">Update</a>]</p><ul><li><p>Maple AI chat product is now available as native apps for macOS and Linux users, offering end-to-end encryption, secure enclaves, and cross-device syncing.</p></li></ul></li></ul><h4><strong>Project spotlight</strong></h4><ul><li><p>01:28:59 Git With Me: Peer-to-peer, encrypted, ephemeral Git collaboration (git daemon with encryption) [<a href="https://git.sr.ht/~meejah/git-withme">Code repository</a>]</p><ul><li><p>Git withme provides a way for a single host to invite numerous peers with short, one-time secure codes. The peers connect directly via Dilated Magic Wormhole channels, allowing collaborators to git clone git://localhost/.</p></li></ul></li></ul><h3><strong>Lightning + L2+</strong></h3><h4><strong>Project spotlight</strong></h4><ul><li><p>01:29:17 Misty Breez: A hybrid Lightning and Liquid network wallet built with the Nodeless Breez SDK [<a href="https://github.com/breez/misty-breez">Github</a>]</p><ul><li><p>The wallet supports multiple payment options including BOLT 11/12 invoices, LNURL-Pay, Lightning Addresses, BTC addresses, and offline payments via mobile notifications.</p></li></ul></li><li><p>01:29:25 <a href="https://sovereigntools.com/">Sovereign Tools</a>: A comprehensive Bitcoin and Lightning Network wallet comparison tool built with React, Express, and TypeScript [<a href="https://github.com/gustavojfe/sovereigntools">Github</a>]</p><ul><li><p>The platform currently evaluates 18 Lightning Network wallets across 43 features including platform availability, invoice compatibility, payment routing, and privacy features.</p></li></ul></li><li><p>01:29:28 <a href="https://silkroadonlightning.com/">Silk Road on Lightning</a>: A marketplace for legal items and services using Bitcoin on the Lightning Network</p><ul><li><p>The platform requires no KYC for registration, withdrawals, or purchases.</p></li><li><p>Sellers receive all payments in Bitcoin through the Lightning Network, even when buyers pay in USD. The platform automatically converts USD payments to Bitcoin.</p></li></ul></li><li><p>01:29:37 <a href="https://decode.8333.space/">Cashu Token Decoder</a>: A web tool for parsing and editing Cashu tokens</p></li></ul><h4><strong>Software Releases &amp; Project Updates</strong></h4><ul><li><p>CLN <a href="https://github.com/ElementsProject/lightning/releases/tag/v25.02.1">v25.02.1</a> - Onion Packet Filler Accreditation II</p><ul><li><p>Several bug-fixes were addressed in this release, including:</p><ul><li><p>wallet: we could miss our own returned outputs on mutual closes if our peer didn&#8217;t support <code>option_shutdown_anysegwit</code></p></li><li><p><code>lightningd</code> now properly handles duplicate HTLCs on closing and no longer spams the log</p></li><li><p>Unilateral closes now calculate fees with the correct HTLC timeout and no longer pay egregious fees</p></li><li><p><code>topology</code> crash on invoice creation if a peer had a really high feerate</p></li><li><p><code>make</code> cleans up the old clnrest directory prior to building and installing the new rust version of the plugin</p></li></ul></li></ul></li><li><p>LNbits <a href="https://github.com/lnbits/lnbits/releases/tag/v1.0.0">v1.0.0</a> - Alan Bits</p><ul><li><p>Key Highlights</p><ul><li><p>LNbits now at v1.0.0: the software is stable, hardened, and production-ready</p></li><li><p>Vue 3 migration: a complete frontend overhaul for performance and long-term maintainability</p></li><li><p>WebSocket payments: faster and more efficient, replacing older SSE and long-polling methods</p></li><li><p>New lnbits.sh install script: simplifies setup and local deployment</p></li><li><p>Access Control Lists (ACL): token-based permissions for powerful role and scope control</p></li><li><p>Admin tools:</p><ul><li><p>Admin payments overview</p></li><li><p>Toggle outgoing payments</p></li><li><p>View payments from deleted wallets</p></li></ul></li><li><p>NWC (Nostr Wallet Connect) support</p></li><li><p>Login with Nostr or OAuth: expanding integration and authentication options</p></li></ul></li></ul></li><li><p>01:29:48 Zeus</p><ul><li><p><a href="https://github.com/ZeusLN/zeus/releases/tag/v0.10.1">v0.10.1</a></p><ul><li><p>NameDesc/bLIP-11 support: add receiver name to invoices</p></li><li><p>Locales: Hindi</p></li><li><p>UI: Add dynamic background/text colors to Android NFC modal</p></li></ul></li><li><p><a href="https://x.com/ZeusLN/status/1907084936856662061">v0.11.0</a> - Rolling out to community sponsors and contributors</p><ul><li><p><a href="https://github.com/ZeusLN/zeus/pull/2946">PR #2946</a> introduces support for Cashu</p><ul><li><p>Add support for an optional Cashu ecash wallet for Embedded LND users</p></li><li><p>Add support for all backends to sweep Cashu tokens to self-custody</p></li><li><p>New Cashu Lightning addresses added alongside our existing Zaplocker address (switch between as you wish)</p></li><li><p>New ZEUS Pay+ service for premium features, incl. custom handles, web POS, early access, LSP discounts</p></li><li><p>Modal messages to prompt users to upgrade to self-custody</p></li></ul></li></ul></li></ul></li><li><p>01:29:49 LDK <a href="https://github.com/lightningdevkit/rust-lightning/releases/tag/v0.1.2">v0.1.2</a> - &#8220;Foolishly Edgy Cases&#8221;</p><ul><li><p>API Updates</p><ul><li><p><code>lightning-invoice</code> is now re-exported as <code>lightning::bolt11_invoice</code></p></li></ul></li><li><p>Performance Improvements</p><ul><li><p><code>rapid-gossip-sync</code> graph parsing is substantially faster, resolving a regression in 0.1</p></li><li><p><code>NetworkGraph</code> loading is now substantially faster and does fewer allocations, resulting in a 20% further improvement in <code>rapid-gossip-sync</code> loading when initializing from scratch</p></li><li><p><code>ChannelMonitors</code> for closed channels are no longer always re-persisted immediately after startup, reducing on-startup I/O burden</p></li></ul></li></ul></li><li><p>LNDg <a href="https://github.com/cryptosharks131/lndg/releases/tag/v1.10.0">v1.10.0</a></p><ul><li><p>Improve performance with LND using an updated forwards query</p></li><li><p>AutoFees now uses aggregated pubkey metrics for those that have multiple channels with the same peer</p></li><li><p>New metrics page: Unprofitable/Stuck Channels</p></li><li><p>Automates inbound fee updates when using AutoFees (enable with AF-InboundFees)</p></li><li><p>Batch Open Warnings</p></li><li><p>P&amp;L Chart updated with on-chain costs</p></li><li><p>Advanced settings added for those who would like their channel db size to be read remotely (default remains local)</p></li></ul></li><li><p>Alby</p><ul><li><p>Js-SDK <a href="https://github.com/getAlby/js-sdk/releases/tag/v5.0.0">v5.0.0</a></p><ul><li><p>In this release, we introduce a new LN class which makes it even easier to get quickly started sending and receiving bitcoin payments. We also add a NWCWalletService class which allows wallet developers to add NWC support without having to implement the low-level NWC code of creating and signing events, relay connection, etc.</p></li><li><p>Features</p><ul><li><p>feat: add NWC Wallet Service</p></li><li><p>feat: add simpler LNClient class</p></li></ul></li></ul></li><li><p>Hub <a href="https://github.com/getAlby/hub/releases/tag/v1.16.0">v1.16.0</a> - Rop Gonggrijp</p><ul><li><p>Features</p><ul><li><p>Alby pro subscriptions</p></li><li><p>Add bitrefill to app store</p></li><li><p>New sidebar</p></li><li><p>App store submission: ZEUS</p></li><li><p>Add lightning messageboard to app store</p></li><li><p>Improve settings pages UI</p></li><li><p>Add healthcheck alert</p></li><li><p>Add update button to what&#8217;s new widget</p></li><li><p>Show channel duration on open channel pages</p></li><li><p>Add funding txid and amount to LDK channel closed event</p></li><li><p>Show date on lightning messageboard messages</p></li></ul></li></ul></li><li><p>Go <a href="https://github.com/getAlby/go/releases/tag/v1.12.0">v1.12.0</a></p><ul><li><p>Wallet switcher to swap wallets during payments, withdrawals, and connections</p></li><li><p>Enhance number formatting for locales that use decimal commas</p></li></ul></li></ul></li><li><p>Ark <a href="https://github.com/ark-network/ark/releases/tag/v0.5.4">v0.5.4</a> - New SubscribeForAddress API, Fixes and Optmiziations</p><ul><li><p>SubmitRedeemTx: remove useless extra PSBT decode</p></li><li><p>Add SubscribeForAddress explorer API</p></li><li><p>hotfix: TapscriptsVtxoScript.Decode returns an error in case array is empty</p></li><li><p>hotfix: GetTaprootTree use bytes.Contains instead of bytes.Equal</p></li><li><p>hotfix: CLTV locktime decoding</p></li><li><p>[Server] Move db write ops to background</p></li></ul></li><li><p>Ark Labs HQ wallet-sdk</p><ul><li><p><a href="https://github.com/ArkLabsHQ/wallet-sdk/releases/tag/v0.0.12">v0.0.12</a></p><ul><li><p><code>DefaultVtxo.Script</code> add default exit timelock</p></li></ul></li><li><p><a href="https://github.com/ArkLabsHQ/wallet-sdk/releases/tag/v0.0.11">v0.0.11</a></p><ul><li><p><code>VtxoScript</code> abstraction</p></li><li><p>Mark as side-effect-free to allow Tree Shaking</p></li><li><p>Add <code>ArkNote</code> class</p></li><li><p>Reveal tapscripts in virtual transactions</p></li><li><p>SubscribeForAddress RPC + service worker database</p></li><li><p>feat: optimize ESM and CommonJS dual package support</p></li><li><p>ServiceWorker: support concurrent calls</p></li></ul></li></ul></li><li><p>Fedimint</p><ul><li><p><a href="https://github.com/fedimint/fedimint/releases/tag/v0.7.0">v0.7.0</a> - Going Full-Stack</p><ul><li><p>Highlights</p><ul><li><p>Initial recurring payment support through LNURL (to be extended to BOLT12)</p></li><li><p>Integrated guardian and setup UI to simplify deployment</p></li><li><p>Beta support for running <code>fedimintd</code> behind firewalls and NAT routers without opening ports and registering domains</p></li><li><p>Lower on-chain fees through better estimation</p></li></ul></li></ul></li><li><p><a href="https://github.com/fedimint/fedimint/releases/tag/v0.6.2">v0.6.2</a></p><ul><li><p>Allow overwriting blockchain API supplied to clients</p></li><li><p>Add parse_invite_code function in fedimint-client-wasm</p></li><li><p>Expose additional backup metrics via prometheus</p></li></ul></li></ul></li><li><p>Breez SDK <a href="https://github.com/breez/breez-sdk-liquid/releases/tag/0.8.0">v0.8.0</a> - Nodeless</p><ul><li><p>Add WASM support (Node.js and Web)</p></li><li><p>Lower the minimum payment amount for sending</p></li><li><p>Enable fee payments in USDT</p></li></ul></li><li><p>BlitzWallet <a href="https://github.com/BlitzWallet/BlitzWallet/releases/tag/Android-v0.4.3-beta">v0.4.3-beta</a></p><ul><li><p>Ecash Improvements</p><ul><li><p>Increased eCash Limits: Users can now customize their maximum receive and balance amounts for eCash transactions. Previously, eCash payments were restricted below the minimum Boltz swap amount of 1,000 sats. Now, users can define:</p></li><li><p>Expanded Manual Swap Options: The manual swap page now supports:</p><ul><li><p>Liquid to eCash transfers</p></li><li><p>eCash to Lightning transfers</p></li><li><p>eCash to Liquid transfers</p></li></ul></li><li><p>Store Payments with eCash: Users can now pay for items in supported stores using eCash.</p></li><li><p>Wallet Balance Visibility: The remove wallet function now displays the entire eCash balance when enabled.</p></li></ul></li><li><p>Payment Experience</p><ul><li><p>SMS Payment Update Messages: Users receive SMS updates on payment progress, improving transparency of background progress.</p></li><li><p>Direct Tip Payments: Employees who use an LNURL or Blitz contact name can now be sent tips directly from the app.</p></li><li><p>Improved App Access with LN Issues: If the Lightning Network (LN) connection fails and LN is enabled, users can still access the app instead of being locked out.</p></li></ul></li><li><p>Performance Optimizations</p><ul><li><p>Optimized Transaction Sorting: Transaction processing has been improved for better app performance.</p></li><li><p>Bulk Requests for Contact Address Updates: Instead of making multiple single requests, the app now processes contact address changes in bulk, reducing network usage by 10x.</p></li></ul></li></ul></li><li><p>CDK <a href="https://github.com/cashubtc/cdk/releases/tag/v0.9.0">v0.9.0</a></p><ul><li><p>Features</p><ul><li><p>Added</p><ul><li><p>Amountless invoices NUT PR</p></li><li><p>create_time, paid_time to mint and melt quotes PR</p></li><li><p>cdk-mint-rpc: Added get mint and melt quotes ttl PR</p></li></ul></li><li><p>Changed</p><ul><li><p>cashu: Move wallet mod to cdk-common</p></li><li><p>Export Mint DB Traits PR</p></li><li><p>Move Mint and Melt quote to cdk commit from cashu PR</p></li></ul></li></ul></li></ul></li><li><p>01:31:40 Minibits Wallet <a href="https://github.com/minibits-cash/minibits_wallet/releases/tag/v0.2.2-beta.5">v0.2.2-beta.5</a></p><ul><li><p>This is a new native Minibits release with huge amount of changes needed to adjust the project to the planned release on iOS devices. However, it still comes with useful features and fixes for Android as well, notably:</p><ul><li><p>New feature to lock ecash to a receiver&#8217;s pubkey</p></li><li><p>Faster confirmations of ecash minting and payments thanks to websockets</p></li><li><p>Major upgrade of all libraries, switch to React native&#8217;s new architecture</p></li><li><p>Planned iOS release-related platform checks and changes for android</p></li></ul></li></ul></li><li><p>01:31:42 Hydrus <a href="https://github.com/aftermath2/hydrus/releases/tag/v0.2.0">v0.2.0</a></p><ul><li><p>Channels routing policies adjustments= Channels routing policies are adjusted based on the channel state (capacity, local balance) and the amount of satoshis forwarded in the last activity period (agent.intervals.routing_policies).</p></li><li><p>CLI commands: Agent instructions and scores queries now have their own command to execute them separately. To run all agent tasks (open/close/updates) use the agent run command.</p></li><li><p>Built-in tasks scheduling: Choose how often to open/close channels or update routing policies without having to use systemd timers or cron jobs.</p></li><li><p>New open heuristic: This release introduces a new open channel heuristic called channels.block_height.</p></li></ul></li></ul><h3><strong>Nostr</strong></h3><h4><strong>Project spotlight</strong></h4><ul><li><p>01:31:44 <a href="https://njump.me/naddr1qq4kzar0d45kxttnd9nkuct5w4ex2ttnwashqueddamx2u3ddehhxarj956z7vfs9uerqv34qgsrkwjz6dx0pg2q95vd2dkf62kzavwxqxdfz5a72uyyeqt96xfwxfgrqsqqqa28w7fkhn">Atomic Signature Swaps over Nostr</a>: A protocol for exchanging Schnorr signatures using Nostr events</p><ul><li><p>The protocol supports applications like paid Nostr events, payment receipts, contract signing, asset exchanges, and credential access tokens through specific event kinds (455, 456, 457, and 30455).</p></li><li><p>The cryptographic mechanism allows two parties to swap signatures by having one party provide a public nonce and the other provide an adaptor signature, with safeguards needed for Taproot UTXOs and Cashu tokens.</p></li></ul></li><li><p>01:31:51 Lantern: A layered annotations noting tool and emphasizer of readables on nostr [<a href="https://git.fiatjaf.com/lantern">Code repository</a></p><ul><li><p>&#8220;Lantern is a fork of Hypothesis that publishes page notes, annotations and highlights to Nostr.&#8221;</p></li><li><p>&#8220;URLs are normalized and we follow NIP-84 for Highlights and NIP-22 for replies, annotations and page notes. NIP-65 relay lists are used for publishing the events in the common case and NIP-51 relay sets for custom relay groups of annotations.&#8221;</p></li></ul></li><li><p>01:31:59 Promenade: Provider of multisig for events on nostr and destroyer of encryption [<a href="https://git.fiatjaf.com/promenade">Github</a>]</p></li><li><p><a href="https://loudr.me/">Loudr</a>: Reference client implementation that uses Atomic Signature Swaps over Nostr for sponsoring the publication of Nostr events [<a href="https://github.com/vstabile/loudr">Github</a>]</p><ul><li><p>&#8220;A reference client that implements the Atomic Signature Swap NIP for sponsoring the publication of Nostr events in exchange for Cashu payments.&#8221;</p></li></ul></li><li><p>01:32:09 Noauth-enclaved: A safe Nostr nip46 signer to be deployed on AWS Nitro Enclave [<a href="https://github.com/nostrband/noauth-enclaved">Github</a>]</p><ul><li><p>Noauth-enclaved is a NIP46 signer deployed in AWS Nitro Enclaves, providing isolated compute environments where clients can verify code integrity cryptographically.</p></li><li><p>Users can verify instance attestations containing code hashes and builder/launcher identities, manage app permissions through encrypted Nostr events, and communicate with the service using end-to-end encryption via Nostr relays.</p></li></ul></li><li><p>01:32:27 <a href="https://gm-nostr.vercel.app/">GM Swap</a>: Atomic exchange of GM notes using Schnorr adaptor signatures [<a href="https://github.com/vstabile/gm-swap">Github</a>]</p><ul><li><p>&#8220;A proof of concept implementation of the Atomic Signature Swaps NIP. This project enables users to swap GM notes, ensuring that both parties&#8217; signatures are exchanged simultaneously or not at all.&#8221;</p></li></ul></li><li><p><a href="https://tajava2006.github.io/sync-nostr-relay/">Nostr Event Synchronizer</a>: Syncs past events to your designated write and read relays based on NIP-65</p><ul><li><p>The service synchronizes nostr events between relays using the outbox model, retrieving past events chronologically and republishing them only to relays where they&#8217;re missing.</p></li></ul></li><li><p>Aegis: A simple and cross-platform Nostr signer that supports multiple connection methods [<a href="https://github.com/ZharlieW/Aegis">Github</a>]</p></li><li><p>Morning Glory: A paid blossom server that only stores blobs for a day&#8230; just like the flower [<a href="https://github.com/hzrd149/morning-glory">Github</a>]</p></li><li><p>Nostr4j: A high-performance Nostr library for the JVM, crosscompilable to javascript [<a href="https://github.com/NostrGameEngine/nostr4j">Github</a>]</p></li><li><p>Flotilla-Budabit: A fork of Flotilla which aims to provide a first class, git-centric community experience for developers [<a href="https://github.com/Pleb5/flotilla-budabit">Github</a>]</p><ul><li><p>The platform offers eleven core features including repository browsing, branch views, issues tracking, patch threads, and real-time git chat for enhanced collaboration.</p></li></ul></li><li><p>Zark: A tool to send sats to npub using Bark [<a href="https://gitlab.com/1440000bytes/zark">Gitlab</a>]</p></li><li><p><a href="https://ngengine.org/">Nostr Game Engine</a>: A game engine and framework for building games and applications integrated with the Nostr ecosystem [<a href="https://github.com/NostrGameEngine">Github</a>]</p><ul><li><p>NGE is an open-source, royalty-free game engine designed for building games and applications integrated with the Nostr ecosystem</p></li></ul></li><li><p><a href="https://bitcoin-calendar.org/">Bitcoin Calendar Bot</a>: Archiving and relaying every Bitcoin milestone [<a href="https://github.com/Bitcoin-Calendar/calendar-bot">Github</a>]</p><ul><li><p>Bitcoin Calendar Bot is an open source Go-based application that tracks and posts historical Bitcoin events daily to Nostr.</p></li></ul></li></ul><h4><strong>Software Releases &amp; Project Updates</strong></h4><ul><li><p>rust-nostr <a href="https://github.com/rust-nostr/nostr/releases/tag/v0.41.0">v0.41.0</a></p><ul><li><p>Breaking changes</p><ul><li><p>nostr: add optional relay URL arg to <code>Tag::coordinate</code></p></li><li><p>nostr: update <code>TagStandard::Label</code> and <code>EventBuilder::label</code></p></li><li><p>nostr: update <code>custom</code> field type in <code>Metadata</code> struct</p></li><li><p>pool: remove <code>Error::Failed</code> variant</p></li><li><p>pool: returns <code>Output</code> instead of an error if the message/event sending fails for all relays</p></li><li><p>pool: add <code>reason</code> field to <code>AdmitStatus::Rejected</code> variant</p></li></ul></li><li><p>Changed</p><ul><li><p>lmdb: enable POSIX semaphores for macOS and iOS targets</p></li><li><p>ndb: bump nostrdb to 0.6.1</p></li><li><p>pool: extend unit tests</p></li><li><p>pool: better handling of <code>CLOSED</code> message for REQs</p></li><li><p>relay-builder: send <code>CLOSED</code> if all possible events have been served</p></li></ul></li><li><p>Added</p><ul><li><p>nostr: add NIP-C0 (Code Snippets) support</p></li><li><p>nostr: add <code>TagKind::u</code> constructor</p></li><li><p>nostr: derive <code>Copy</code> for <code>HttpMethod</code></p></li><li><p>nostr: add <code>nip98::verify_auth_header</code></p></li><li><p>nostr: add <code>push</code>, <code>pop</code>, <code>insert</code> and <code>extend</code> methods to the <code>Tag</code> struct</p></li><li><p>nostr: add <code>nip47::Notification</code></p></li><li><p>nostr: add <code>MachineReadablePrefix::as_str</code> method</p></li><li><p>nostr: derive <code>Hash</code> for <code>EventBuilder</code> and <code>Metadata</code></p></li><li><p>pool: add <code>Relay::ban</code> method</p></li><li><p>pool: add <code>AdmitPolicy::admit_connection</code> method</p></li><li><p>keyring: add <code>NostrKeyring</code></p></li></ul></li></ul></li><li><p>Primal iOS <a href="https://njump.me/nevent1qqsz6fjwdcrhqpvrtgrvy8p4uphyc5sr6fs0uc0mul3asg4hv7u0gaqzyqfr47h86xrm5dkkmhxe0kl54nze4ml7yslhsfvjl78jtm2hnhesvqcyqqqqqqg83k046">v2.1.49</a></p><ul><li><p>Support for animated GIF uploads</p></li><li><p>Resolve issues with zap.stream URLs</p></li><li><p>Improve deep linking to threads</p></li><li><p>Fix rendering of mentioned events with unknown kinds</p></li></ul></li><li><p>Nostur <a href="https://github.com/nostur-com/nostur-ios-public/releases/tag/1.20.0">v1.20.0</a></p><ul><li><p>Add support for Lists (kind 30000)</p></li><li><p>Show preview of feed from list</p></li><li><p>Turn list into feed tab with 1 tap</p></li><li><p>Subscribe toggle to keep updating the feed from original maintainer, or keep list as-is</p></li><li><p>Share List: Toggle to make list public</p></li><li><p>Lists tab on Profile view</p></li><li><p>&#8216;Add all contacts to feed/list&#8217; post menu item</p></li><li><p>Discover tab now shows Lists shared by your follows</p></li><li><p>Enable manual ordering of custom feeds/tabs</p></li><li><p>New Top Zapped feed</p></li><li><p>New onboarding screens</p></li><li><p>New default color scheme/adjusted backgrounds</p></li><li><p>Lower delays and timeouts for fetching things</p></li><li><p>Improved hellthread handling</p></li><li><p>Support for comment on highlights (kind 9802)</p></li><li><p>Toggle to post to restricted/locked relay when starting post from single relay feed</p></li><li><p>Support relay auth for bunker/remote signer accounts</p></li><li><p>And more</p></li></ul></li><li><p>Keychat App</p><ul><li><p><a href="https://github.com/keychat-io/keychat-app/releases/tag/1.31.9%2B6364">v1.31.9</a> - Multi browser tabs</p><ul><li><p>Multi browser tabs for desktop</p></li><li><p>Add pull_refresh to room list</p></li><li><p>Update style for browser home page</p></li></ul></li><li><p><a href="https://github.com/keychat-io/keychat-app/releases/tag/1.31.2%2B6356">v1.31.2</a> - MLS Group &amp;&amp; Macos dmg</p><ul><li><p>Support desktop layout: Add DMG file for Mac OS</p></li><li><p>Desktop: Support pasting images and files into input fields</p></li></ul></li></ul></li><li><p>Nostr PHP <a href="https://github.com/nostrver-se/nostr-php/releases/tag/1.7.0">v1.7.0</a></p><ul><li><p>Add support for NIP-19 encoding and decoding bech32-encoded entities with identifiers and metadata.</p></li><li><p>Features</p><ul><li><p>Implement NIP-19</p></li><li><p>Notes on naddr decoder (NIP-19)</p></li><li><p>Support all encodings, especially naddr</p></li></ul></li></ul></li><li><p>Citrine <a href="https://github.com/greenart7c3/Citrine/releases/tag/v0.7.3">v0.7.3</a></p><ul><li><p>Improve performance when exporting events</p></li><li><p>Improve memory usage when downloading your events</p></li><li><p>Improve query performance</p></li></ul></li><li><p>Pokey <a href="https://github.com/KoalaSat/pokey/releases/tag/v0.1.6-alpha">v0.1.6</a></p><ul><li><p>Now notifications include NIP-05 mentions</p></li></ul></li><li><p>Nstart <a href="https://njump.me/nevent1qqsqqqpfq60q0r3jrqg7u72jvqscacdvf9lugmutm0ssvf8zg8a33ucprfmhxue69uhkx6rjdahxjcmvv5hxgar0dehkutnrdaksygrmmmmmugka3evlgcqwq3922wsul966nhrayl04svauwldhsjjcq52zg7z7">Update</a></p><ul><li><p>Nstart is now multilingual: Currently available in English, Espa&#241;ol, Italiano, Fran&#231;ais, Deutsch and &#26085;&#26412;&#35486;.</p></li></ul></li></ul><h3><strong>Boosts</strong></h3><ul><li><p>01:33:04 Thanks to everyone who streamed sats, and shoutout to our top boosters:</p><ul><li><p>[&#127942; TOP BOOSTER] @Rod Palmer Bugle News (10,000 sats) &#8220;PODCONF &#9989;&#8221;</p></li><li><p>@pink monkey (1,000 sats) &#8220;Whoa! &#128293;&#128076;&#128175;&#128079;&#8221;</p></li><li><p>@btconboard (300 sats) &#8220;Happy to discover this AI and coding podcast&#8221;</p></li><li><p>@jespada (100 sats) &#8220;Feeding the show to DVM rn, then asking o1 to write the spec then cursor = profit &#129353;&#8221;</p></li><li><p>@AVERAGE_GARY (200 sats) &#8220;Does ecash enable blinded auditing for bitcoin books? &#129300;&#8221; &#8220;First 30min is &#129292;&#129309;&#128293;&#8221;</p></li><li><p>@larryoshi finkamoto (100 sats)</p></li></ul></li></ul><h3><strong>Tech Tips of the Day</strong></h3><ul><li><p>Hide My Email (with Cloudflare): A browser extension to create unique, random email addresses that forward to your real inbox [<a href="https://github.com/webmonch/hide-my-mail-cloudflare">Github</a>]</p><ul><li><p>Create up to 200 anonymous emails</p></li><li><p>Instantly creates new mailboxes</p></li><li><p>Works on any OS</p></li></ul></li><li><p><a href="https://tosdr.org/en/">Terms of Service; Didn&#8217;t Read</a>, a website that helps users decipher complicated ToS, has just released an <a href="https://tosdr.org/en/sites/download">Android app</a> for mobile users</p></li></ul><h3><strong>Bitcoin Optech Newsletter</strong></h3><ul><li><p>Highlights from recent Bitcoin Optech Newsletters</p><ul><li><p><a href="https://bitcoinops.org/en/newsletters/2025/04/11/">349</a></p><ul><li><p>SwiftSync speedup for initial block download: Sebastian Falbesoner <a href="https://delvingbitcoin.org/t/ibd-booster-speeding-up-ibd-with-pre-generated-hints-poc/1562/">posted</a> to Delving Bitcoin a sample implementation and performance results for SwiftSync</p></li></ul></li><li><p><a href="https://bitcoinops.org/en/newsletters/2025/04/04/">348</a></p><ul><li><p>News</p><ul><li><p>Educational and experimental-based secp256k1 implementation: Sebastian Falbesoner, Jonas Nick, and Tim Ruffing <a href="https://mailing-list.bitcoindevs.xyz/bitcoindev/d0044f9c-d974-43ca-9891-64bb60a90f1f@gmail.com/">posted</a> to the Bitcoin-Dev mailing list to announce a Python implementation of various functions related to the cryptography used in Bitcoin.</p></li></ul></li><li><p>Changing consensus</p><ul><li><p>Multiple discussions about quantum computer theft and resistance: several conversations examined how Bitcoiners could respond to quantum computers becoming powerful enough to allow stealing bitcoins.</p></li><li><p>Multiple discussions about a CTV+CSFS soft fork: several conversations examined various aspects of soft forking in the OP_CHECKTEMPLATEVERIFY (CTV) and OP_CHECKSIGFROMSTACK (CSFS) opcodes.</p></li><li><p>OP_CHECKCONTRACTVERIFY semantics: Salvatore Ingala posted to Delving Bitcoin to describe the semantics of the proposed OP_CHECKCONTRACTVERIFY (CCV) opcode, link to a first draft BIP, and link to an implementation draft for Bitcoin Core.</p></li><li><p>Draft BIP published for consensus cleanup: Antoine Poinsot posted to the Bitcoin-Dev mailing list a link to a draft BIP he&#8217;s written for the consensus cleanup soft fork proposal.</p></li></ul></li></ul></li></ul></li></ul><h3><strong>News &amp; Noteworthy</strong></h3><h4><strong>Bitcoin</strong></h4><ul><li><p>Bitcoin entropy puzzles: 68-bit challenge solved for 6.8 BTC [<a href="https://x.com/Kowala24731/status/1909320999235096764">Twitter post</a>]</p><ul><li><p>The 68-bit puzzle was solved on April 7, 2025, by the same team that cracked <a href="https://x.com/Kowala24731/status/1892831634921082991">the 67-bit puzzle</a> in February, earning them 6.8 BTC.</p></li></ul></li></ul><h4><strong>Business &amp; Finance</strong></h4><ul><li><p>ACINQ resumes making its products available to customers in the United States, mentioning the &#8220;Ending Regulation By Prosecution&#8221; memo issued by the U.S. Deputy Attorney General [<a href="https://x.com/acinq_co/status/1909651903421554833">Announcement</a>]</p></li><li><p>Bull Bitcoin launches in Mexico, allowing users to send pesos instantly to Mexican bank accounts using self-custodial BTC, LN, or Liquid wallets [<a href="https://x.com/BullBitcoin_/status/1910361487140356205">Announcement</a>]</p></li><li><p>Tether plans to implement OCEAN&#8217;s DATUM Gateway across global mining operations [<a href="https://tether.io/news/tether-to-deploy-hashrate-on-ocean-advancing-decentralized-bitcoin-mining-infrastructure/">Press release</a>]</p></li><li><p>U.S.-based Bitcoin mining chip designer Auradine raises $153M in series C funding for Bitcoin and AI expansion [<a href="https://www.theminermag.com/news/2025-04-17/auradine-mara-bitcoin">The Miner Mag</a>]</p></li><li><p>Bakkt investors sue over revenue loss from non-renewed contracts [<a href="https://cointelegraph.com/news/bakkt-class-action-lawsuit-webull">Coin Telegraph</a>]</p><ul><li><p>Investors file class-action lawsuit against Bakkt Holdings, alleging the crypto firm violated securities laws by failing to disclose its heavy dependence on Webull and Bank of America contracts.</p></li></ul></li><li><p>BitGo and Voltage partner to scale Lightning Network for Bitcoin payments [<a href="https://www.voltage.cloud/blog/bitgo-and-voltage-team-up-to-deliver-instant-bitcoin-and-stablecoin-payments-via-lightning">Press release</a>]</p><ul><li><p>The partnership aims to bridge institutional security with Lightning infrastructure, allowing exchanges, neobanks, and fintech platforms to integrate instant Bitcoin payments.</p></li></ul></li><li><p>Voltage announces Voltage Payments, a new API for bitcoin and stablecoin transactions [<a href="https://www.voltage.cloud/blog/new-voltage-platform-enables-fastest-way-to-enable-bitcoin-and-soon-stablecoin-transactions">Announcement</a>]</p><ul><li><p>The service features flexible custody models, USD settlement options, and built-in compliance with SOC 2 Type II certification.</p></li></ul></li><li><p>Bitcoin Keeper introduces <a href="https://bitcoinkeeper.app/private/">Keeper Private</a>, a premium self-custody service for high-net-worth individuals and organizations seeking long-term Bitcoin holdings guidance [<a href="https://medium.com/bitbees/introducing-keeper-private-where-wealth-meets-sovereignty-278e93332b32">Blog post</a>] and <a href="https://medium.com/bitbees/introducing-keeper-learn-your-simple-expert-guided-path-to-understanding-bitcoin-be53470be069">Keeper Learn</a>, a service offering a three-session educational program teaching Bitcoin fundamentals to beginners and teams.</p></li><li><p>Theya launches Bitcoin management solutions for businesses [<a href="https://blog.theya.us/theya-announces-bitcoin-management-solutions-for-businesses/">Announcement</a>]</p><ul><li><p>The platform features flexible vault architecture supporting single-key or 2-of-3 multisig vaults for both cold storage and daily operations</p></li></ul></li><li><p>Bitcoin on-ramp and custody service Magnolia completes Lightning Network implementation and will support it from launch, pending regulatory approval [<a href="https://x.com/joinMagnolia/status/1912146256488521998">Announcement</a>]</p></li></ul><h4><strong>Funding</strong></h4><ul><li><p>OpenSats announces two new grant waves:</p><ul><li><p>The <a href="https://opensats.org/blog/fourth-wave-of-education-grants">Fourth Wave of Education Grants</a>, supporting three projects that make Bitcoin education more accessible, practical, and useful: Librer&#237;a de Satoshi, Crack the Orange, and FREE Madeira</p></li><li><p>The <a href="https://opensats.org/blog/eleventh-wave-of-nostr-grants">Eleventh Wave of Nostr Grants</a>, supporting five projects focused on decentralized live streaming, off-grid connectivity, web-of-trust infrastructure, private messaging, and open tools for game development: Swae, HAMSTR, Vertex, Nostr Double Ratchet, and Nostr Game Engine</p></li></ul></li><li><p>Brink announces supporting Bitcoin developer <a href="https://x.com/bitcoinbrink/status/1909238416232874192">Sebastian Falbesoner (@theStack)</a>&#8217;s transition to full-time open source work and that <a href="https://brink.dev/blog/2025/04/01/eugene/">Eugene Siegel</a> is joining Brink as an open source engineer for Bitcoin Core, bringing security experience from Lightning Network work and previous vulnerability disclosures.</p></li><li><p>Spiral <a href="https://x.com/spiralbtc/status/1912176891609362505">announces</a> <a href="https://x.com/L0RINC">@L0RINC</a> as its newest grantee for his work on Bitcoin Core, &#8220;emphasizing performance benchmarking and optimizations, along with code quality enhancements, code reviews, block download time reductions, memory optimization, and code refactoring.&#8221;</p></li><li><p>Vinteum renews grant to now appointed BDK maintainer Leonardo Lima for his contributions to BDK and Fedimint [<a href="https://medium.com/vinteum-org/leonardo-lima-named-bdk-maintainer-and-renews-his-vinteum-grant-65df014e9292">Announcement</a>]</p></li><li><p>Einundzwanzig grants funding to Bitcoin Safe [<a href="https://x.com/coinjoined/status/1906050537927164277">Announcement</a>]</p><ul><li><p>Bitcoin Safe, created by former Specter developer Andreas Griffin, receives 1,000,000 satoshis funding to continue development of this open-source multisig wallet.</p></li></ul></li><li><p>The Human Rights Foundation <a href="https://hrf.org/latest/hrf-bitcoin-development-fund-supports-20-projects-worldwide/">announces</a> 1 billion satoshis in gifts from its Bitcoin Development Fund to support 20 projects worldwide: NetBlocks, TollGate, Vinteum, BTCPay Server, Africa Bitcoin Institute, Bitcoin Core Graphical User Interface (GUI), Rkrux, Elsat, Relay Wizard, Waye, Hashpool, Cashu KVAC, Brandon Black (Rearden), Tony Klausing&#8217;s Stable Channels, Bitsacco, The Core, Bitcoin Babies, East Asia Bitcoin Developer Apprenticeship Program, TalentLand 2025, Base58&#8217;s Bitcoin Live Action Role Play (LARP), BTCenEspa&#241;ol, Bitcoin researcher Daniel Batten, and Bitcoin for Good.</p></li><li><p>Instant exchange eXch announces a 50 BTC open-source fund to support privacy-enhancing projects [<a href="https://bitcointalk.org/index.php?topic=577207.msg65286839#msg65286839">Bitcoin Talk Announcement</a>]</p><ul><li><p>eXch is shutting down operations and changing owners on May 1st, 2025 after learning they are the target of a transatlantic operation aiming to prosecute them for money laundering and terrorism.</p></li></ul></li><li><p>OpenCash Association offers a 2 million satoshi <a href="https://opencash.dev/projects">bounty</a> for developing an open-source BTCPayServer plugin for Cashu payments</p><ul><li><p>The plugin must include features to melt incoming tokens automatically to Lightning wallets and allow whitelisting of trusted mints to mitigate risks for merchants.</p></li></ul></li><li><p>256 Foundation <a href="https://x.com/256FOUNDATION/status/1908585602968170598">announces</a> 2025 open-source Bitcoin mining grant projects: Ember One hashboard, Hydra Pool, Libre Board, and Mujina Firmware, each led by specialized developers.</p><ul><li><p>Grant cycles for the projects begin in April/May 2025 with end dates ranging from September to December, while a fifth project called Block Watcher is paused.</p></li></ul></li><li><p>BDK Foundation adds AnchorWatch, CleanSpark, and Proton Foundation as new corporate members for 2025, joining founding members Spiral and OpenSats [<a href="https://bitcoindevkit.org/blog/_2025q1-new-foundation-members/">Announcement</a>]</p><ul><li><p>Corporate membership dues fund open source developers who maintain BDK libraries and related FOSS projects supporting Bitcoin technology.</p></li></ul></li><li><p>Bitcoin Legacy Project: A new funding initiative for Bitcoin ecosystem by Unchained [<a href="https://www.unchained.com/blog/introducing-the-bitcoin-legacy-project">Blog post</a>]</p><ul><li><p>Financial commitments include $50,000 to the Bitcoin Policy Institute, $150,000 for a university endowment at University of Austin, and up to $250,000 in research grants through the Bitcoin Scholars program.</p></li></ul></li><li><p>Project Eleven launches <a href="https://www.qdayprize.org/">Q-Day Prize</a> offering 1 BTC to the first team that breaks bitcoin&#8217;s elliptic curve cryptography using Shor&#8217;s algorithm on a quantum computer before April 2026 [<a href="https://bitcoinmagazine.com/news/project-eleven-to-award-1-btc-to-tackle-bitcoins-quantum-vulnerability">Bitcoin Magazine</a>]</p></li></ul><h4><strong>Mining</strong></h4><ul><li><p><a href="https://b10c.me/blog/015-bitcoin-mining-centralization/">Bitcoin Mining Centralization in 2025</a>: A new publication by researcher B10c reveals that six pools control 95% of the network</p><ul><li><p>Currently, Foundry (30%) and AntPool (19%) dominate Bitcoin mining, with the top four pools controlling 75% of the hashrate compared to a more decentralized era in 2017.</p></li><li><p>When accounting for &#8220;AntPool &amp; friends&#8221; proxy pooling, the centralization becomes even more extreme, with six mining pools mining 96-99% of all blocks in 2025.</p></li></ul></li></ul><h4><strong>Privacy</strong></h4><ul><li><p>Gmail introduces simplified E2EE for business customers [<a href="https://workspace.google.com/blog/identity-and-security/gmail-easy-end-to-end-encryption-all-businesses">Google Blog post</a>]</p><ul><li><p>Gmail offers end-to-end encryption without complex S/MIME implementation, allowing users to send encrypted emails with just a few clicks regardless of recipient.</p></li></ul></li><li><p>UK Court rejects secret hearing in Apple encryption challenge [<a href="https://www.openrightsgroup.org/press-releases/ipt-supports-orgs-call-for-open-hearing-in-apple-encryption-case-uk/">Open Rights Group</a>]</p><ul><li><p>The Investigatory Powers Tribunal rejects the Home Office&#8217;s application for a secret hearing in Apple&#8217;s challenge against UK Government demands to break encryption.</p></li></ul></li><li><p>European Commission unveils <a href="https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A52025PC0148">ProtectEU</a>, a strategy aiming to establish Europol as &#8220;a truly operational police agency&#8221; for investigating cross-border threats [<a href="https://therecord.media/european-commission-takes-aim-encryption-europol-fbi-proposal">The Record</a>]</p><ul><li><p>The Commission plans to create roadmaps for lawful access to encrypted data while &#8220;safeguarding cybersecurity and fundamental rights&#8221; despite potential controversy and member states&#8217; reluctance to surrender sovereignty.</p></li></ul></li></ul><h4><strong>Security</strong></h4><ul><li><p>CISA renews MITRE&#8217;s Common Vulnerabilities and Exposures Program contract hours before expiration [<a href="https://www.nextgov.com/cybersecurity/2025/04/cisa-extends-mitre-backed-cve-contract-hours-its-lapse/404601/">NextGov</a>]</p><ul><li><p>The CVE Program, a 25-year global standard for cataloging cybersecurity vulnerabilities, faces uncertainty as a subset of the CVE Board plans to form an independent CVE Foundation.</p></li><li><p>CISA faces potential budget reductions amid political scrutiny. Homeland Security Secretary Noem aims to make CISA &#8220;much more effective, smaller, more nimble, to really fulfill their mission.&#8221;</p></li></ul></li><li><p>The European Union Agency for Cybersecurity launch its own CVE database, the [<a href="https://euvd.enisa.europa.eu/">European Union Vulnerability Database (EUVD)</a>]</p><ul><li><p>It serves as a centralized platform for the collection, management, and dissemination of information regarding vulnerabilities in information and communication technology products and services.</p></li></ul></li><li><p>Android adds auto-reboot security feature after three days of inactivity [<a href="https://techcrunch.com/2025/04/15/for-security-android-phones-will-now-auto-reboot-after-three-days/">TechCrunch</a>]</p><ul><li><p>Google updates Android with new security feature that automatically reboots phones locked for three consecutive days, following Apple&#8217;s similar implementation last year.</p></li></ul></li></ul><h4><strong>Protocol</strong></h4><ul><li><p>Bitcoin Core #31363: cluster mempool: introduce TxGraph [<a href="https://github.com/bitcoin/bitcoin/pull/31363">Merged</a>]</p></li><li><p>Bitcoin Core #31278: wallet, rpc: deprecate settxfee and paytxfee [<a href="https://github.com/bitcoin/bitcoin/pull/31278">Merged</a>]</p></li><li><p>Rust Bitcoin #4302: Add push_relative_lock_time() and deprecate push_sequence() [<a href="https://github.com/rust-bitcoin/rust-bitcoin/pull/4302">Merged</a>]</p></li><li><p>LND #9669: Downgrade to legacy coop close for taproot channels [<a href="https://github.com/lightningnetwork/lnd/pull/9669">Merged</a>]</p></li><li><p>LND #9620: chain: add testnet4 support [<a href="https://github.com/lightningnetwork/lnd/pull/9620">Merged</a>]</p></li><li><p>LDK #3670: Handle receiving payments via Trampoline [<a href="https://github.com/lightningdevkit/rust-lightning/pull/3670">Merged</a>]</p></li><li><p>LDK #3593: [RFC] Implement a way to do BOLT 12 Proof of Payment [<a href="https://github.com/lightningdevkit/rust-lightning/pull/3593">Merged</a>]</p></li><li><p>Eclair #3045: Optional <code>payment_secret</code> in trampoline outer payload [<a href="https://github.com/ACINQ/eclair/pull/3045">Merged</a>]</p></li><li><p>Eclair #2963: Use package relay for anchor force-close [<a href="https://github.com/ACINQ/eclair/pull/2963">Merged</a>]</p></li><li><p>BOLTs #1242: Make payment_secret mandatory and ASSUMED [<a href="https://github.com/lightning/bolts/pull/1242">Merged</a>]</p></li><li><p>NIPs #1881: Allow multi-user AUTH [<a href="https://github.com/nostr-protocol/nips/pull/1881">Open</a>]</p></li><li><p>NIPs #1875: Add Diff and Permalink kinds [<a href="https://github.com/nostr-protocol/nips/pull/1875">Open</a>]</p></li><li><p>NIPs #1873: Add guidelines tag to NIP-29 group metadata [<a href="https://github.com/nostr-protocol/nips/pull/1873">Open</a>]</p></li></ul><h4><strong>Quantum</strong></h4><ul><li><p>OpenSSL v3.5.0 introduces post-Quantum cryptography support [<a href="https://cybersecuritynews.com/openssl-3-5-0-released/">Cyber Security News</a>]</p><ul><li><p>OpenSSL v3.5.0 integrates three major post-quantum cryptography algorithms: ML-KEM, ML-DSA, and SLH-DSA</p></li><li><p>The update enhances TLS support with hybrid PQC Key Encapsulation Mechanism groups and adds server-side QUIC protocol support</p></li><li><p>Version 3.5.0 introduces new configuration options including no-tls-deprecated-ec and enable-fips-jitter, while changing default encryption from des-ede3-cbc to aes-256-cbc for some applications</p></li></ul></li></ul><h4><strong>Government &amp; Political</strong></h4><ul><li><p>Justice Department dismantles cryptocurrency enforcement team as part of Trump&#8217;s regulatory pullback [<a href="https://fortune.com/crypto/2025/04/08/doj-ncet-disbands-memo-todd-blanche-trump/">Fortune Crypto</a>]</p><ul><li><p>The DOJ disbands its National Cryptocurrency Enforcement Team (NCET), established in 2021 under Biden that prosecuted major crypto-related felonies including Tornado Cash and North Korean laundering operations.</p></li><li><p>Deputy Attorney General Todd Blanche calls for ending &#8220;regulation by prosecution,&#8221; but the memo contains numerous caveats that may still allow prosecution of developers if their services are deemed to facilitate criminal activity [<a href="https://www.therage.co/doj-crypto-mixers-memo/">The Rage</a>]</p></li></ul></li><li><p>Trump signs resolution to repeal IRS DeFi reporting requirements [<a href="https://www.reuters.com/world/us/trump-signs-bill-nullify-expanded-irs-crypto-broker-rule-2025-04-11/">Reuters</a>]</p><ul><li><p>President Trump signs H.J.Res.25, nullifying Biden-era IRS regulations that would have required non-custodial cryptocurrency service providers to file Form 1099 reports beginning in 2026.</p></li></ul></li><li><p>Local authorities across China engage private companies to convert confiscated bitcoin into cash amid regulatory uncertainty [<a href="https://www.reuters.com/world/china/china-debates-how-handle-criminal-crypto-cache-2025-04-15/">Reuters</a>]</p></li><li><p>Panama City Council approves cryptocurrency payments for municipal services, including taxes, fees, and permits [<a href="https://bitcoinmagazine.com/news/panama-city-approves-bitcoin-and-crypto-payments-for-taxes-fees-and-permits">Bitcoin Magazine</a>]</p></li></ul><h4><strong>Events</strong></h4><ul><li><p>BTC Prague, Swan and GW University launch <a href="https://btcindc.com/">BTC in D.C.</a>, the Bitcoin conference in Washington D.C.</p><ul><li><p>September 30 to October 1st, 2025 in Washington, D.C., U.S.</p></li></ul></li><li><p>Chiang Mai approves <a href="https://www.bitcoinmarathon.org/">Bitcoin Marathon and Festival</a>, The World&#8217;s First Bitcoin Half Marathon</p><ul><li><p>November 1-2, 2025 in Chiang Mai, Thailand</p></li></ul></li><li><p><a href="https://event.bitcoin.design/">Bitcoin Designathon</a>, a global online event organized by the Bitcoin Design Community to encourage designers and artists to collaboratively improve Bitcoin&#8217;s UX and accessibility through creative, open-source design projects. &#8203;</p><ul><li><p>May 4-18, 2025</p></li></ul></li></ul><h3><strong>Reads</strong></h3><ul><li><p>Here&#8217;s a list of our top recently published reads:</p><ul><li><p>A simple backup scheme for wallet accounts, by Salvatore Ingala [<a href="https://delvingbitcoin.org/t/a-simple-backup-scheme-for-wallet-accounts/1607/1">Delving Bitcoin</a>]</p></li><li><p>Bitcoin Address Poisoning Attacks, by Jameson Lopp [<a href="https://blog.lopp.net/bitcoin-address-poisoning-attacks/">Cypherpunk Cogitations</a>]</p></li><li><p>A Brief History of Wallet Clustering, by @not_nothingmuch [<a href="https://spiralbtc.substack.com/p/the-scroll-3-a-brief-history-of-wallet">The Scroll #3</a>]</p></li><li><p>How Coinkite Defines Cypherpunk Bitcoin Security [<a href="https://bitcoinmagazine.com/business/how-coinkite-defines-cypherpunk-bitcoin-security">Bitcoin Magazine</a>]</p></li><li><p>Who pays for Bitcoin wallets?, by @Scoresby [<a href="https://stacker.news/items/944967">Stacker News</a>]</p></li><li><p>Three Staged Assassinations, by BitMEX Research [<a href="https://blog.bitmex.com/three-staged-assassinations-2/">Blog post</a>]</p></li><li><p>The Unwritten Rule, by Alekos Filini [<a href="https://afilini.com/blog/the-unwritten-rule/">Blog post</a>]</p></li><li><p>DVMs were a mistake, by hzrd149 [<a href="https://njump.me/naddr1qvzqqqr4gupzqfngzhsvjggdlgeycm96x4emzjlwf8dyyzdfg4hefp89zpkdgz99qqwkgandwvkhwetjv5kkzttdd9ehgcttv5kngte3xvhnyvpjx5m8uc7e">Note</a>]</p></li><li><p>Transacting with ecash while offline, by Gandlaf21 [<a href="https://njump.me/nevent1qqsfhlf2w6n63wx539fkjetqacflf3kk6dc9k5jrw40j3aynvfpf64gppamhxue69uhkumewwd68ytnrwgq37amnwvaz7tmwdaehgu3wv45kuatwv3a8wctw0f5kwtnnwpskxegzyrzt2d56nke85tsme9ajt74ysckelna8gagxk8e89785kd4cztdav3qhahy">Note</a>]</p></li></ul></li></ul><h3><strong>Episode submission ideas</strong></h3><ul><li><p>We&#8217;re looking for ideas for interesting panel conversations. To send Bitcoin related questions, just go to <a href="https://bitcoin.review/">bitcoin.review</a> and follow the contact links at the bottom of the page.</p></li></ul><h3><strong>Get in touch with the pod</strong></h3><ul><li><p><a href="https://twitter.com/bitcoinreviewhq">Podcast Twitter</a></p></li><li><p><a href="https://twitter.com/nvk">NVK Twitter</a></p></li><li><p><a href="https://t.me/BitcoinReviewPod">Telegram</a></p></li><li><p><a href="mailto:producer@coinkite.com">Email</a></p></li><li><p>Nostr &amp; LN &#9889;nvk@nvk.org (not an email!)</p></li></ul>]]></content:encoded></item><item><title><![CDATA[BR094 - COLDCARD KeyTeleport, Harbor, Ark, Cove, Zaprite, BTC Core, OMEMO, Knots, Vibe Coding, Trezor Safe 3 Attack Vector, Coinbase Phishing Campaign, Bitcoin Business Software + MORE ft. Rob & Paul]]></title><description><![CDATA[I&#8217;m joined by guests Rob Hamilton & Future Paul to go through the list.]]></description><link>https://substack.bitcoin.review/p/br094-coldcard-keyteleport-harbor</link><guid isPermaLink="false">https://substack.bitcoin.review/p/br094-coldcard-keyteleport-harbor</guid><dc:creator><![CDATA[STACK TO THE FUTURE]]></dc:creator><pubDate>Wed, 02 Apr 2025 18:15:38 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a95ac75-ac77-4167-9383-9930a48690bb_1080x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I&#8217;m joined by guests <a href="https://twitter.com/Rob1Ham">Rob Hamilton</a> &amp; <a href="https://twitter.com/futurepaul">Future Paul</a> to go through the list.</p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://bitcoin.review/podcast/episode-56/&quot;,&quot;text&quot;:&quot;Listen on your favorite podcast app&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://bitcoin.review/podcast/episode-56/"><span>Listen on your favorite podcast app</span></a></p><div><hr></div><h3><strong>Housekeeping</strong></h3><ul><li><p>00:01:09 <a href="https://datamachine.ai/app/rundvm">Nostr DVM Playground</a>: Test out Nostr Data Vending Machines from <a href="https://datamachine.ai/app/rundvm">DataMachine</a></p><ul><li><p>Choose between Text Summarization, Text Generation, People Discovery, and People Search.</p></li></ul></li><li><p>00:26:33 <a href="https://bitcoinsecurity.org/">Bitcoin Security Guide</a> updated</p></li><li><p>00:27:23 Looking for more beta testers for Cove, <a href="https://t.co/OATM9ky13M">iOS Beta</a> on TestFlight</p></li><li><p>00:33:19 <a href="https://github.com/Coldcard/firmware/blob/master/docs/key-teleport.md">COLDCARD Key Teleport</a></p><ul><li><p>Purpose: Send a small quantity of very secret data between two COLDCARD Q systems, with no risk of anything in the middle learning the secret.</p></li><li><p>Method: ECDH and AES-256-CTR plus an extra wrapping layer, transmitted over a mixture of NFC, passive websites, and QR/BBQr codes.</p></li></ul></li></ul><h3><strong>Urgent Vulnerability Disclosures</strong></h3><ul><li><p>00:29:04 &#8220;Designated seed phrase&#8221;: A new email phishing campaign is out, targets Coinbase users [<a href="https://x.com/nvk/status/1906511919881585117">Twitter post</a>]</p></li></ul><h3><strong>Bitcoin</strong></h3><h4><strong>Software Releases &amp; Project Updates</strong></h4><ul><li><p>00:44:33 Bitcoin Core <a href="https://github.com/bitcoin/bitcoin/releases/tag/v29.0rc2">v29.0rc2</a> - Bitcoin Core 29.0 release candidate 2</p><ul><li><p>Bitcoin Core 29.0rc2 is a release candidate for the next major version [<a href="https://github.com/bitcoin-core/bitcoin-devwiki/wiki/29.0-Release-Candidate-Testing-Guide">Testing Guide</a>]</p></li></ul></li><li><p>00:45:52 Fulcrum <a href="https://github.com/cculianu/Fulcrum/releases/tag/v1.12.0">v1.12.0</a></p><ul><li><p>Add support for UPnP</p></li><li><p>Add support for bitcoind&#8217;s ZMQ <code>pubhashtx</code> message</p></li><li><p>Improve Fulcrum&#8217;s mempool model efficiency by adding parent/child links for txns</p></li><li><p>Add support for Unix domain sockets in ZeroMQ notifications</p></li><li><p>Fix a rare and esoteric bug where Fulcrum would announce its TCP/SSL/WS/WSS port(s) to peers even if it was actually listening on a loopback interface for those ports</p></li></ul></li><li><p>00:46:06 Blue Wallet <a href="https://github.com/BlueWallet/BlueWallet/releases/tag/v7.1.5">v7.1.5</a></p><ul><li><p>Add market android widget</p></li><li><p>Allow app to run in Vision Pro</p></li><li><p>Allow quick tap to copy address- Bitcoin Keeper</p></li><li><p>Mobile <a href="https://github.com/bithyve/bitcoin-keeper/releases/tag/v2.1.0">v2.1.0</a></p><ul><li><p>Add Emergency Key to vaults for recovery in emergency situations</p></li><li><p>Update the Server Key with Spending limits and security delays</p></li><li><p>Send batch transactions to multiple recipients at the same time</p></li><li><p>Purchase hardware wallets with discounts</p></li><li><p>Single Key support for Portal</p></li><li><p>Improve wallet migration flow on key changes</p></li><li><p>Significant improvements to wallets syncing</p></li><li><p>Multiple UI updates and performance improvements</p></li></ul></li><li><p>Desktop <a href="https://github.com/bithyve/keeper-desktop/releases/tag/keeper-desktop-v0.2.1">v0.2.1</a></p><ul><li><p>Support subscription purchases using Bitcoin, powered by BTCPay Server.</p></li></ul></li></ul></li><li><p>00:46:27 Bitcoin Safe</p><ul><li><p><a href="https://github.com/andreasgriffin/bitcoin-safe/releases/tag/1.2.1">v1.2.1</a></p><ul><li><p>You can now assign names to participants in Sync&amp;Chat</p></li></ul></li><li><p><a href="https://github.com/andreasgriffin/bitcoin-safe/releases/tag/1.2.0">v1.2.0</a></p><ul><li><p>Improve QR scanning performance in Linux, Mac, Windows</p></li><li><p>Enhance PSBT signing UI</p></li><li><p>Add message signing via USB and QR (Coldcard Q rocks)</p></li><li><p>Add Thai language support</p></li><li><p>Add Linux Gnome dark-mode</p></li></ul></li></ul></li></ul><h3><strong>Interlude: OMEMO</strong></h3><ul><li><p>00:48:54 <a href="https://en.wikipedia.org/wiki/OMEMO">OMEMO</a></p></li></ul><h3><strong>Bitcoin (Cont.)</strong></h3><h4><strong>Software Releases &amp; Project Updates</strong></h4><ul><li><p>00:53:28 Bitcoin Knots <a href="https://github.com/bitcoinknots/bitcoin/releases/tag/v28.1.knots20250305">v28.1.knots20250305</a></p><ul><li><p>P2P and Network Changes</p><ul><li><p>Add support for Testnet4</p></li><li><p>UNIX domain sockets can now be used for proxy connections</p></li><li><p>Transactions having a feerate that is too low will be opportunistically paired with their child transactions and submitted as a package</p></li></ul></li><li><p>Mempool Policy Changes</p><ul><li><p>Topologically Restricted Until Confirmation (TRUC) parents are now allowed to be below the minimum relay feerate</p></li><li><p>Pay To Anchor (P2A) is a new standard witness output type for spending</p></li><li><p>Limited package RBF is now enabled, where the proposed conflicting package</p></li></ul></li><li><p>GUI Changes</p><ul><li><p>Add basic block visualizer to the Window menu</p></li></ul></li><li><p>Signed Messages</p><ul><li><p>Verifying BIP 137, BIP 322, and Electrum signed messages is now supported.</p></li><li><p>When signing messages for a Segwit or Taproot address, a BIP 322 signature will be produced</p></li></ul></li></ul></li><li><p>00:53:59 BoltzExchange</p><ul><li><p>boltz-backend <a href="https://github.com/BoltzExchange/boltz-backend/releases/tag/v3.10.0">v3.10.0</a> - Rescue mission</p><ul><li><p>Support for rescue files that allow swaps to be refunded with only the refund keys</p></li><li><p>Nested fee premiums to allow referrals to add extra fees</p></li><li><p>Discount CT on Liquid mainnet</p></li></ul></li><li><p>boltz-web-app <a href="https://github.com/BoltzExchange/boltz-web-app/releases/tag/v1.7.0">v1.7.0</a></p><ul><li><p>Swap recovery rescan</p></li><li><p>Download rescue key in settings</p></li><li><p>Adjust network fee when RIF is needed</p></li><li><p>Defer swap creation after backup is done</p></li></ul></li></ul></li><li><p>00:54:01 Blockstream Green QT <a href="https://github.com/Blockstream/green_qt/releases/tag/release_2.0.22">v2.0.22</a></p><ul><li><p>Add option to request an email containing the user&#8217;s nLockTime transactions</p></li></ul></li><li><p>00:54:58 FullyNoded <a href="https://github.com/Fonta1n3/FullyNoded-Server/releases/tag/0.1.0-beta">v0.1.0-beta</a></p><ul><li><p>This update removes all functionality related to Lightning and Bitcoin Knots by commenting out the related code</p></li><li><p>The focus for the first proper release is going to be on Bitcoin Core and Join Market only</p></li></ul></li><li><p>00:55:11 BullBitcoin Mobile</p><ul><li><p><a href="https://github.com/SatoshiPortal/bullbitcoin-mobile/releases/tag/v0.4.2">v0.4.2</a></p><ul><li><p>Using public/price endpoints for Bitcoin Price</p></li></ul></li><li><p><a href="https://github.com/SatoshiPortal/bullbitcoin-mobile/releases/tag/v0.4.1">v0.4.1</a></p><ul><li><p>DiscountCT for liquid transactions</p></li></ul></li></ul></li><li><p>00:55:19 RoboSats <a href="https://github.com/RoboSats/robosats/releases/tag/v0.7.5-alpha">v0.7.5-alpha</a></p><ul><li><p>For Users</p><ul><li><p>When Javascript is disabled a box appears to help the user to enable it</p></li><li><p>Users will now be advised when they select a coordinator not offering swamps in order creation</p></li></ul></li><li><p>For Coordinators</p><ul><li><p>Now orders stay public even if there is a non-confirmed Taker, allowing multiple robots to try to take the order</p></li></ul></li></ul></li><li><p>00:55:24 Bisq 2 <a href="https://github.com/bisq-network/bisq2/releases/tag/v2.1.7">v2.1.7</a></p><ul><li><p>New features</p><ul><li><p>Official Bisq mediators and moderators can now be identified by the badge next to their nickname</p></li><li><p>Add a splitpane to calibrate sizes between offerbook chat and offer list</p></li></ul></li><li><p>Improvements</p><ul><li><p>The Bisq Easy protocol has been enhanced to protect against triangular scams. Now, when the buyer does the Fiat transfer, trade ID must be set as &#8220;Reason for payment&#8221;.</p></li><li><p>Splash screen now shows the loading progress for each required step: Starting Tor, publishing onion service, connection to P2P network and, finally, data inventory request.</p></li></ul></li><li><p>Improve Trade process, Message delivery, and Mediation (more details in release notes)</p></li></ul></li><li><p>00:55:26 Zaprite <a href="https://help.zaprite.com/en/articles/10805728-zaprite-release-notes-2025-03-17">v2025-03-17</a></p><ul><li><p>Global Tags: Add a Tags feature that allows merchants to add tags and categorize incoming Transactions for reporting</p></li><li><p>Invoices: Add a Total column to the Invoices table, which shows the calculated total amount due after discounts taxes</p></li><li><p>Recurring Invoices: Add a Biannual option to Recurring Invoice schedule options</p></li><li><p>API Orders: Add a new expiresAt field to the POST /order endpoint</p></li><li><p>API Orders: Add a new metadata field to the POST /order endpoint</p></li></ul></li><li><p>00:56:38 Bitcoin Jungle App <a href="https://apps.apple.com/tt/app/bitcoin-jungle/id1600313979">v1.3.6</a></p><ul><li><p>Includes the ability to add a backup recovery email to your account in case you lose access to your phone number</p></li><li><p>Adds beta support for Bolt Cards- a protocol enabling you to link a contactless card to your wallet that lets you pay without your phone</p></li></ul></li><li><p>00:57:22 SRI <a href="https://github.com/stratum-mining/stratum/releases/tag/v1.3.0">v1.3.0</a></p><ul><li><p>This release migrates the old CI system based on Message Generator into the new SRI Integration Tests Framework.</p></li><li><p>Main changes (amongst many):</p><ul><li><p>New integration test framework and tests</p></li><li><p>Enhanced APIs for role development</p></li><li><p>Core low-level crates now support <code>no_std</code></p></li></ul></li></ul></li><li><p>00:57:57 Stratum.work <a href="https://x.com/boerst/status/1906320686886400159">Update</a></p><ul><li><p>New visual on stratum.work displays precise timing data for block template reception from pools, making it easier to spot similarities between pools</p></li></ul></li><li><p>00:58:46 Braiins OS</p><ul><li><p><a href="https://x.com/BraiinsMining/status/1904553029258330368">v25.03</a></p><ul><li><p>Toolbox now supports DPS Boost&#8211;introduced in the Braiins OS 25.01 update.</p></li><li><p>Users can now detect Avalon miners, both via CLI and GUI. Additionally, you can perform actions such as pause, resume, reboot, and change pool config for these miners. Please note that this feature is available in beta testing.</p></li><li><p>CSV exports have been enhanced. The export functionality now allows for filtering, sorting, column visibility, and the order set in the GUI&#8217;s device list.</p></li><li><p>Extended Pool Username Variables now include , which represents the miner&#8217;s IP address with an &#8220;x&#8221; separator, instead of a dot.</p></li></ul></li><li><p><a href="https://x.com/BraiinsMining/status/1894829750440407304">v25.01</a></p><ul><li><p>Full support for Antminer S21 Imm. and Antminer S21 XP Imm. with AML control board now available</p></li><li><p>Logs are now persistent across all control boards</p></li><li><p>DPS now has two modes&#8212;Normal and Boost. DPS Boost has been recently added</p></li><li><p>Customizable MIN/MAX fan speed ranges can now be set in the GUI and API</p></li><li><p>Fans on Braiins Mini Miners will now run quieter</p></li></ul></li></ul></li><li><p>00:58:50 Coinselect</p><ul><li><p><a href="https://github.com/bitcoinerlab/coinselect/releases/tag/v1.3.1">v1.3.1</a></p><ul><li><p>Prevent crash in dustThreshold for addr() descriptors lacking miniscript</p></li></ul></li><li><p><a href="https://github.com/bitcoinerlab/coinselect/releases/tag/v1.3.0">v1.3.0</a></p><ul><li><p>Add support for single-key tr(KEY) and addr(TAPROOT_ADDRESS) descriptors</p></li></ul></li></ul></li></ul><h4><strong>Project spotlight</strong></h4><ul><li><p><a href="https://grid.orange.surf/">Grid</a>: An interactive tool designed to analyze and visualize Bitcoin mining data</p><ul><li><p>Users can customize metrics and miner groupings to explore various aspects of mining pools and their activities. &#8203;</p></li><li><p>For example, the tool allows analysis of specific miner groups such as &#8220;AntPool &amp; friends,&#8221; which includes AntPool, BTC.com, Binance Pool, WhitePool, and SECPOOL.</p></li></ul></li><li><p>CTV Playground: A native Android implementation and demonstration of Bitcoin&#8217;s proposed OP_CHECKTEMPLATEVERIFY (CTV) soft fork, including a CTV Vault implementation. [<a href="https://github.com/percy-g2/android_app_ctv_playground">Github</a>]</p></li><li><p><a href="https://bip370.org/">Bitcoin PSBTv2 Explorer</a>: A quick and dirty PSBTv2 parser and converter [<a href="https://github.com/Shadouts/bip370org">Github</a>]</p><ul><li><p>This tool aims to provide an updated version of the tremendously useful bip174.org compatible with modern PSBT features.</p></li></ul></li><li><p>Fuzzamotto: Holistic Fuzzing for Bitcoin Protocol Implementations [<a href="https://github.com/dergoegge/fuzzamoto">Github</a>]</p><ul><li><p>Fuzzamoto framework enables coverage-guided fuzzing of Bitcoin full nodes through external interfaces like P2P and RPC, functioning as &#8220;Functional Fuzz Tests&#8221; rather than using in-process testing methods.</p></li><li><p>The system uses snapshot fuzzing with afl++&#8217;s Nyx mode for deterministic and performant testing of multiple node instances simultaneously, with future integration possibilities for other snapshot fuzzing tools.</p></li></ul></li><li><p><a href="https://bitcoinhumanalliance.org/">Bitcoin Humanitarian Alliance</a>: A global initiative leveraging Bitcoin to support freedom, financial inclusion, and humanitarian causes</p><ul><li><p>The alliance aims to unite activists and humanitarian groups worldwide who use Bitcoin, educate nonprofits on integrating Bitcoin into their work, and host events to share strategies for financial freedom.</p></li></ul></li><li><p>BetterStrike: Strike Tor Web Wallet [<a href="https://codeberg.org/olivertwist43/BetterStrike">Gitlab</a>]</p><ul><li><p>Strike Wallet functions as a web-based Bitcoin wallet interface that uses Strike API and Tor technology to enable both Lightning and on-chain transactions.</p></li></ul></li><li><p><a href="https://github.com/coinbase/cb-mpc">Coinbase MPC</a>: Coinbase open sources its MPC cryptography library [<a href="https://www.coinbase.com/en-fr/blog/introducing-coinbases-open-source-mpc-cryptography-library">Announcement</a>]</p><ul><li><p>The library provides cryptographic protocols using secure multiparty computation, and is derived from Coinbase&#8217;s internal system but modified for general-purpose public use.</p></li><li><p>The library includes practical examples like HD-MPC, threshold EC-DKG for ECDSA-MPC, and ECDSA-MPC with threshold backup implementations.</p></li></ul></li><li><p><a href="https://www.branta.pro/core">Branta Core</a>: A multi-platform app you to guard your clipboard on Mac, Linux and Windows [<a href="https://docs.branta.pro/core">Docs</a>]</p></li><li><p><a href="https://www.branta.pro/">Branta Guardrail</a>: A tool to verify invoices and checkouts before sending Bitcoin or Lightning [<a href="https://docs.branta.pro/guardrail">Docs</a>]</p></li><li><p><a href="https://www.satoshis.forex/">Satoshi Forex</a>: A straightforward forex page listing the sat value of each unit of currency.</p><ul><li><p>The website compares Bitcoin&#8217;s value to the world&#8217;s top 30 currencies in real-time, using data from CoinGecko and the IMF World Economic Outlook database (2024).</p></li></ul></li><li><p><a href="https://antidote.biz/">Antidote</a>: London&#8217;s first Bitcoin startup incubator hub</p><ul><li><p>Antidote is a startup studio and collaborative workspace for entrepreneurs, developers, investors, hackers and anybody building on or around bitcoin.</p></li></ul></li><li><p>Satsify: A Chrome extension that converts Amazon product prices from USD to satoshis [<a href="https://github.com/TristanBietsch/Satsify">Github</a>]</p></li></ul><h3><strong>Privacy &amp; Other Related Bitcoin Projects</strong></h3><h4><strong>Software Releases &amp; Project Updates</strong></h4><ul><li><p>01:18:13 Sideband <a href="https://github.com/markqvist/Sideband/releases/tag/1.5.0">v1.5.0</a></p><ul><li><p>Added the ability to make and receive LXST voice calls</p></li><li><p>Add basic voice call UI</p></li><li><p>Add option to configure audio devices for LXST voice calls</p></li><li><p>Add option to block non-trusted callers</p></li><li><p>Add support for sharing any file type as attachment on Android</p></li><li><p>Add link stats to object details</p></li><li><p>Add a BME280 telemetry plugin example</p></li><li><p>Add button on Android to quickly go to full RNS interface status</p></li><li><p>Improve map initialisation time</p></li></ul></li><li><p>Reticulum MeshChat <a href="https://github.com/liamcottle/reticulum-meshchat/releases/tag/v1.21.0">v1.21.0</a></p><ul><li><p>Migrated to using micron-parser from NPM</p></li></ul></li><li><p>01:18:23 Mullvad VPN</p><ul><li><p>Release of DAITA v2 for all platforms [<a href="https://mullvad.net/en/blog/daita-version-2-now-available-on-all-platforms">Blog post</a>]</p><ul><li><p>DAITA version 2 introduces reduced traffic overhead by more carefully inserting dummy packets, cutting their number by half while maintaining defense levels and improving connection speed.</p></li><li><p>The new dynamic configurations feature randomly assigns different rules to VPN connections, making two clients visiting the same webpage produce different data streams and helping resist targeted attacks.</p></li></ul></li><li><p>Multihop feature now available on Android [<a href="https://mullvad.net/en/blog/2025/3/28/multihop-now-available-on-android">Blog post</a>]</p><ul><li><p>Users can now route traffic through two servers instead of one in the Android app version 2025.1 and newer, allowing the selection of entry and exit servers in different jurisdictions</p></li></ul></li></ul></li><li><p>01:18:33 NymVPN officially launches its privacy solution built on a Noise Generating Mixnet technology [<a href="https://nym.com/blog/NymVPN-launch-press-release">Press release</a>]</p><ul><li><p>The system uses zero-knowledge proofs to prevent linking payment information to online activity, with no logging by design and censorship resistance features.</p></li></ul></li></ul><h3><strong>Vulnerability Disclosures</strong></h3><ul><li><p>01:18:42 Ledger Donjon conducts a security analysis of Trezor&#8217;s hardware wallets and reveals Trezor Safe 3 is susceptible to physical supply chain attacks [<a href="https://www.ledger.com/why-secure-elements-make-a-crucial-difference-to-hardware-wallet-security">Security Audit</a>]</p><ul><li><p>Trezor Safe 3 and Safe 5 products incorporate Secure Elements (Infineon Optiga Trust M) that safeguard user PINs and secrets.</p></li><li><p>Donjon details the remaining security considerations:</p><ul><li><p>Critical cryptographic operations still occur on the microcontroller, not the Secure Element, creating potential vulnerabilities if an attacker modifies the microcontroller&#8217;s firmware.</p></li><li><p>Ledger Donjon demonstrated they could bypass firmware verification measures to run modified code that could &#8220;lead to the remote recovery of all the user&#8217;s funds.&#8221;</p></li><li><p>The newer Trezor Safe 5 uses an STM32U5 microcontroller that offers improved security against fault injection attacks compared to the TRZ32F429 used in Safe 3.</p></li></ul></li></ul></li><li><p><a href="https://github.com/Chapoly1305/nroottag">nRootTag</a>: Turning a Bluetooth device into an Apple AirTag without root privileges [<a href="https://cs.gmu.edu/~zeng/papers/2025-security-nrootgag.pdf">Research paper</a>]</p><ul><li><p>Researchers discover &#8220;nRootTag&#8221; vulnerability allowing attackers to convert any Bluetooth device into an AirTag-like tracker without root privileges.</p></li><li><p>Attack exploits address confusion in Apple&#8217;s Find My network, using over 1.5 billion iPhones as unwitting tracking agents.</p></li><li><p>Attack requires malicious app installation, Bluetooth capability, and proximity to Apple devices participating in Find My network.</p></li><li><p>Apple released patches in December 2024 (iOS 18.2 and other system updates) to address this vulnerability.</p></li></ul></li><li><p>Eavesdropping on black-box mobile devices via audio amplifier&#8217;s EMR [<a href="https://www.ndss-symposium.org/wp-content/uploads/2024-240-paper.pdf">Research Paper</a>]</p><ul><li><p>Periscope is a proof-of-concept system demonstrating how electromagnetic radiations (EMR) from mobile devices&#8217; audio amplifiers can be exploited to recover audio sounds.</p></li><li><p>Headphones connected to devices act as antennas that enhance EMR signals, making them measurable at distances up to 15m with a miniaturized prototype similar in size to hidden voice recorders.</p></li><li><p>The attack successfully recovers private audio with a word error rate as low as 7.44% across 11 mobile devices and 6 headphones, producing results intelligible to both human hearing and speech-to-text tools.</p></li></ul></li><li><p>Microsoft discovers StilachiRAT, a sophisticated trojan targeting credentials and crypto wallet information [<a href="https://thehackernews.com/2025/03/microsoft-warns-of-stilachirat-stealthy.html">The Hacker News</a>]</p><ul><li><p>The malware targets at least 20 cryptocurrency wallet extensions in Chrome, including MetaMask and Coinbase Wallet, and can execute 10 different commands from its command-and-control server. [<a href="https://www.microsoft.com/en-us/security/blog/2025/03/17/stilachirat-analysis-from-system-reconnaissance-to-cryptocurrency-theft/">Microsoft Analysis</a>]</p></li></ul></li><li><p>Android apps are covertly tracking users through Bluetooth and WiFi [<a href="https://cyberinsider.com/android-apps-use-bluetooth-and-wifi-scanning-to-track-users-without-gps/">Cyber Insider</a>]</p><ul><li><p>Study reveals 86% of analyzed apps gather sensitive data, including device identifiers and WiFi scan results, often bypassing Android&#8217;s privacy controls.</p></li></ul></li><li><p>Next.js discloses critical authentication bypass vulnerability (<a href="https://nextjs.org/blog/cve-2025-29927">CVE-2025-29927</a>) with CVSSv3 score of 9.1 in middleware layer, exploitable through an extra HTTP header [<a href="https://www.runzero.com/blog/next-js/">runZero Blog post</a>]</p><ul><li><p>Remote attackers can bypass security checks including authentication mechanisms by exploiting this vulnerability.</p></li></ul></li><li><p>Clevo boot guard keys leak threatens system security [<a href="https://securityexpress.info/leaked-clevo-boot-guard-keys-threaten-firmware-integrity-binarly-reveals/">Security Express</a>]</p><ul><li><p>Binarly <a href="https://www.binarly.io/blog/clevo-boot-guard-keys-leaked-in-update-package">confirms</a> discovery of leaked private Boot Guard keys in Clevo firmware packages. The keys were found in a publicly available BIOS update containing BootGuardKey.exe with private keys that could be used to bypass security measures.</p></li><li><p>Investigation identifies 15 affected firmware packages across 10 unique Clevo-manufactured devices, including several Gigabyte laptop models. The compromised keys remain in use on &#8220;actively supported products, thereby elevating the severity of the threat.&#8221;</p></li></ul></li><li><p>Five dollars wrench attacks:</p><ul><li><p>41-year-old man assaulted and robbed of HK$318,000 in cash in Hong Kong after completing a cryptocurrency trade [<a href="https://www.thestandard.com.hk/breaking-news/section/4/229929/Man-robbed-of-over-$300,000-in-cash-after-crypto-trade">The Standard</a>]</p><ul><li><p>The victim received the cash from a cryptocurrency trade and was heading to his home when the robbery occurred at around 11pm.</p></li></ul></li><li><p>Turkish man carrying &#8364;5 million cash for cryptocurrency trading is attacked in Hong Kong by knife-wielding assailants [<a href="https://www.dimsumdaily.hk/four-arrested-after-attempted-robbery-of-5-million-euro-cash-from-27-year-old-turkish-man-in-tsim-sha-tsui/">Dimsum Daily</a>]</p><ul><li><p>Victim fights off attackers, suffers 10-centimetre knife wound to forehead, but retains his money bag. Police arrests four men.</p></li></ul></li><li><p>Four men and one woman arrested after the kidnapping of a cryptocurrency investor in Paris over a failed &#8364;10,000 cryptocurrency investment that collapsed [<a href="https://archive.is/jH9pD#selection-2717.0-2841.321">Le Parisien</a>]</p><ul><li><p>The 20-year-old victim was forced into a car trunk during what appeared to be a setup meeting with a 19-year-old woman. Kidnappers demanded &#8364;40,000.</p></li></ul></li><li><p>South Korean prosecutors request 10-year sentence for a man who stabbed Haru Invest CEO in the neck during a court hearing in August 2024 [<a href="https://www.theblock.co/post/346953/south-korean-man-faces-10-years-in-prison-for-stabbing-crypto-ceo-during-fraud-trial">The Block</a>]</p><ul><li><p>The attacker, surnamed Kang, lost 100 BTC in Haru Invest, which allegedly defrauded around 16,000 investors of nearly $962 million after suspending operations in June 2023.</p></li></ul></li></ul></li></ul><h3><strong>Interlude (Rob&#8217;s Corner)</strong></h3><ul><li><p>01:21:05 Coinbase is open-sourcing their multiparty computation (MPC) cryptography library [<a href="https://x.com/CoinbaseInsto/status/1905296276662386762">Accouncement</a>]</p></li><li><p>01:21:35 Mempool.space <a href="https://x.com/Rob1Ham/status/1907054612504330517">now supports address poisoning detection</a></p></li></ul><h3><strong>Privacy &amp; Other Related Bitcoin Projects (cont.)</strong></h3><h4><strong>Project spotlight</strong></h4><ul><li><p>Voca: A privacy-focused Text-to-Speech (TTS) app for Android that respects system language settings and provides a clean, simple interface [<a href="https://git.nostrdev.com/voca/voca">Gitea</a>]</p><ul><li><p>Users can configure language through system TTS settings, with all processing done locally without data collection.</p></li><li><p>Voca is FOSS and operates on a value for value model [<a href="https://njump.me/nprofile1qqs0tj5e4fj8ljvy0tdkrdhdyqxek9vsjwjmjunvfe8zhxdlnlfj8rcksauwz">Npub</a>]</p></li></ul></li><li><p><a href="https://silkpadcomputers.com/">Silkpad Computers</a>: Privacy-focused refurbished computers, focuses on older Thinkpads models</p><ul><li><p>Silkpad Computers offers refurbished devices emphasizing privacy and security through auditable firmware (IME disabled) and open-source software.</p></li></ul></li></ul><h3><strong>Lightning + L2+</strong></h3><h4><strong>Project spotlight</strong></h4><ul><li><p>LN-spam-prevention: Fee-based protocols for preventing spam on the Bitcoin Lightning Network [<a href="https://github.com/JohnLaw2/ln-spam-prevention">Github</a>]</p><ul><li><p>The project introduces protocols to assign and collect fees for Lightning services, aiming to reduce network spam by charging for all significant costs incurred.</p></li><li><p>The collection system uses griefer-penalization where both parties lose comparable funds in griefing attempts, protecting users who select self-interested partners [<a href="https://github.com/JohnLaw2/ln-spam-prevention/blob/main/spam_prevention_v1.0.pdf">Research paper</a>]</p></li></ul></li><li><p>Hydrus: Lightning automated liquidity management agent [<a href="https://github.com/aftermath2/hydrus">Github</a>]</p><ul><li><p>Hydrus automatically opens and closes Lightning Network channels based on network graph analysis and performance metrics.</p></li><li><p>The system selects nodes using weighted heuristics including capacity, centrality, routing policies, and connectivity.</p></li></ul></li><li><p>Alby Lite: A minimal Lightning address server powered by NWC [<a href="https://github.com/getAlby/lite">Github</a>]</p></li><li><p>ngx_l402: An Nginx module that enables pay-per-request authentication using the L402 protocol [<a href="https://github.com/DhananjayPurohit/ngx_l402">Github</a>]</p><ul><li><p>An L402 authentication module/plugin for Nginx that integrates seamlessly into your web server, enabling Lightning Network-based monetization for your REST APIs</p></li><li><p>It supports invoice generation through LND, LNURL, and NWC</p></li></ul></li><li><p><a href="https://lnvps.net/">LNVPS</a>: A bitcoin powered VPS provider</p><ul><li><p>LNVPS is a VPS provider based in Ireland that specializes in integrating Bitcoin&#8217;s Lightning Network for payments</p></li></ul></li><li><p>Sig4Sats Script: Atomic exchange of Cashu payments for Nostr event signatures using Schnorr adaptor signatures [<a href="https://github.com/vstabile/sig4sats-script">Github</a>]</p><ul><li><p>A simple script demonstrating how to atomically exchange Cashu payments for Nostr event signatures using Schnorr adaptor signatures.</p></li></ul></li><li><p>nut-bridge: Bridging the gap between NIP-57 and NutZaps [<a href="https://github.com/Egge21M/nut-bridge">Github</a>]</p><ul><li><p>&#8220;nut-bridge is bridging the gap between NIP-57 Zaps and NIP-61 NutZaps by providing a LNURL server that will receive payments via a Lightning Address and then turn them into a nut zap.&#8221;</p></li></ul></li></ul><h4><strong>Software Releases &amp; Project Updates</strong></h4><ul><li><p>01:22:46 LDK <a href="https://lightningdevkit.org/blog/announcing-vss/">announces</a> Versioned Storage Service (VSS)</p><ul><li><p>VSS provides server-side storage for non-custodial Lightning Network and Bitcoin wallets, which enables fund recovery after a device loss as well as future multi-device access.</p></li><li><p>The service ensures real-time synchronization of wallet states, and prevents loss of funds by securing every state change as it occurs rather than relying on periodic backups.</p></li><li><p>VSS is designed with privacy features including client-side encryption and can be self-hosted or cloud-deployed, with integration already available in LDK Node v0.4.x as alpha support.</p></li></ul></li><li><p>Eclair <a href="https://github.com/ACINQ/eclair/releases/tag/v0.12.0">v0.12.0</a></p><ul><li><p>This release adds support for creating and managing Bolt 12 offers and a new channel closing protocol (option_simple_close) that supports RBF.</p></li><li><p>We also add support for storing small amounts of (encrypted) data for our peers (option_provide_storage).</p></li></ul></li><li><p>Phoenixd <a href="https://github.com/ACINQ/phoenixd/releases/tag/v0.5.1">v0.5.1</a></p><ul><li><p>Use ubuntu for docker runtime image</p></li><li><p>Add <code>parent_id</code> link for first outgoing payment part</p></li></ul></li><li><p>Breez SDK <a href="https://github.com/breez/breez-sdk-liquid/releases/tag/0.7.2">v0.7.2</a> - Nodeless</p><ul><li><p>Add seed support to ConnectRequest</p></li><li><p>Improve realtime sync and restore</p></li></ul></li><li><p>Alby</p><ul><li><p>Go <a href="https://github.com/getAlby/go/releases/tag/v1.11.0">v1.11.0</a></p><ul><li><p>Add support for NWC deep linking and NWA</p></li><li><p>BTC rates now refresh every 5 minutes for up-to-date pricing</p></li><li><p>Improve branding with Alby Go logos on success screens</p></li><li><p>Update wallet removal copy for better clarity</p></li></ul></li></ul></li><li><p>Ark <a href="https://github.com/ark-network/ark/releases/tag/v0.5.2">v0.5.2</a> - Handle RBF transactions</p><ul><li><p>Telemetry: Go runtime metrics</p></li><li><p>SDK: Detect rbf txs while listening for boarding utxos</p></li></ul></li><li><p>Ark Labs HQ wallet-sdk</p><ul><li><p><a href="https://github.com/ArkLabsHQ/wallet-sdk/releases/tag/v0.0.9">v0.0.9</a></p><ul><li><p><code>VtxoScript</code> abstraction</p></li><li><p>Mark as side-effect-free to allow Tree Shaking</p></li><li><p>Add <code>ArkNote</code> class</p></li></ul></li><li><p><a href="https://github.com/ArkLabsHQ/wallet-sdk/releases/tag/v0.0.8">v0.0.8</a></p><ul><li><p>Support Boarding</p></li><li><p>Cleaning types</p></li><li><p>Identity abstraction</p></li><li><p>Add getTransactionHistory()</p></li><li><p>Add ServiceWorkerWallet implementation</p></li></ul></li></ul></li><li><p>BitBanana <a href="https://github.com/michaelWuensch/BitBanana/releases/tag/v0.9.3">v0.9.3</a></p><ul><li><p>Significantly enhanced channel rebalancing interface</p></li><li><p>Nostr Wallet Connect support</p></li><li><p>Channel sorting</p></li><li><p>UTXO sorting</p></li><li><p>Exposed timeout setting for backend communication and lightning payments</p></li></ul></li><li><p>BlitzWallet <a href="https://github.com/BlitzWallet/BlitzWallet/releases/tag/Android-v0.4.2-beta">v0.4.2-beta</a></p><ul><li><p>eCash Revamp: More Flexibility &amp; Security</p><ul><li><p>Deterministic Proofs: eCash proofs are now linked to your Blitz Wallet seed phrase</p></li><li><p>New SQL Storage System: Moved from encrypted database storage to a local SQL database</p></li><li><p>Cross-Wallet Portability: Upload and migrate eCash proofs between compatible wallets</p></li><li><p>Laying the Groundwork for Higher Limits: Preparing to increase the eCash storage limit beyond the current 5,000 sats cap</p></li></ul></li><li><p>Manual Migration Required: Existing eCash proofs must be manually migrated via Settings &gt; Experimental Features</p></li><li><p>Point-of-Sale Enhancements:</p><ul><li><p>Customizable Currency Display: Toggle between sats or fiat, with proper regional formatting</p></li><li><p>Integrated Tipping System: Employees can now enter their name during PoS transactions, and business owners can track tips for proper distribution</p></li></ul></li></ul></li><li><p>CDK <a href="https://github.com/cashubtc/cdk/releases/tag/v0.8.0">v0.8.0</a></p><ul><li><p>Add redb feature to mintd in order to meet MSRV target</p></li><li><p>cdk-sqlite: In memory sqlite database</p></li><li><p>Add <code>tos_url</code> to <code>MintInfo</code></p></li><li><p>cdk: Add tos_url setter to <code>MintBuilder</code></p></li><li><p>Add optional &#8220;request&#8221; and &#8220;unit&#8221; fields to MeltQuoteBolt11Response NUT Change</p></li><li><p>Add optional &#8220;amount&#8221; and &#8220;unit&#8221; fields to MintQuoteBolt11Response NUT Change</p></li><li><p>Compile-time error when no lightning backend features are enabled</p></li><li><p>Add support for sqlcipher</p></li><li><p>Payment processor</p></li><li><p>Payment request builder</p></li><li><p>Sends should be initiated by calling Wallet::prepare_send</p></li><li><p>A SendOptions struct controls optional functionality for sends</p></li><li><p>Allow Amount splitting to target a fee rate amount</p></li></ul></li><li><p>CashuBTC <a href="https://x.com/callebtc/status/1903079881325400407">Update</a></p><ul><li><p>Add the ability to use tap-to-pay with eCash, enables Bitcoin payments via NFC without internet or delay</p></li><li><p>The system supports payments from any mint and integrates with the Lightning Network</p></li></ul></li><li><p>Cashu-ts</p><ul><li><p><a href="https://github.com/cashubtc/cashu-ts/releases/tag/v2.4.1">v2.4.1</a></p><ul><li><p>Export OutputData</p></li></ul></li><li><p><a href="https://github.com/cashubtc/cashu-ts/releases/tag/v2.4.0">v2.4.0</a></p><ul><li><p>Remove dleqValid from proof and expose verification api</p></li><li><p>Extract from- and to- raw request functions</p></li><li><p>Handle specific errors cases in request.ts</p></li></ul></li><li><p><a href="https://github.com/cashubtc/cashu-ts/releases/tag/v2.3.0">v2.3.0</a></p><ul><li><p>Add method for automated batch restoration</p></li><li><p>NUT-18 is implemented, updating README.</p></li><li><p>NUT-15 MultiPath Melt Quotes</p></li><li><p>NUT-20 Signed Mint Payloads</p></li></ul></li></ul></li><li><p>Nutstash <a href="https://github.com/gandlafbtc/nutstash-wallet/releases/tag/nutstash-v2.0.4">v2.0.4</a></p><ul><li><p>Switch qr code lib to @paulmillr/qr</p></li><li><p>Feature: Offline tokens</p></li></ul></li></ul><h3><strong>Nostr</strong></h3><h4><strong>Project spotlight</strong></h4><ul><li><p><a href="https://gm.family/">GM.family</a>: Send a &#8216;GM&#8217; note to @fiatjaf by the press of a button</p></li><li><p><a href="https://nostringer.starknetonbitcoin.com/">Nostringer</a>: JavaScript library providing unlinkable ring signatures (SAG) for Nostr pubkeys [<a href="https://github.com/AbdelStark/nostringer">Github</a>]</p><ul><li><p>The library draws inspiration from Monero&#8217;s Ring Signatures using Spontaneous Anonymous Group signatures (SAG) and implements ring signatures using Ed25519 elliptic curve and Keccak hashing.</p></li></ul></li><li><p>Igloo: Frostr keyset manager and remote signer [<a href="https://github.com/FROSTR-ORG/igloo">Github</a>]</p><ul><li><p>&#8220;Desktop-based key management and signing device. Options to import an existing nsec, or generate a new one. Allows you to manage and rotate shares, plus recover your nsec using shares. Can be used online for remote signing, or offline for key management only.&#8221;</p></li></ul></li><li><p>Frost2x: Notes and other stuff signed by an extension, using the powers of FROST [<a href="https://github.com/FROSTR-ORG/frost2x">Github</a>]</p><ul><li><p>Fork of the popular nos2x extension</p></li><li><p>Uses the Bifrost library for encryption and signing of events</p></li><li><p>Allows FROST-based signing for any website that supports NIP-07</p></li></ul></li><li><p>Permafrost: Ephemeral relay and remote signing server for the FROSTR protocol [<a href="https://github.com/FROSTR-ORG/permafrost">Github</a>]</p><ul><li><p>Server-based signing device and personal ephemeral relay</p></li><li><p>Includes a NIP-07 based web portal for managing your server</p></li><li><p>Options to run as a node service (using bun) or inside a docker environment</p></li></ul></li><li><p><a href="https://23gmt.nostr.technology/">23GMT</a>: A specialized Nostr relay with time-based constraints</p><ul><li><p>23GMT is a specialized Nostr relay with some constraints:</p><ul><li><p>Only accepts posts from 23:00 to 24:00 GMT</p></li><li><p>Deletes its database at 01:00 GMT</p></li><li><p>Only accepts events with kind 1 (text notes)</p></li><li><p>Only accepts events with a NIP-70 &#8220;-&#8220; tag</p></li></ul></li></ul></li><li><p>Runstr: A motion tracking app built on top of Nostr [<a href="https://github.com/HealthNoteLabs/Runstr">Github</a>]</p><ul><li><p>Runstr aims to offer an open source, privacy-focused alternative to platforms like Nike Run Club or Strava</p></li><li><p>Current features include Nostr login, run tracker, global running feed, and Wavlake music</p></li></ul></li><li><p><a href="https://enterthenostr.com/">EnterTheNostr</a>: Matrix-themed Nostr note composer</p><ul><li><p>Aside from the nostr extension sign up, it features a &#8220;Load Smith&#8221; function that creates anonymous, one-time identities for users to post without a signer extension</p></li></ul></li><li><p><a href="https://njump.me/npub1p0wer69rpkraqs02l5v8rutagfh6g9wxn2dgytkv44ysz7avt8nsusvpjk">POWR</a>: Proof Of Workout over Relays [<a href="https://github.com/nostr-protocol/nips/pull/1816">NIP-101e: Workout Events</a>]</p><ul><li><p>POWR is a local-first, open-source fitness app for Android and iOS supercharged by Nostr [<a href="https://njump.me/nevent1qqsgsq2w59734x6995h97mt639wu80uafn05vrr4qxvd0tgfts9nj7qpp4mhxue69uhkummn9ekx7mqpzemhxue69uhhyetvv9ujuurjd9kkzmpwdejhgq3qxy54p83r6wnpyhs52xjeztd7qyyeu9ghymz8v66yu8kt3jzx75rqvjegn4">Announcement</a>]</p></li></ul></li><li><p>Nostr NIP Repository Extension: Opens the NIP repository in your browser [<a href="https://github.com/joel-st/kunkun-nostr-goto-repo">Github</a>]</p><ul><li><p>&#8220;This extension provides quick access to Nostr NIPs (Nostr Implementation Possibilities) documentation directly from Kunkun. It allows you to open Nostr-related repositories and browse specific NIPs with ease.&#8221;</p></li></ul></li><li><p>Dezh DSR: A repository containing a set of Nostr relays designed to be used for specific purposes [<a href="https://github.com/dezh-tech/ddsr">Github</a>]</p><ul><li><p><a href="https://github.com/dezh-tech/ddsr/blob/main/zapoli">Zapoli</a>: A relay designed to used by NIP-82 clients</p></li><li><p><a href="https://github.com/dezh-tech/ddsr/blob/main/210maxi">210maxi</a>: A relay that only accepts 210 character events, tuned for NIP-B1 feeds</p></li><li><p><a href="https://github.com/dezh-tech/ddsr/blob/main/pages">Pages</a>: A relay that only keeps profiles and follow lists. You can simply resolve any pubkey from it</p></li><li><p><a href="https://github.com/dezh-tech/ddsr/blob/main/bunklay">Bunklay</a>: A relay that only accept bunker related events</p></li></ul></li><li><p><a href="https://notebin.io/">Notebin</a>: NIP-95: Decentralized code snippets with Lightning tips [<a href="https://github.com/nodetec/notebin">Github</a>]</p><ul><li><p>The proposal defines a new Nostr event kind specifically for code snippets, separate from regular text notes.</p></li><li><p>Code snippets include specialized metadata such as programming language, file extension, and other code-specific attributes.</p></li></ul></li><li><p><a href="https://sats.gg/">Sats.gg</a>: A Nostr client focused on live streaming [<a href="https://github.com/satsgg/sats.gg">Github</a>]</p><ul><li><p>Sats.gg helps content creators monetize their work on platforms like Twitter, Ghost, Substack, Squarespace, and Nostr</p></li><li><p>The platform supports integration with LNURLPay and Lightning Address, facilitating seamless payment processes for users</p></li></ul></li><li><p><a href="https://yumyu.me/">Yumyume</a>: A FOSS social bookmarking client built on the Nostr protocol, distributing bookmarks across multiple relays [<a href="https://gitlab.com/digitalethicsagency/nostr/yumyume">Gitlab</a>]</p><ul><li><p>Yumyume supports self-hosting, and operates client-side but requires a local web server for full functionality.</p></li></ul></li><li><p><a href="https://postr-for-nostr.joelstuedle.ch/">Postr For Nostr</a>: Share your WordPress Posts to Nostr with Postr For Nostr [<a href="https://github.com/joel-st/postr-for-nostr">Github</a>]</p><ul><li><p>This plugin provides the ability to postr content from WordPress to Nostr.</p></li></ul></li><li><p>Flightless2: A terminal-based user interface client for Nostr direct messaging DM [<a href="https://github.com/jeremyd/flightless2">Github</a>]</p></li><li><p><a href="https://nostr-components.web.app/">Nostr Components</a>: Take Nostr content beyond Nostr clients - embed it anywhere on the internet [<a href="https://github.com/saiy2k/nostr-components">Github</a>]</p><ul><li><p>Nostr Components makes it easy to embed Nostr profiles, posts, and follow buttons in any website.</p></li></ul></li><li><p><a href="https://hellonostr.xyz/">Hello Nostr</a>: A collection of Nostr educational resources</p><ul><li><p>This site serves as a companion through the Nostr universe, helping users from downloading their first client to running relays and using self-custodial Lightning wallets.</p></li></ul></li><li><p>Nostr MCP Server: A Model Context Protocol (MCP) server that provides Nostr capabilities to LLMs like Claude [<a href="https://github.com/AustinKelsay/nostr-mcp-server">Github</a>]</p><ul><li><p>The server supports both hex public keys and npub formats, and implements five tools for interacting with the Nostr network:&#8203; getProfile, getKind1Notes, getReceivedZaps, getSentZaps, getAllZaps</p></li></ul></li><li><p><a href="https://bookstr.xyz/">Bookstr</a>: Bookstr is a Goodreads or Storygraph alternative built on Nostr built with Lovable AI [<a href="https://github.com/marykatefain/bookverse-nostr">Github</a>]</p></li></ul><h4><strong>Software Releases &amp; Project Updates</strong></h4><ul><li><p>rust-nostr <a href="https://github.com/rust-nostr/nostr/releases/tag/v0.40.0">v0.40.0</a></p><ul><li><p>Add NIP-38 and NIP-62 support</p></li><li><p>Add nostr parser, to easily parse any text and extract nostr URIs, URLs and more</p></li><li><p>Extend Tags capabilities (i.e., add deduplication support)</p></li><li><p>Add admission policies, to selectively select which events to allow receiving and which to reject</p></li><li><p>Add Mac Catalyst support for Swift package</p></li></ul></li><li><p>Coracle <a href="https://github.com/coracle-social/coracle/releases/tag/0.6.9">v0.6.9</a></p><ul><li><p>Quote addressable events by address rather than nevent</p></li><li><p>Bump nostr-tools to fix nostrcheck uploads</p></li><li><p>Show error when DM fails to send</p></li></ul></li><li><p>Nostur <a href="https://github.com/nostur-com/nostur-ios-public/releases/tag/1.19.0">v1.19.0</a></p><ul><li><p>Faster feed loading</p></li><li><p>Improve fullscreen image viewer</p></li><li><p>Prefetch images when swiping in gallery</p></li><li><p>Add blur hash metadata when posting images</p></li><li><p>Keep scroll position improvements</p></li><li><p>Show connecting thread lines in full width image mode</p></li><li><p>Multiple picture select for regular posts</p></li><li><p>Better m3u8 video stream detection</p></li><li><p>Show own npub in sidebar + copy</p></li></ul></li><li><p>Nostr PHP <a href="https://github.com/nostrver-se/nostr-php/releases/tag/1.6.0">v1.6.0</a></p><ul><li><p>Allow verification of Event objects</p></li><li><p>Add NIP-04 and NIP-44 encryption</p></li></ul></li><li><p>Yana <a href="https://github.com/frnandu/yana/releases/tag/v0.16.0">v0.16.0</a></p><ul><li><p>NWC alby go 1-click connection</p></li><li><p>Outbox relay set calculation progress</p></li><li><p>Upload media using blossom</p></li><li><p>Video player fullscreen</p></li><li><p>NIP-42 Relay Authentication</p></li></ul></li><li><p>Gossip <a href="https://github.com/mikedilger/gossip/releases/tag/v0.14.0">v0.14.0</a></p><ul><li><p>Zappers and amounts are now shown</p></li><li><p>Reactions and who reacted are now shown</p></li><li><p>UI: Side panel contains less so it can be thinner. Bottom bar added.</p></li><li><p>UI: frame count and spinner (optional)</p></li><li><p>Relay UI: sorting by score puts important relays at the top.</p></li><li><p>Relay UI: add more filters so all the bits are covered</p></li><li><p>Image and video loading is much faster</p></li><li><p>Subject in draft (when replying) can be edited</p></li><li><p>DM feeds automatically update, and note order is fixed</p></li><li><p>Logging to stderr by default</p></li><li><p>Relay errors and fetch errors are now considered as warnings</p></li></ul></li><li><p>Citrine <a href="https://github.com/greenart7c3/Citrine/releases/tag/v0.7.2">v0.7.2</a></p><ul><li><p>Add a button to delete events by kind</p></li><li><p>Change the delete all button color and separate it from the other buttons</p></li><li><p>Download events just with a npub</p></li><li><p>Change the relays when downloading events</p></li></ul></li><li><p>0xChat App Desktop <a href="https://github.com/0xchat-app/0xchat-app-main/releases/tag/v1.0.2-desktop-beta">v1.0.2</a></p><ul><li><p>Supports NIP-104 MLS secret chat</p></li><li><p>Supports copying images from the clipboard</p></li><li><p>The desktop client will remain running after the window is closed.</p></li></ul></li><li><p>nostr-relay-tray <a href="https://github.com/CodyTseng/nostr-relay-tray/releases/tag/v2.0.0">v2.0.0</a></p><ul><li><p>Support one-click to expose the relay to the internet</p></li><li><p>Add ability to delete events based on specific conditions</p></li><li><p>Breaking Change: Improved event rules structure for better control</p></li></ul></li><li><p>Pokey <a href="https://github.com/KoalaSat/pokey/releases/tag/v0.1.5-alpha">v0.1.5-alpha</a></p><ul><li><p>Zap notifications now displays zapper&#8217;s profile</p></li><li><p>Pokey will skip notifications for events containing more than a configurable amount of tagger users (Hell Threads)</p></li></ul></li><li><p>Nostr-zap <a href="https://github.com/SamSamskies/nostr-zap/releases/tag/v1.3.0">v1.3.0</a></p><ul><li><p>Introduce data-naddr property as alternative to data-note-id</p></li></ul></li><li><p>Electrum 4.6 will feature built-in Nostr support with a <a href="https://github.com/spesmilo/electrum-aionostr">custom aionostr library</a> developed specifically for this purpose [<a href="https://x.com/ElectrumWallet/status/1905024339759550760">Announcement</a>]</p><ul><li><p>Nostr integration aims to decentralize previously centralized services, enabling users to become liquidity providers for submarine swaps and replacing central servers for PSBT cosigning.</p></li><li><p>Developers are also currently working on a NWC plugin to further improve on connectivity options.</p></li></ul></li></ul><h3><strong>Boosts</strong></h3><ul><li><p>01:26:33 Thanks to everyone who streamed sats, and shoutout to our top boosters:</p><ul><li><p>[&#127942; TOP BOOSTER] @pink monkey (1,000 sats)</p></li><li><p>@Anonymous (1,000 sats)</p></li><li><p>@jespada (100 sats) &#8220;I need to sleep more often, please keep shipping&#8221;</p></li><li><p>@. (350 sats)</p></li><li><p>@Anonymous (350 sats)</p></li><li><p>@Anonymous (350 sats)</p></li><li><p>@btconboard (200 sats) &#8220;&#9889;&#65039;&#9889;&#65039;&#128077;&#127995;&#128077;&#127995;&#8221;</p></li><li><p>@AVERAGE_GARY (100 sats) &#8220;<a href="https://github.com/m1sterc001guy/roastr">Roastr</a> exists.&#8221; &#8220;ed25519?&#8221;</p></li><li><p>@alanStacksSats &#8220;Good tech content away from the usual price and macro talk alot of podcasts focus on.&#8221;</p></li></ul></li></ul><h3><strong>Tech Tip of the Day</strong></h3><ul><li><p>No Ghibli Chrome Extension: A Chrome extension that helps you identify and filter out Studio Ghibli-related content from Twitter [<a href="https://github.com/faisalsayed10/no-ghibli">Github</a>]</p></li></ul><h3><strong>Bitcoin Optech Newsletter</strong></h3><ul><li><p>Highlights from recent Bitcoin Optech Newsletters</p><ul><li><p><a href="https://bitcoinops.org/en/newsletters/2025/03/28/">347</a></p><ul><li><p>LN upfront and hold fees using burnable outputs: John Law <a href="https://delvingbitcoin.org/t/fee-based-spam-prevention-for-lightning/1524/">posted</a> to Delving Bitcoin the summary of a paper he&#8217;s written about a protocol nodes can use to charge two additional types of fees for forwarding payments</p></li><li><p>Discussion of testnets 3 and 4: Sjors Provoost <a href="https://mailing-list.bitcoindevs.xyz/bitcoindev/9FAA7EEC-BD22-491E-B21B-732AEA15F556@sprovoost.nl/">posted</a> to the Bitcoin-Dev mailing list to ask whether anyone was still using testnet3 now that testnet4 has been available for about six months</p></li><li><p>Plan to relay certain taproot annexes: Peter Todd <a href="https://mailing-list.bitcoindevs.xyz/bitcoindev/Z9tg-NbTNnYciSOh@petertodd.org/">announced</a> to the Bitcoin-Dev mailing list his plan to update his Bitcoin Core-based node, Libre Relay, to begin relaying transactions containing taproot annexes if they follow particular rules.</p></li></ul></li><li><p><a href="https://bitcoinops.org/en/newsletters/2025/03/21/">346</a></p><ul><li><p>Discussion of LND&#8217;s dynamic feerate adjustment system: Matt Morehouse <a href="https://delvingbitcoin.org/t/lnds-deadline-aware-budget-sweeper/1512">posted</a> to Delving Bitcoin a description of LND&#8217;s recently-rewritten sweeper system, which determines the feerates to use for onchain transactions. <strong>See #### Lightning&#8230;</strong></p></li></ul></li><li><p><a href="https://bitcoinops.org/en/newsletters/2025/03/14/">345</a></p><ul><li><p>P2P traffic analysis: developer Virtu <a href="https://delvingbitcoin.org/t/bitcoin-node-p2p-traffic-analysis/1490/">posted</a> to Delving Bitcoin an analysis of the network traffic generated and received by his node in four different modes: initial block download (IBD), non-listening (outbound connections only), non-archival (pruned) listening, and archival listening.</p></li><li><p>Research into single-path LN pathfinding: Sindura Saraswathi <a href="https://delvingbitcoin.org/t/an-exposition-of-pathfinding-strategies-within-lightning-network-clients/1500">posted</a> to Delving Bitcoin about research she conducted with Christian K&#252;mmerle about finding optimal paths between LN nodes for sending payments in a single part.</p></li><li><p>Probabilistic payments using different hash functions as an xor function: Robin Linus <a href="https://delvingbitcoin.org/t/emulating-op-rand/1409/10">replied</a> to the Delving Bitcoin thread about probabilistic payments.</p></li></ul></li></ul></li></ul><h3><strong>News &amp; Noteworthy</strong></h3><h4><strong>Bitcoin</strong></h4><ul><li><p>CISA: Cross-Input Signature Aggregation <a href="https://hrf.org/wp-content/uploads/2025/03/CISA-Industry-Paper-V4.pdf">research paper</a> released</p><ul><li><p>HRF sponsors research paper on Cross-Input Signature Aggregation, a Bitcoin protocol enhancement that combines multiple Schnorr signatures into a single, smaller signature.</p></li><li><p>CISA aims to reduce Bitcoin transaction sizes and storage requirements, lower transaction fees, and improve bandwidth efficiency.</p></li></ul></li></ul><h4><strong>Lightning + L2+</strong></h4><ul><li><p>LND&#8217;s Deadline-Aware Budget Sweeper: A new approach to Lightning transaction fee management [<a href="https://morehouse.github.io/lightning/lnd-deadline-aware-budget-sweeper/">Matt Morehouse</a>]</p><ul><li><p>LND v0.18.0 introduces a completely rewritten sweeper subsystem that dynamically adjusts transaction fees based on HTLC deadlines and fee budgets.</p></li><li><p>The new approach makes replacement cycling attacks uneconomical by allocating up to 50% of HTLC value for fees when necessary.</p></li><li><p>This deadline-aware strategy provides better security than existing methods while reducing reliance on potentially inaccurate fee estimators.</p></li></ul></li><li><p>Second launches its Ark protocol implementation on signet, inviting developers to test it before mainnet release [<a href="https://blog.second.tech/try-ark-on-signet/">Second Blog post</a>]</p><ul><li><p>The company provides signet faucet and test store to facilitate testing.</p></li></ul></li><li><p>Exodus announces end of Lightning wallet support on May 30, 2025, after which users cannot access Lightning wallets or funds [<a href="https://www.exodus.com/support/en/articles/8598830-lightning-in-exodus-support-ends-may-30-2025">Announcement</a>]</p><ul><li><p>Users must withdraw their entire LN balance before May 30, 2025 to avoid losing access to their funds.</p></li></ul></li></ul><h4><strong>Business &amp; Finance</strong></h4><ul><li><p>Chinese automobile financing platform Cango set to become Bitcoin mining proxy for Bitmain through Antalpha connection [<a href="https://www.theminermag.com/news/2025-03-17/cango-bitcoin-bitmain">The Miner Mag</a>]</p><ul><li><p>The connection between Antalpha, Antpool, Bitmain, and EWCL suggests Cango was positioned as a mining proxy for Bitmain from the beginning, explaining Cango&#8217;s recent purchase of 32 EH/s hashrate from Bitmain despite limited cash reserves.</p></li></ul></li><li><p>Bitcoin financial firm NYDIG to acquire Crusoe&#8217;s bitcoin mining business [<a href="https://blockspace.media/insight/bitcoin-financial-firm-nydig-to-acquire-crusoes-bitcoin-mining-business">Blockspace</a>]</p><ul><li><p>NYDIG is negotiating to purchase Crusoe Energy&#8217;s 270 MW bitcoin mining portfolio across 20 sites, including 135 employees. The acquisition allows NYDIG to expand mining operations while leveraging potential synergies with parent company Stone Ridge Holding&#8217;s 10 GW natural gas assets.</p></li><li><p>Crusoe Energy is pivoting away from bitcoin mining to focus on AI infrastructure, including a 1.6 GW datacenter project in Texas.</p></li></ul></li><li><p>L&#333;D Technologies, an IoT-driven energy intelligence provider, now operates across all Bitfarms datacenters globally [<a href="https://lod.io/lod-rolls-out-globally-with-bitfarms-optimizing-operations-management-across-all-sites/">Press release</a>]</p><ul><li><p>The platform enables Bitfarms to track electricity markets, respond to grid conditions, and optimize power costs while maximizing demand response revenue potential.</p></li></ul></li><li><p>Bitcoin mining hardware manufacturer Canaan Inc. secures $200 million through a Series A-1 Preferred Shares financing [<a href="https://www.theminermag.com/news/2025-03-11/canaan-bitcoin-mining-200-million">The Miner Mag</a>]</p><ul><li><p>The funding supports R&amp;D, production expansion, and digital mining infrastructure in North America.</p></li></ul></li><li><p>DLC Markets announces addition of options booking and settlement to their platform, automating margin calls, liquidation, and settlement processes [<a href="https://blog.dlcmarkets.com/dlc-markets-launches-bilateral-options-booking-settlement/">Blog post</a>]</p></li></ul><h4><strong>Funding</strong></h4><ul><li><p>OpenSats</p><ul><li><p><a href="https://opensats.org/blog/tenth-wave-of-bitcoin-grants">Announces</a> the Tenth Wave of Bitcoin Grants, supporting six projects advancing the Bitcoin ecosystem:</p><ul><li><p>First-time project grants for Bitcoin Safe, Stable Channels, and Waye.</p></li><li><p>And renewed project grants for Floresta, Krux, and Krux-Installer.</p></li></ul></li><li><p><a href="https://opensats.org/blog/10th-wave-of-nostr-grants">Reveals</a> the recipients of the Tenth Wave of Nostr Grants, comprising of seven innovative projects that showcase the growing versatility of the nostr ecosystem:</p><ul><li><p>The four first-time project grants in this wave are: Chachi, Zapstore, HyperNote, and Nostr Epoxy.</p></li><li><p>In addition, OpenSats has renewed project grants for: Futr, Npub.cash, and Notedeck.</p></li></ul></li><li><p><a href="https://opensats.org/blog/let-a-thousand-flowers-bloom">Announces</a> its support to OpenSats-like organizations, focusing on a specific domain, namely: 2140, OpenCash, Bitshala, Summer of Bitcoin, Bitcoin Dev Launchpad, and Foundation Formation Kit</p></li></ul></li><li><p>Vinteum <a href="https://medium.com/vinteum-org/announcing-our-fellowship-program-086ae25b5bde">announces</a> its fellowship program, a structured phase of onboarding new open-source contributors, selecting seven fellows which are starting a six-month journey:</p><ul><li><p>Luis Schwab (BDK)</p></li><li><p>Jo&#227;o Leal (Floresta)</p></li><li><p>Lucas Balieiro (PlebLottery and StratumV2)</p></li><li><p>QLRD (Krux and Floresta)</p></li><li><p>Erick Cestari (Rust-Bitcoin)</p></li><li><p>Moises Pompilio (LDK)</p></li><li><p>Lucad70 (Floresta)</p></li></ul></li><li><p>Btrust <a href="https://blog.btrust.tech/announcing-q1-2025-btrust-grants/">awards</a> Q1 2025 Starter Grants to Brandon Odiwuor, active Bitcoin Core contributor, and Itoro Ukpong, contributor to Bitcoinj and BDK-FFI.</p></li><li><p>Btrust Builders launches five structured learning tracks to train African developers in Bitcoin open-source development [<a href="https://blog.btrust.tech/introducing-the-btrust-builders-pathways/">Announcement</a>]</p><ul><li><p>The pathways include Mastering Bitcoin, Bitcoin Core CLI, Rust for Bitcoin, Programming for Bitcoin, and Start Your Career in BOSS.</p></li></ul></li></ul><h4><strong>Mining</strong></h4><ul><li><p>Foundry mines 9 blocks in a row on March 29th, from block <a href="https://mempool.space/block/000000000000000000010b44be0030738b941d47bf5c20161bfc8130a44c98d6">889982</a> to <a href="https://mempool.space/block/000000000000000000011c1b9079623b37a8cfaabbbae6ad6d9245f2277bb71a">889990</a></p></li><li><p><a href="https://mempool.space/block/00000000000000000000a517d87e63ea04c7ec3dd51d20926e82cca5466dccaf">Block 888989</a>: First public-pool block mined by self-hosted user</p><ul><li><p>A Bitcoin block with hash 00000000000000000000a517d87e63ea04c7ec3dd51d20926e82cca5466dccaf was successfully mined on a self-hosted public-pool.</p></li></ul></li><li><p>DMND launches Stratum V2 mining pool [<a href="https://blockspace.media/insight/stratum-v2-pool-dmnd-launches-announces-raise/">Blockspace</a>]</p><ul><li><p>DMND, backed by Trammell Venture Partners, <a href="https://www.dmnd.work/upcoming/">opens</a> applications for its Stratum V2 mining pool, offers miners a 0% fee for two months.</p></li></ul></li><li><p>Bitdeer introduces the A2 Pro Bitcoin miner with 14.9 J/TH efficiency, improving upon the original A2&#8217;s 16.5 J/TH and matching Bitmain&#8217;s Antminer S21 Pro [<a href="https://ir.bitdeer.com/news-releases/news-release-details/bitdeer-launches-sealminer-a2-pro-bitcoin-mining-machines">Press release</a>]</p><ul><li><p>The A2 Pro comes in two versions: air-cooled (255-270TH/) and hydro-cooled (500-530TH/s), with Bitdeer projecting total production of 35 EH/s of SEALMINER units by October.</p></li></ul></li><li><p>Auradine unveils the Teraflux AH3880, the first U.S.-engineered hydro-cooled Bitcoin miner, delivering up to 600 TH/s with 14.5 J/TH efficiency, marking the first U.S.-engineered hydro-cooled Bitcoin miner [<a href="https://www.theminermag.com/news/2025-03-26/auradine-teraflux-bitcoin-miner">The Miner Mag</a>]</p></li></ul><h4><strong>Privacy</strong></h4><ul><li><p>GSMA introduces end-to-end encryption for cross-platform messaging [<a href="https://cyberinsider.com/gsma-introduces-end-to-end-encryption-for-cross-platform-rcs-messaging/">Cyber Insider</a>]</p><ul><li><p>GSMA announces RCS standard upgrade with end-to-end encryption using the Messaging Layer Security protocol, marking the first large-scale interoperable encryption system between different clients.</p></li><li><p>Apple confirms involvement, with spokesperson Shane Bauer stating: &#8220;End-to-end encryption is a powerful privacy and security technology that iMessage has supported since the beginning.&#8221;</p></li></ul></li><li><p>U.S. Officials misuse Signal app for Yemen strike coordination, accidentally include journalist [<a href="https://cyberinsider.com/u-s-officials-used-signal-to-coordinate-yemen-strikes-accidentally-included-a-journalist-in-the-chat/">Cyber Insider</a>]</p><ul><li><p>National security team members under Trump administration mistakenly add Atlantic editor Jeffrey Goldberg to a Signal group chat coordinating military strikes in Yemen.</p></li><li><p>Officials including VP Vance, Defense Secretary Hegseth, and Secretary of State Rubio exchange classified tactical information on commercial smartphones using an unauthorized platform.</p></li></ul></li><li><p>Switzerland considers expanding its surveillance law to include VPNs, messaging apps, and social networks with over 5,000 users or $100 million turnover [<a href="https://www.techradar.com/vpn/vpn-privacy-security/secure-encryption-and-online-anonymity-are-now-at-risk-in-switzerland-heres-what-you-need-to-know">TechRadar</a>]</p><ul><li><p>The amendment creates &#8220;three types of information and two types of monitoring&#8221; that would force privacy-focused companies to modify encryption and identification practices.</p></li></ul></li><li><p>Mullvad VPN provides details on why its iOS app doesn&#8217;t enable Apple&#8217;s &#8216;includeAllNetworks&#8217; flag despite its potential privacy benefits [<a href="https://cyberinsider.com/mullvad-vpn-explains-why-it-holds-back-key-ios-privacy-feature/">Blog post</a>]</p><ul><li><p>The Swedish VPN provider discovers that enabling this feature causes critical system failures during app updates, resulting in complete network loss on iOS devices.</p></li></ul></li></ul><h4><strong>Protocol</strong></h4><ul><li><p>Bitcoin Core #31407: guix: Notarize MacOS app bundle and codesign all MacOS and Windows binaries [<a href="https://github.com/bitcoin/bitcoin/pull/31407">Merged</a>]</p></li><li><p>BIPs #1800: Consensus Cleanup BIP draft [<a href="https://github.com/bitcoin/bips/pull/1800">Open</a>]</p></li><li><p>BDK #1839: This PR allows the receiving structures (bdk_chain, bdk_wallet) to detect and evict incoming transactions that are double spent (cancelled). [<a href="https://github.com/bitcoindevkit/bdk/pull/1839">Merged</a>]</p></li><li><p>LND #9620: Adds <code>testnet4</code> support to <code>lnd</code> [<a href="https://github.com/lightningnetwork/lnd/pull/9620">Merged</a>]</p></li><li><p>LDK #3624: Support scalar tweak to rotate holder funding key during splicing [<a href="https://github.com/lightningdevkit/rust-lightning/pull/3624">Merged</a>]</p></li><li><p>LDK #3649: Add BOLT12 support to bLIP-51 / LSPS1 [<a href="https://github.com/lightningdevkit/rust-lightning/pull/3649">Merged</a>]</p></li><li><p>LDK #3608: Correct and update confirmation target constant definitions [<a href="https://github.com/lightningdevkit/rust-lightning/pull/3608">Merged</a>]</p></li><li><p>LND #9458: multi+server.go: add initial permissions for some peers [<a href="https://github.com/lightningnetwork/lnd/pull/9458">Merged</a>]</p></li><li><p>BTCPayServer #6581: RBF and UX improvement to fee bumping [<a href="https://github.com/btcpayserver/btcpayserver/pull/6581">Merged</a>]</p></li><li><p>Eclair #3044: Remove amount-based confirmation scaling [<a href="https://github.com/ACINQ/eclair/pull/3044">Merged</a>]</p></li><li><p>Eclair #3026: Support p2tr bitcoin wallet [<a href="https://github.com/ACINQ/eclair/pull/3026">Merged</a>]</p></li><li><p>BOLT #1233: Check for preimage before failing back missing HTLCs [<a href="https://github.com/lightning/bolts/pull/1233">Merged</a>]</p></li><li><p>NIP #1822: Add B0 NIP for Blossom interaction [<a href="https://github.com/nostr-protocol/nips/pull/1822">Open</a>]</p></li><li><p>NIP #1826: A way for relays to be honest about their algos [<a href="https://github.com/nostr-protocol/nips/pull/1826">Open</a>]</p></li></ul><h4><strong>Tutorial</strong></h4><ul><li><p>Liana Simple Inheritance Taproot Miniscript Wallet with Krux [<a href="https://gist.github.com/odudex/7c50d8bb95066a738e88cc9843735cff">Guide</a>]</p><ul><li><p>This guide details how to set up a Taproot miniscript wallet using:</p><ul><li><p>Krux: For key creation, backup, and transaction signing.</p></li><li><p>Liana Wallet: For creating a &#8220;Simple Inheritance&#8221; wallet that uses the keys generated on Krux.</p></li></ul></li></ul></li><li><p>Setting up a Strfry Nostr Relay as a TOR Hidden Service [<a href="http://primal.net/0xtr/1742932879611">0xtr&#8217;s Guide</a>]</p><ul><li><p>This guide will walk you through setting up your own Strfry Nostr relay on a Debian/Ubuntu server and making it accessible exclusively as a TOR hidden service.</p></li></ul></li></ul><h4><strong>Cryptography</strong></h4><ul><li><p>GPU advancements in cryptographic brute force attacks [<a href="https://tosc.iacr.org/index.php/ToSC/article/view/12078/11919">Research paper</a>]</p><ul><li><p>Researchers optimize implementations of KASUMI, SPECK, and TEA3 algorithms on GPUs, achieving 235.72, 236.72, and 234.71 keys tested per second on a single RTX 4090.</p></li><li><p>The KASUMI implementation shows 15x improvement over previous work, reducing requirements for breaking GPRS/GSM from 2400 RTX 3090 GPUs to just 142 RTX 4090 GPUs.</p></li></ul></li></ul><h4><strong>Government &amp; Political</strong></h4><ul><li><p>DeFi Education Fund publishes coalition letter asking Congress to correct DOJ&#8217;s interpretation of money transmission laws as applied to software developers [<a href="https://x.com/fund_defi/status/1904884463131119685">Announcement</a>]</p><ul><li><p>The <a href="https://www.defieducationfund.org/_files/ugd/84ba66_47e9f09699414451b5a7269cb4ef96ea.pdf">letter</a> challenges DOJ&#8217;s August 2023 legal theory that expands criminal liability to developers, which signatories believe contradicts FinCEN guidance and threatens the U.S. blockchain ecosystem.</p></li><li><p>Coalition maintains money transmitting businesses require &#8220;possessing &amp; transmitting funds on behalf of others&#8221; and urges policymakers to &#8220;protect U.S. software developers from regulatory overreach.&#8221;</p></li></ul></li><li><p>France rejects encryption backdoor mandate [<a href="https://www.eff.org/deeplinks/2025/03/win-encryption-france-rejects-backdoor-mandate">EFF</a>]</p><ul><li><p>The rejected proposal would have implemented a &#8220;ghost participant model&#8221; allowing law enforcement to silently join encrypted chats, undermining private communication security.</p></li></ul></li><li><p>The FAIR Act aims to protect bitcoin holders from civil asset forfeiture [<a href="https://bitcoinmagazine.com/politics/the-fair-act-would-protect-bitcoin-holders">Bitcoin Magazine</a>]</p><ul><li><p>The Fifth Amendment Integrity Restoration (FAIR) Act seeks to reform civil asset forfeiture laws, requiring clear and convincing evidence before the government can seize property, thereby offering stronger protections for Bitcoin holders. &#8203;</p></li></ul></li><li><p>U.S. Treasury removes Tornado Cash from sanctions list and issues warning to users [<a href="https://www.therage.co/tornado-cash-officially-removed-from-sanctions-list-treasury-issues-warning/">The Rage</a>]</p><ul><li><p>OFAC has officially lifted sanctions against Tornado Cash, removing it from the SDN List after the Fifth Circuit ruled the designation unlawful in November.</p></li><li><p><a href="https://www.therage.co/tornado-cash-treasury-attempts-to-block-sanctions-judgement/">Update</a>: Treasury files notice to prevent Texas district court from issuing final judgment on Tornado Cash sanctions reversal, attempting to retain power to list software on OFAC&#8217;s SDN list.</p><ul><li><p>Despite removing Tornado Cash from sanctions list, Treasury seeks to avoid binding court order that would prevent it from sanctioning similar privacy software in future, signaling continued focus on cryptocurrency privacy services.</p></li></ul></li></ul></li><li><p>US government prosecutors allegedly withhold evidence showing Chainalysis incorrectly attributed 300 million to North Korea in the Roman Storm case where they claimed 1 billion was laundered through Tornado Cash [<a href="https://x.com/FreeAlexeyRoman/status/1899485896904159648">Twitter post</a>]</p><ul><li><p>The defense argues prosecutors violated the Brady rule by failing to disclose evidence that &#8220;undermines a core allegation&#8221; despite prosecutors claiming the material &#8220;stretch[ed] beyond recognition what constitutes Brady material.&#8221;</p></li></ul></li><li><p>Chainalysis sued by bankruptcy debtors for facilitating fraud in Celsius network collapse [<a href="https://www.therage.co/chainalysis-sued-celsius-scam/">The Rage</a>]</p><ul><li><p>The lawsuit claims Chainalysis &#8220;knowingly and willfully fueled one of the biggest cons in cryptocurrency history&#8221; by validating inflated asset figures calculated using methodology designed by Celsius founder Alex Mashinsky.</p></li></ul></li><li><p>Samourai Wallet developers attend fourth pre-trial hearing [<a href="https://bitcoinmagazine.com/news/samourai-wallet-developers-appear-together-in-court-at-fourth-pre-trial-hearing">Bitcoin Magazine</a>]</p><ul><li><p>The court establishes pre-trial motion schedule starting May 9, with prosecution responses due June 6.</p></li><li><p>Expert disclosures are scheduled for July 15 (prosecution) and August 8 (defense). The trial is officially scheduled to begin on November 3, 2025.</p></li></ul></li><li><p>U.S. IRS sharing tax data with immigration agencies for deportation purposes [<a href="https://www.therage.co/irs-shares-tax-data-with-ice-dhs-deportations/">The Rage</a>]</p><ul><li><p>The IRS has agreed to share confidential tax records with ICE and DHS to help locate and deport immigrants who have removal orders.</p></li><li><p>This marks the second major increase in financial surveillance under the Trump administration, following Treasury&#8217;s lowering of reporting thresholds along the Mexican border from $10,000 to $200</p></li></ul></li><li><p>The European Central Bank plans to finish the digital euro testing phase by October 2025 [<a href="https://www.coindesk.com/policy/2025/03/10/ecb-targets-october-launch-for-digital-euro-but-lawmakers-raise-concerns">CoinDesk</a>]</p><ul><li><p>ECB board members are actively campaigning with European Parliament, Council, and Commission stakeholders to advance the digital euro project.</p></li></ul></li></ul><h4><strong>Events</strong></h4><ul><li><p><a href="https://mayanbitcoinconference.com/">Mayan Bitcoin Conference</a>:</p><ul><li><p>December 7-9, 2025 in M&#233;rida, Mexico</p></li></ul></li><li><p><a href="https://btcazores.com/">BTCAzores</a> 2025 edition is canceled [<a href="https://x.com/btcazores/status/1899523697926386097">Announcement</a>]</p><ul><li><p>The next edition is scheduled for 2026</p></li></ul></li></ul><h3><strong>Reads</strong></h3><ul><li><p>Here&#8217;s a list of our top recently published reads:</p><ul><li><p>Cashu: Bitcoin freebanking, by Juraj Bednar [<a href="https://juraj.bednar.io/en/blog-en/2025/03/18/cashu-bitcoin-freebanking/">Blog post</a>]</p></li><li><p>Wallet Clustering Basics, by Spiral [<a href="https://spiralbtc.substack.com/p/the-scroll-2-wallet-clustering-basics">The Scroll #2</a>]</p></li><li><p>Bitcoin&#8217;s Duplicate Transactions, by BitMEX Research [<a href="https://blog.bitmex.com/bitcoins-duplicate-transactions/">Blog post</a>]</p></li><li><p>Nostr Security: Account Hacks, by Odell [<a href="https://njump.me/naddr1qvzqqqr4gupzqpxfzhdwlm3cx9l6wdzyft8w8y9gy607tqgtyfq7tekaxs7lhmxfqq35ummnw3ez65m9vd6hy6t50yk5zcmrda6kuapdfpskx6mn94h8zcm2d4jsfjd2gy">Note</a>]</p></li><li><p>Comprehensive Analysis and Proposed Solutions for Mitigating Sybil Attacks on Nostr, by PPQ Deep Research [<a href="https://njump.me/naddr1qvzqqqr4gupzq3huhccxt6h34eupz3jeynjgjgek8lel2f4adaea0svyk94a3njdqqxnzde5xgmr2dpcxscnyve563jzel">Note</a>]</p></li><li><p>The bitcoiner&#8217;s guide to physical security, by Jameson Lopp [<a href="https://blog.casa.io/the-bitcoiners-guide-to-physical-security/">Casa Blog post</a>]</p></li><li><p>Bitcoin and the Rise of Cypherpunks: A Historical Timeline, by Craig [<a href="https://onbitcoin.substack.com/p/bitcoin-and-the-rise-of-cypherpunks">On Bitcoin</a>]</p></li></ul></li></ul><h3><strong>Episode submission ideas</strong></h3><ul><li><p>We&#8217;re looking for ideas for interesting panel conversations. To send Bitcoin related questions, just go to <a href="https://bitcoin.review/">bitcoin.review</a> and follow the contact links at the bottom of the page.</p></li></ul><h3><strong>Get in touch with the pod</strong></h3><ul><li><p><a href="https://twitter.com/bitcoinreviewhq">Podcast Twitter</a></p></li><li><p><a href="https://twitter.com/nvk">NVK Twitter</a></p></li><li><p><a href="https://t.me/BitcoinReviewPod">Telegram</a></p></li><li><p><a href="mailto:producer@coinkite.com">Email</a></p></li><li><p>Nostr &amp; LN &#9889;nvk@nvk.org (not an email!)</p></li></ul>]]></content:encoded></item><item><title><![CDATA[BR093 - ECDSA Key Extraction, ESP32 Security Concerns, COLDCARD, Cove Wallet, Krux, Nunchuk, Invalid Mining Jobs, Javascript Injection Attack, CTV Back on the table? + MORE ft. Rob & Vivek]]></title><description><![CDATA[I&#8217;m joined by guests Rob Hamilton & Vivek to go through the list.]]></description><link>https://substack.bitcoin.review/p/br093-ecdsa-key-extraction-esp32</link><guid isPermaLink="false">https://substack.bitcoin.review/p/br093-ecdsa-key-extraction-esp32</guid><dc:creator><![CDATA[STACK TO THE FUTURE]]></dc:creator><pubDate>Thu, 13 Mar 2025 19:05:24 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a95ac75-ac77-4167-9383-9930a48690bb_1080x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I&#8217;m joined by guests <a href="https://twitter.com/Rob1Ham">Rob Hamilton</a> &amp; <a href="https://twitter.com/Seardsalmon">Vivek</a> to go through the list.</p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://bitcoin.review/podcast/episode-56/&quot;,&quot;text&quot;:&quot;Listen on your favorite podcast app&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://bitcoin.review/podcast/episode-56/"><span>Listen on your favorite podcast app</span></a></p><div><hr></div><h3><strong>Housekeeping</strong></h3><ul><li><p>00:01:18 Unleashed.chat rebrands to <a href="https://datamachine.ai/">dataMachine</a> and enables Nostr Wallet Connect.</p></li></ul><h3><strong>Urgent Vulnerability Disclosures</strong></h3><ul><li><p>00:01:52 ECDSA private key extraction upon signing a malformed input in Elliptic library [<a href="https://github.com/indutny/elliptic/security/advisories/GHSA-vjh7-7g9h-fjfh">Vulnerability disclosure</a>]</p><ul><li><p>The elliptic library versions up to 6.6.0 have a critical vulnerability allowing private key extraction when signing malformed inputs, such as strings or numbers.</p></li><li><p>This issue arises because the library, by design, accepts hex strings as input types, leading to potential nonce reuse during the signing process.</p></li></ul></li><li><p>00:09:12 ESP32 Security Concerns</p><ul><li><p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27840">CVE-2025-27840</a>: Undocumented commands in ESP32 Bluetooth chip raise security concerns [<a href="https://www.tarlogic.com/news/backdoor-esp32-chip-infect-ot-devices/">Tarlogic Security&#8217;s disclosure</a>]</p><ul><li><p>Tarlogic Security researchers discover undocumented HCI commands in ESP32 microcontrollers, which are present in over one billion IoT devices worldwide. These proprietary commands allow memory access and modifications to the chip&#8217;s functionality.</p></li><li><p>Post-exploitation: The hidden commands require physical HCI access and high privileges on the controller, making remote exploitation via Bluetooth impossible.</p></li><li><p>Tarlogic introduces BluetoothUSB, a free tool designed to democratize Bluetooth security testing across operating systems, helping manufacturers and security experts conduct comprehensive device audits without expensive hardware requirements.</p></li></ul></li><li><p>Undocumented commands found in Bluetooth chip used by a billion devices [<a href="https://www.bleepingcomputer.com/news/security/undocumented-commands-found-in-bluetooth-chip-used-by-a-billion-devices/">Bleeping Computer</a>]</p></li><li><p>[<a href="https://x.com/nvk/status/1899610451173908722">NVK Tweet</a>] [<a href="https://bitcoin.review/podcast/episode-93/esp32.fail">esp32.fail</a>]</p><ul><li><p>ESP32 is an amazing platform, but not good for securing things, especially not securing #Bitcoin.</p></li><li><p>Here are a few known Secure Boot Bypass Methods, including both hardware (fault injection, EMFI) and software-based attacks with emojis!</p></li><li><p>Unpatched Bypasses (Active Threats)</p><ul><li><p>CVE-2023-35818 &#8211; EMFI attack bypasses Secure Boot V3 on ESP32 rev 3.0/3.1, allowing unsigned code execution &amp; plaintext flash readout.<br>&#128313; Not patchable in software, requires future silicon fix.<br>&#128196; <a href="http://usenix.org/system/files/woot24-delvaux.pdf">USENIX WOOT &#8217;24 Paper</a><br>&#128196; <a href="http://espressif.com/sites/default/files/advisory_downloads/AR2023-005%20Security%20Advisory%20Concerning%20Bypassing%20Secure%20Boot%20and%20Flash%20Encryption%20Using%20EMFI%20EN.pdf">Espressif Security Advisory AR2023-005</a></p></li><li><p>AR2023-007 &#8211; Power analysis + voltage glitch on ESP32-C3 &amp; ESP32-C6 extracts Flash Encryption Key &amp; bypasses Secure Boot.<br>&#128313; No fix yet, Espressif confirmed future silicon will mitigate.<br>&#128196; <a href="http://espressif.com/sites/default/files/advisory_downloads/AR2023-007.pdf">Espressif Security Advisory</a></p></li></ul></li><li><p>Patched Bypasses (Fixed in Newer Hardware)</p><ul><li><p>CVE-2020-13629 &#8211; EMFI attack on ESP32 (rev 0/1) bypasses Secure Boot &amp; Flash Encryption. Attackers inject faults to force execution of unsigned code.<br>&#128313; Patched in ESP32 V3+ (ECO3).<br>&#128196; <a href="http://raelize.com/blog/espressif-esp32-bypassing-encrypted-secure-boot-cve-2020-13629/">Raelize Research Blog</a></p></li><li><p>CVE-2019-15894 &#8211; Voltage glitch skips Secure Boot digest check, allowing execution of unsigned firmware if Flash Encryption is off.<br>&#128313; Patched in ESP32 V3 (ECO3).<br>&#128196; <a href="http://espressif.com/en/news/Espressif_Security_Advisory_Concerning_Fault_Injection_and_Secure_Boot">Espressif Security Advisory</a></p></li><li><p>CVE-2019-17391** &#8211; Fault injection allows reading Secure Boot &amp; Flash Encryption keys from eFuses, permanently compromising security.<br>&#128313; Patched in ESP32 V3.<br>&#128196; <a href="http://espressif.com/sites/default/files/advisory_downloads/Security%20Advisory%20CVE-2020-15048%2C%2013629%20EN%26CN.pdf">Espressif Security Advisory</a></p></li></ul></li></ul></li></ul></li><li><p>00:21:32 Coinos revokes NWC connection secrets due to security leak concerns [<a href="https://njump.me/nevent1qvzqqqqqqypzpw5qnyrxdmctda962pvng7ltzvjzjg09ge57dqqxfjn42ft2rcaxqyt8wumn8ghj7un9d3shjtnrda5kummn9e5k7tcpzemhxue69uhhyetvv9ujucm0d9hx7uewd9hj7qpqeslgcjp2anz29phrxpsw9wgml4t35zfasttzyrktx0hgztfky6ksfc63fm">Announcement</a>]</p><ul><li><p>Users experiencing issues with Coinos zaps via NWC are advised to generate a new connection at Coinos settings and update their Nostr app.</p></li></ul></li></ul><h3><strong>Vivek&#8217;s Corner</strong></h3><ul><li><p>00:22:51 Invalid mining jobs by AntPool &amp; friends during forks [<a href="https://b10c.me/observations/14-antpool-and-friends-invalid-mining-jobs/">b10c</a>]</p><ul><li><p>AntPool and associated pools (CloverPool, Ultimus, Rawpool, Poolin) published invalid mining jobs with excessive coinbase output values, indicating a bug in their coinbase creation code.</p></li><li><p>Invalid jobs were observed during block races, particularly on March 1, 2025, and in December 2024, suggesting a pattern of errors linked to these pools.</p></li><li><p>Historical data shows that invalid jobs often reused coinbase output values from previous blocks, hinting at a caching issue in the coinbase building process.</p></li><li><p>The behavior does not appear to be a selfish mining attempt but rather a result of technical glitches in job templates or coinbase code.</p></li><li><p>The consistent invalid job publication reinforces the idea that these pools are interconnected and potentially operated by the same entity, warranting the label &#8220;AntPool &amp; friends.&#8221;</p></li><li><p>[<a href="https://x.com/boerst/status/1899102559161520497">Boerst Tweet</a>]</p></li></ul></li><li><p>Mempool Partitioning and Identifying Mining Nodes [<a href="https://crypt-iq.github.io/coinscope-post.html">crypt-iq</a>]</p><ul><li><p>The study aimed to identify influential mining nodes on the Bitcoin network to assess potential attack vectors, such as mempool partitioning and pinning attacks.</p></li><li><p>A list of approximately 5,700 listening p2p nodes was created, filtering out those that did not accept incoming connections or participated in transaction relay.</p></li><li><p>Using the Candidate Selection algorithm from the CoinScope paper, the researcher conducted 100 trials, finding that major miners like Foundry and AntPool accounted for a significant portion of mined conflicts.</p></li><li><p>The top 200 influential nodes represented about 40% of the network&#8217;s hashrate, while a refined list of influential nodes from individual mining pools improved the representation to 50%.</p></li><li><p>The high rate of unintentional mempool partitioning (91%) indicates that attackers could exploit this for effective partitioning attacks, suggesting further analysis and refinement of the influential node list is warranted.</p></li></ul></li><li><p>BIP-119 (OP_CHECKTEMPLATEVERIFY) (no activation) <a href="https://github.com/bitcoin/bitcoin/pull/31989">#31989</a></p></li></ul><h3><strong>Bitcoin</strong></h3><h4><strong>Software Releases &amp; Project Updates</strong></h4><ul><li><p>00:37:44 COLDCARD</p><ul><li><p>New COLDCARD Release: <a href="https://github.com/Coldcard/firmware/releases/tag/2025-02-13T1415-v5.4.1">v5.4.1</a> (Mk4) and <a href="https://github.com/Coldcard/firmware/releases/tag/2025-02-13T1413-v1.3.1Q">v1.3.1</a> (Q)</p><ul><li><p>New (Message) Signing Features:</p><ul><li><p>Sign message from secure note text, or password note</p><ul><li><p>Sign message with key resulting from positive ownership check. Press (0) and enter or scan message text to be signed</p></li><li><p>Sign message with key selected from Address Explorer Custom Path menu. Press (2) and enter or scan message text to be signed</p></li><li><p>JSON message signing. Use JSON object to pass data to sign</p></li></ul></li></ul></li><li><p>Delta Mode Enhancements:</p><ul><li><p>Hide Secure Notes &amp; Passwords in Deltamode. Wipe seed if notes menu accessed</p></li><li><p>Hide Seed Vault in Deltamode. Wipe seed if Seed Vault menu accessed</p></li><li><p>Catch more DeltaMode cases in XOR submenus</p></li></ul></li><li><p>Address Display Changes:</p><ul><li><p>New address display format improves address verification on screen by splitting addresses into groups of 4 and showing with a space between them</p></li><li><p>Related: Added option to show/export full multisg addresses without censorship</p></li></ul></li><li><p>Other Changes:</p><ul><li><p>Both Mk4 and Q</p><ul><li><p>Enhancement: Add ability to switch between BIP-32 xpub, and obsolete SLIP-132 format in Export XPUB</p></li><li><p>Enhancement: Use the fact that master seed cannot be used as ephemeral seed, to show message about successful master seed verification</p></li><li><p>Enhancement: Allow devs to override backup password</p></li><li><p>Enhancement: If derivation path is omitted during message signing, derivation path default is no longer root (m), instead it is based on requested address format (m/44h/0h/0h/0/0 for p2pkh, and m/84h/0h/0h/0/0 for p2wpkh)</p></li></ul></li><li><p>Mk4 Specific Changes</p><ul><li><p>Enhancement: Export single sig descriptor with simple QR.</p></li></ul></li><li><p>Q Specific Changes</p><ul><li><p>New Feature: Verify Signed RFC messages via BBQr</p></li><li><p>New Feature: Sign message from QR scan (format has to be JSON)</p></li><li><p>Enhancement: Sign/Verify Address in Sparrow via QR</p></li><li><p>Enhancement: Sign scanned Simple Text by pressing (0). Next screen query information about which key to use</p></li><li><p>Enhancement: Add option to &#8220;Sort By Title&#8221; in Secure Notes and Passwords</p></li></ul></li></ul></li></ul></li><li><p>New COLDCARD EDGE Release: <a href="https://github.com/Coldcard/firmware/releases/tag/2025-02-19T1941-v6.3.5X">v6.3.5X</a> (Mk4) and <a href="https://github.com/Coldcard/firmware/releases/tag/2025-02-19T1940-v6.3.5QX">v6.3.5QX</a> (Q) - Catch-Up Release</p><ul><li><p>Update the startup warning which now reads: &#8220;This firmware version is qualified for use with wallets (such as AnchorWatch) that keep redundant key schemas for recovery independent of COLDCARD. We support the very latest Bitcoin innovations in the Edge Version.&#8221;</p></li><li><p>Catch up with latest releases</p></li><li><p>Qualified for use with miniscript wallets, such as AnchorWatch</p></li><li><p>Shared Changes - Both Mk4 and Q</p><ul><li><p>Allow origin-less extended keys in multisig &amp; miniscript descriptors</p></li><li><p>Static internal keys disallowed - all keys need to be ranged extended keys</p></li></ul></li></ul></li></ul></li><li><p>00:52:47 Sparrow Wallet <a href="https://github.com/sparrowwallet/sparrow/releases/tag/2.1.3">v2.1.3</a></p><ul><li><p>OneKey Pro and Classic 1S hardware wallet support</p></li><li><p>Update BIP329 wallet labels export to include additional fields</p></li><li><p>Make BIP329 wallet labels import and export scannable</p></li><li><p>Add Copy Payment Code item to the transaction diagram outputs context menu for BIP47 outputs</p></li><li><p>Add Show Transaction as QR button to signed transaction tabs when offline</p></li><li><p>Upgrade libusb to v1.0.27 on all platforms</p></li><li><p>Add specific handling for invalid Windows device drivers on Trezor devices</p></li><li><p>Handle scanning and pasting server URLs in the Electrum (x.x.x.x:n:t/s) format</p></li><li><p>Additionally check for Trezor model against internal name and improve exception handling on no match</p></li></ul></li><li><p>00:54:33 Lark <a href="https://github.com/sparrowwallet/larkapp/releases/tag/1.1.0">v1.1.0</a></p><ul><li><p>Add support for OneKey Pro and Classic 1S</p></li><li><p>Validate and sanitize multisig wallet names on Jade, BitBox02 and Ledger</p></li><li><p>Remove unnecessary public key field from BitBox02 pairing config</p></li><li><p>Add the Jade Plus to udev rules</p></li><li><p>Upgrade libusb to 1.0.27</p></li><li><p>Throw an error if trying to sign a Taproot input on legacy Ledger firmware</p></li><li><p>Additionally check for Trezor model against internal name and improve exception handling on no match</p></li><li><p>Support Coldcard P2TR address display and show correct address for script type on message sign</p></li><li><p>Add specific handling for invalid Windows device drivers on Trezor devices</p></li></ul></li><li><p>00:55:03 Krux <a href="https://github.com/selfcustody/krux/releases/tag/v25.03.0">v25.03.0</a></p><ul><li><p>Taproot and WSH Miniscript support</p><ul><li><p>Add an indented visualization of Miniscripts for improved readability</p></li><li><p>Implement Miniscripts policy and cosigner verification</p></li><li><p>Support custom derivations</p></li><li><p>Detect unspendable internal keys in Taproot</p></li><li><p>Include various UI and settings adjustments</p></li></ul></li><li><p>Easter Eggs Reveal</p><ul><li><p>Hints have been introduced to help users discover hidden features, such as:</p><ul><li><p>Swiping sideways to change the keypad keyset</p></li><li><p>Switching between camera modes</p></li><li><p>Adjusting QR code brightness</p></li><li><p>Rearranged Keypad Keysets</p></li><li><p>Keypad keysets were organized to group similar keys and help with visibility</p></li></ul></li><li><p>More Camera Modes</p><ul><li><p>A zoomed camera mode is now available for all cameras</p></li><li><p>An anti-glare mode has been added for the GC0328 camera</p></li></ul></li><li><p>More Intuitive Tamper Check</p><ul><li><p>The Tamper Check Flash Hash is now displayed immediately after generating the Tamper Check code</p></li></ul></li><li><p>Display Customization Options</p><ul><li><p>Screen orientation can now be flipped on Yahboom and WonderMV devices</p></li></ul></li><li><p>SD Card PSBT Signing Preserves All Fields</p><ul><li><p>When signing PSBTs via SD card, all fields&#8212;including signatures from other keys&#8212;are preserved</p></li><li><p>This ensures a seamless signing process across multiple devices and locations, allowing a single PSBT file to be incrementally signed by different signers</p></li></ul></li><li><p>Other Bug Fixes and Optimizations</p><ul><li><p>New encrypted mnemonics now display a key strength score during confirmation</p></li><li><p>Address scanning for Blue Wallet has been updated to match its revised export format</p></li><li><p>A faster algorithm for double mnemonic calculation has been introduced</p></li><li><p>PSBT change detection has been made more restrictive</p></li></ul></li></ul></li></ul></li><li><p>00:56:37 Cove Wallet</p><ul><li><p><a href="https://github.com/bitcoinppl/cove/releases/tag/v0.2.1">v0.2.1</a></p><ul><li><p>Add more plausible deniability to decooy PIN mode</p><ul><li><p>Pretend to change PIN and trick PINs in the settings screen</p></li></ul></li><li><p>Make it easier to click the &#8220;Change PIN&#8221; button in the settings screen</p></li></ul></li><li><p><a href="https://t.co/OATM9ky13M">iOS Beta</a>, is now available on TestFlight [<a href="https://x.com/covewallet/status/1895559787091271804">Announcement</a>]</p><ul><li><p>It supports importing hardware wallets via NFC, file, and QR code.</p></li><li><p>Key features include creating and backing up hot wallets, sending Bitcoin via PSBTs, managing multiple wallets, and connecting to personal nodes. Users can also set Trick Pins for added security and lock wallets with Face ID or a PIN.</p></li><li><p>Upcoming updates will introduce CoinControl, TapSigner and SatsCard support, and UTXO locking/unlocking. An Android version is planned for release in a few months.</p></li></ul></li></ul></li><li><p>00:59:09 Nunchuk Desktop <a href="https://github.com/nunchuk-io/nunchuk-desktop/releases/tag/1.9.43">v1.9.43</a> / Android <a href="https://github.com/nunchuk-io/nunchuk-android/releases/tag/android.1.9.64">v1.9.64</a></p><ul><li><p>New and improved encrypted group wallet:</p><ul><li><p>End-to-end encrypted group wallet and communication</p></li><li><p>Single-file recovery using wallet descriptors</p></li><li><p>Compatibility with hardware signing devices</p></li><li><p>Supports both standard multisig and Taproot multisig</p></li><li><p>Automatic message deletion for enhanced privacy</p></li></ul></li></ul></li><li><p>01:00:32 BTCPayServer <a href="https://github.com/btcpayserver/btcpayserver/releases/tag/v2.0.7">v2.0.7</a></p><ul><li><p>Display fiat amount previews in Transaction Details page</p></li><li><p>Greenfield: Adding endpoint to set server email settings</p></li></ul></li><li><p>01:00:44 Bitcoin Keeper <a href="https://github.com/bithyve/bitcoin-keeper/releases/tag/v2.0.2">v2.0.2</a></p><ul><li><p>Redesign manage subscription screen</p></li><li><p>Support External Key for Miniscript vaults</p></li><li><p>Support Specter DIY for Miniscript vaults</p></li><li><p>Improve ColdCard NFC integration</p></li><li><p>Improve import old wallets speed</p></li></ul></li><li><p>01:01:25 BlueWallet <a href="https://github.com/BlueWallet/BlueWallet/releases/tag/v7.1.0">v7.1.0</a></p><ul><li><p>Add support for importing minikeys (Casascius Coin, Satori Coin etc.)</p></li></ul></li><li><p>01:02:08 Bitcoin Safe</p><ul><li><p><a href="https://github.com/andreasgriffin/bitcoin-safe/releases/tag/1.1.0">v1.1.0</a></p><ul><li><p>Support for Jade Plus</p></li><li><p>Deb build</p></li><li><p>Xpub import from USB signers for different accounts</p></li></ul></li><li><p><a href="https://github.com/andreasgriffin/bitcoin-safe/releases/tag/1.0.7">v1.0.7</a></p><ul><li><p>Add languages: &#127474;&#127474; Burmese - &#4121;&#4156;&#4116;&#4154;&#4121;&#4140;, &#127472;&#127479; Korean - &#54620;&#44397;&#50612;</p></li></ul></li></ul></li><li><p>01:03:15 Bitkey App <a href="https://github.com/proto-at-block/bitkey/releases/tag/app%2F2025.1.1">v2025.1.1</a></p><ul><li><p>Inheritance is here. You can now add a beneficiary of your Bitkey wallet in the app.</p></li><li><p>It allows users to designate beneficiaries for their Bitcoin without sharing PINs or seed phrases</p></li></ul></li><li><p>01:04:05 libwally-core <a href="https://github.com/ElementsProject/libwally-core/releases/tag/release_1.4.0">v1.4.0</a></p><ul><li><p>tx: Add caching to signature hash generation/PSBT signing making signing faster</p></li><li><p>tx: Add support for generating Elements taproot signature hashes and signing Elements taproot inputs</p></li><li><p>descriptor: Add support for &#8220;tr()/rawtr()&#8221; keyspend-only taproot descriptors</p></li><li><p>descriptor: Add support for parsing Elements-core compatible descriptors, including taproot</p></li><li><p>psbt: Add accessors for keypath/taproot related fields</p></li><li><p>pset: Add support for ELIP-101 genesis hash</p></li><li><p>psbt: Add support for serializing/parsing/combining signature-only PSBTs</p></li><li><p>script: Add support for generating Elements p2tr scripts</p></li><li><p>BIP85: Add support for deriving RSA keys via BIP85</p></li><li><p>base64/psbt: Add support for parsing from known length (non-NUL terminated) strings</p></li><li><p>build: Add Debian Bookworm docker build image</p></li></ul></li><li><p>01:06:00 Bisq2 <a href="https://github.com/bisq-network/bisq2/releases/tag/v2.1.6">v2.1.6</a></p><ul><li><p>Security update: To enhance security for buyers, sellers must have sufficient reputation to secure a trade for the specified amount. See new formula.</p></li><li><p>New features:</p><ul><li><p>The new Profile Card comes with many features. Find the user profile details, trade terms, reputation, offers created and the public messages posted by clicking on the profile icon or profile name anywhere in the app.</p></li><li><p>To improve on privacy, sensitive trade data will be automatically deleted after a certain period of time</p></li></ul></li><li><p>Improvements: The create offer wizard has been consolidated into three steps to improve quickness and ease of use</p></li></ul></li><li><p>01:06:04 RoboSats <a href="https://github.com/RoboSats/robosats/releases/tag/v0.7.4-alpha">v0.7.4-alpha</a></p><ul><li><p>You can now see LNp2pBot orders on RoboSats mobile app</p></li><li><p>Order creation view now displays all available payment methods</p></li><li><p>Changed URLs to https://robosats.org and new <a href="http://robosatsy56bwqn56qyadmcxkx767hnabg4mihxlmgyt6if5gnuxvzad.onion/">onion</a> (#Robosats&#8217; previous clearnet and onion domains are no longer accessible as the original maintainer, @Reckless_Satoshi, has been unreachable for months [<a href="https://njump.me/nevent1qqsgjgwu3avytceu8jw4sweemskm2xryj4ks05epg6amn5wgzqf8zwcpz3mhxue69uhhyetvv9ujuerpd46hxtnfduq35amnwvaz7tmwdaehgu3wwdshgum5wfskc6tp9e3k7mgpz4mhxue69uhhwmm59ehx7um5wgh8qctjw3usygzr2gmcmlvu25h0cqeq8mqvu2yx224lpu2nnx4sdq2jz6hg825eeq7quaul">Note</a>])</p></li><li><p>Libraries updates</p></li></ul></li><li><p>01:06:08 Boltz Exchange</p><ul><li><p>boltz-client <a href="https://github.com/BoltzExchange/boltz-client/releases/tag/v2.4.0">v2.4.0</a></p><ul><li><p>With this release, boltz-client will start to use the highly anticipated Discount CT on the Liquid Network and introduces a new pro configuration option for using Boltz Pro fee rates</p></li></ul></li><li><p>boltz-web-app <a href="https://github.com/BoltzExchange/boltz-web-app/releases/tag/v1.6.2">v1.6.2</a></p><ul><li><p>Transaction broadcasts via block explorer</p></li><li><p>Add tropykus and speed as integrations</p></li></ul></li><li><p>boltz-backend <a href="https://github.com/BoltzExchange/boltz-backend/releases/tag/v3.9.1">v3.9.1</a></p><ul><li><p>Add custom fees and limits based on referrals</p></li><li><p>Fixes for RSK swap</p></li><li><p>Fixes for handling CLN xpay payment failures</p></li><li><p>Lightning network information API</p></li></ul></li></ul></li><li><p>01:06:10 Zaprite <a href="https://help.zaprite.com/en/articles/10576355-zaprite-release-notes-2025-02-17">v2025-02-17</a></p><ul><li><p>Copy Contact ID: Add an option to copy the Contact ID from the View Contact page</p></li><li><p>Improve the UI for Bank/Wire Transfer payment information on our Checkouts</p></li><li><p>Update the Delete Transaction modal to show more helpful messaging.</p></li><li><p>Adjust login/sign-up page to fallback and use a Recaptcha Puzzle when necessary</p></li></ul></li><li><p>01:06:13 Blockstream Explorer API <a href="https://blog.blockstream.com/introducing-the-new-blockstream-explorer-api-faster-easier-and-more-transparent/">Update</a></p><ul><li><p>New features include a 99.9% SLA, transparent pricing, and an open beta with a free tier for developers.</p></li><li><p>Built on open-source Esplora, the API simplifies blockchain data access, supporting wallets, exchanges, and other applications.</p></li></ul></li><li><p>01:07:22 Mempal <a href="https://github.com/aeonBTC/Mempal/releases/tag/v1.5.2">v1.5.2</a></p><ul><li><p>Add welcome screen with quick tips</p></li><li><p>Add hashrate, difficulty, and adjustments to dashboard</p></li><li><p>Modify widget auto-refresh intervals</p></li></ul></li><li><p>01:07:29 Iris Wallet desktop <a href="https://github.com/RGB-Tools/iris-wallet-desktop/releases/tag/0.1.2">v0.1.2</a> - First experimental release</p><ul><li><p>Attached you can find 2 versions running on different bitcoin networks, testnet and a shared public regtest.</p></li><li><p>For the latter you can use our <a href="https://t.me/rgb_lightning_bot">telegram bot</a> to get some funds and play around.</p></li></ul></li><li><p>01:07:31 Utreexo</p><ul><li><p><a href="https://github.com/utreexo/utreexo/releases/tag/v0.4.0">v0.4.0</a></p><ul><li><p>Export <code>detectOffset</code></p></li></ul></li><li><p><a href="https://github.com/utreexo/utreexo/releases/tag/v0.3.3">v0.3.3</a></p><ul><li><p>Export parent util functions</p></li></ul></li><li><p><a href="https://github.com/utreexo/utreexo/releases/tag/v0.3.2">v0.3.2</a></p><ul><li><p>Export <code>childMany</code>, <code>leftChild</code>, and <code>rightChild</code></p></li></ul></li><li><p><a href="https://github.com/utreexo/utreexo/releases/tag/v0.3.1">v0.3.1</a></p><ul><li><p>Export <code>detectRow</code></p></li></ul></li></ul></li><li><p>01:07:34 ESP Miner <a href="https://github.com/skot/ESP-Miner/releases/tag/v2.6.0b8">v2.6.0b8</a></p><ul><li><p>Show firmware updates on the display</p></li><li><p>Trim spaces from SSID</p></li><li><p>Add sorting switch to swarm page for hostname and ip</p></li><li><p>Show share reject reasons</p></li><li><p>Remove unit test workaround for qemu</p></li><li><p>Frequency transition</p></li></ul></li><li><p><a href="https://utxo.live/oracle/">UTXOracle</a> is now available again [<a href="https://x.com/SteveSimple/status/1889325264808677668">Announcement</a>]</p><ul><li><p>UTXOracle is a tool that estimates Bitcoin&#8217;s daily price by analyzing on-chain transactions, avoiding reliance on exchange rates</p></li><li><p>The tool uses a method involving clusters of on-chain payments at round USD amounts to calculate the price, offering an alternative to exchange-based averages</p></li></ul></li><li><p>Metamask announces &#8220;full bitcoin support&#8221; for Bitcoin within its wallet coming in Q3 2025 [<a href="https://metamask.io/en-GB/news/metamask-roadmap-2025">Roadmap</a>]</p></li></ul><h4><strong>Project spotlight</strong></h4><ul><li><p>01:07:38 <a href="https://bitcoinops.org/en/tools/reorg-calculator/">Reorg Calculator</a>: A calculator to estimate the probability of an attacker reorganizing <code>z</code> blocks, considering their hash power and the time ratio (<code>&#954;</code>)</p></li><li><p>01:07:51 Bitcoin Core Config Generator: A TUI for generating Bitcoin Core configuration [<a href="https://github.com/jurraca/core-config-tui">Github</a>]</p><ul><li><p>Provides an interactive terminal interface to generate bitcoin.conf files for Bitcoin Core.</p></li><li><p>Features include form-based configuration, real-time validation, and conditional field display.</p></li></ul></li><li><p>01:09:05 <a href="https://bitcoin-snapshots.jaonoctus.dev/">Bitcoin Core Snapshots</a>: Fast-track your node setup with pre-synced blockchain data [<a href="https://github.com/jaonoctus/bitcoin-snapshots-react">Github</a>]</p><ul><li><p>The website offers verified Bitcoin blockchain snapshots at specific points, reducing initial sync time for new nodes</p></li><li><p>Snapshots are available for mainnet (pruned at block height 885,445), testnet4 (full at block height 71,808), and signet (full at block height 237,052)</p></li></ul></li><li><p>01:09:11 Boot Protocol: A decentralized protocol for bitcoin hashing nodes to share block rewards and reduce variance [<a href="https://github.com/gridlabs-science/boot-protocol">Github</a>]</p><ul><li><p>The protocol aims to solve Bitcoin mining centralization by enabling miners to share block rewards without traditional pools. It reduces variance up to 16x compared to solo mining while maintaining decentralization.</p></li><li><p>The system operates through a &#8220;Winners List&#8221; of 15 addresses that have provided the highest difficulty hashes. Block rewards are split between these addresses and the block finder&#8217;s address.</p></li></ul></li><li><p>01:09:18 <a href="https://multisigbackup.com/">multisig-backup</a>: Encrypt and inscribe your k-of-n multisig descriptor &#8212; recover with any k seeds [<a href="https://github.com/joshdoman/multisig-backup">Github</a>]</p><ul><li><p>Sensitive data, such as master fingerprints and xpubs, is encrypted to prevent unauthorized decryption, requiring multiple seeds to recover the descriptor.</p></li><li><p>It utilizes Shamir&#8217;s Secret Sharing and ChaCha20 for encryption, and integrates with hardware wallets for the recovery process.</p></li></ul></li><li><p>01:10:04 <a href="https://github.com/thunderbiscuit/regtest-in-a-pod">regtest-in-a-pod</a></p><ul><li><p>Companion to the Using Podman Containers for Regtest Bitcoin Development blog article.</p></li><li><p>Allows you to create a robust regtest environment which you can turn on and off at will using Podman. The final environment includes a lot of useful tools, namely:</p><ul><li><p>A bitcoin core node and daemon (serving compact block filters)</p></li><li><p>bitcoin-cli enabled</p></li><li><p>An Electrum server</p></li><li><p>An Esplora server</p></li><li><p>A block explorer</p></li><li><p>Useful just commands for working with the daemon from your command line</p></li></ul></li></ul></li><li><p>01:09:58 Wallet backup: A document standardizing Bitcoin wallet backup formats [<a href="https://github.com/pythcoiner/wallet_backup">Github</a>]</p><ul><li><p>The document proposes a JSON-based format to export wallet data, including accounts, descriptors, keys, labels, transactions, and PSBTs.</p></li></ul></li><li><p>Explora: A visual tool to follow a chain of transactions [<a href="https://github.com/lontivero/explora">Github</a>]</p><ul><li><p>The tool utilizes APIs from mempool.space and ankr.com to retrieve transaction data</p></li><li><p>Users can input a transaction ID, view transaction details, and navigate through related inputs and outputs</p></li></ul></li><li><p>Panopticon: A tool to monitor Bitcoin addresses privately [<a href="https://github.com/OliverOffing/panopticon">Github</a>]</p><ul><li><p>Users receive alerts from their own Electrum server, while notifications are sent locally, not through Google or Apple&#8217;s notification systems.</p></li></ul></li><li><p>brute-samourai: A resumable samourai.txt backup file cracker, written in Go [<a href="https://github.com/ottosch/brute-samourai">Github</a>]</p><ul><li><p>A tool that enables brute-force attacks on Samourai Wallet backup files, based on <a href="https://github.com/cculianu/brute38">Calin Culianu&#8217;s brute38</a></p></li><li><p>Users can specify character sets, passphrase lengths, patterns, or input files.</p></li></ul></li><li><p><a href="https://www.modulo.network/key">Genesis Key</a>: A 256-bit private key designed for durable offline Bitcoin storage</p><ul><li><p>The key ensures privacy by avoiding electronics and microchips, with entropy generated offline.</p></li></ul></li><li><p><a href="https://www.21e15.com/">21e15</a>: A Micro-Seed kit to stamp seed phrases on a single stainless steel washer</p><ul><li><p>The kit allows users to store up to 240 characters (120 per side) on a quarter-sized washer.</p></li></ul></li><li><p><a href="https://cypherbox.io/">Cypherbox</a>: A modular Bitcoin-Lightning application for self-custody [<a href="https://github.com/Bamskki/Cypher-Box">Github</a>]</p><ul><li><p>Cypherbox is a fork of BlueWallet v6.5.1, made to onboard newer users to advanced self-custody, supports integration with hardware wallets, and utilizes the Coinos.io API.</p></li></ul></li><li><p><a href="https://www.bitspenda.app/">BitSpenda</a>: Send bitcoin and receive mobile money instantly. No account. No KYC.</p><ul><li><p>BitSpenda allows users to send Bitcoin, converting it into mobile money for recipients in Ghana, with plans for expansion.</p></li></ul></li><li><p><a href="https://coinflip.casino/setup">Coinflip</a>: A PoC exploring multiparty contracts on Ark</p><ul><li><p>Real-time coordination is achieved through Nostr, while Ark handles validation and settlement.</p></li></ul></li><li><p><a href="https://ajtowns.github.io/bfg/">Bitcoin Forking Guide</a>: A guide aimed at achieving consensus before code changes</p><ul><li><p>The guide outlines a six-phase process: Research and Development, Power User Exploration, Industry Evaluation, Investor Review, Finalization, and Activation.</p></li></ul></li></ul><h3><strong>Vulnerability Disclosures</strong></h3><ul><li><p>01:11:56 JavaScript injection attack: Safe{Wallet} confirms targeted TraderTraitor attack on Bybit resulting in $1.4 billion stolen [<a href="https://docsend.com/view/s/rmdi832mpt8u93s7">Bybit&#8217;s Audit report</a>] [<a href="https://x.com/safe/article/1897663514975649938">Safe{Wallet} Investigation update</a>]</p><ul><li><p>Forensic analysis confirms that the threat group TraderTraitor successfully compromised a Safe{Wallet} developer&#8217;s machine, extracted AWS session tokens from that machine in order to bypass multi-factor authentication.</p></li><li><p>It then enabled the attackers to target Bybit by spoofing their UI interface during transaction signing.</p></li><li><p>&#8220;As @adam3us suggests, #Web3 and #DeFi visibility is a general intrinsic problem of ALL Hardware Wallets, not of a specific vendor. A low power, air-gapped, small screen device will never be a good place to verify a complex Web3 or DeFi transaction.&#8221; [<a href="https://x.com/TalBeerySec/status/1893967728861458682">Tal Be&#8217;ery</a>]</p></li></ul></li><li><p>01:15:05 Malicious PyPI package &#8216;set-utils&#8217; steals Ethereum private keys by hooking wallet functions [<a href="https://thehackernews.com/2025/03/this-malicious-pypi-package-stole.html">The Hacker News</a>]</p><ul><li><p>The &#8216;set-utils&#8217; package, mimicking popular Python utilities, targeted software wallet developers.</p></li><li><p>It intercepted Ethereum private keys during wallet creation and exfiltrated them through regular on-chain transactions.</p></li></ul></li><li><p>Brain Wallet vulnerability?: A user withdraws 0.024 and 0.06 bitcoin from an exchange to a low-entropy or compromised <a href="https://mempool.space/address/bc1q975yfv05ezuake5hsv4q8h9ux2scc7z3guyayw">address</a> [<a href="https://x.com/mononautical/status/1895639824197206352">Twitter post</a>]</p><ul><li><p>Bots snipped both transactions from the mempool and stole the funds within milliseconds, ensuing a Replace-By-Fee bidding war burning the entire amount in fees.</p></li></ul></li><li><p>01:16:57 OpenSSH vulnerabilities expose clients and servers to attacks [<a href="https://www.qualys.com/2025/02/18/openssh-mitm-dos.txt">Qualys Security Advisory</a>]</p><ul><li><p>The Qualys Threat Research Unit has identified two OpenSSH vulnerabilities:</p><ul><li><p>CVE-2025-26465: MitM attack against OpenSSH&#8217;s VerifyHostKeyDNS-enabled client: allows machine-in-the-middle attacks when the VerifyHostKeyDNS option is enabled, even without user interaction.</p></li><li><p>CVE-2025-26466: DoS attack against OpenSSH&#8217;s client and server: permits pre-authentication denial-of-service attacks, consuming system resources and potentially disrupting SSH services.</p></li></ul></li></ul></li><li><p>01:17:05 USB side-channel attacks: A new privacy threat through hub congestion [<a href="https://cyberinsider.com/new-usb-side-channel-attack-exposes-keystrokes-and-browsing-activity/">CyberInsider</a>]</p><ul><li><p>Security researchers discover a novel USB side-channel attack that exploits hub congestion to monitor user activities without physical access or malware installation. The attack analyzes traffic patterns in shared USB bus architecture.</p></li><li><p>The keystroke recovery attack uses a rogue USB mouse to detect typing patterns, achieving 36.3% accuracy for password prediction within top 10 guesses. Website fingerprinting attacks reach 83.4% accuracy in identifying visited sites.</p></li></ul></li><li><p>01:17:37 Cellebrite: Critical Android security flaws exploited to target student activist in Serbia [<a href="https://techcrunch.com/2025/02/28/researchers-uncover-unknown-android-flaws-used-to-hack-into-a-students-phone/">TechCrunch</a>]</p><ul><li><p>Amnesty International discovers three zero-day vulnerabilities in Android&#8217;s Linux USB kernel, potentially affecting over a billion devices. Google has since fixed these flaws, which were used by Cellebrite&#8217;s forensic tools to unlock phones.</p></li><li><p>The vulnerabilities were uncovered during an investigation of a Serbian student activist&#8217;s phone, who was targeted by the Serbian Security Information Agency. The authorities used Cellebrite software to unlock the Samsung A32 phone without consent.</p></li></ul></li><li><p>01:17:49 Messengers vulnerabilities:</p><ul><li><p>Meshtastic firmware vulnerability allows user impersonation [<a href="https://www.hackster.io/news/mqtt-flaw-leads-to-impersonation-attack-vulnerability-in-meshtastic-firmware-2-5-18-and-lower-049f73b2d09e">Disclosure</a>]</p><ul><li><p>A flaw was discovered in Meshtastic firmware versions up to 2.5.18, enabling attackers to send messages that appear as if sent by any user.</p></li><li><p>The vulnerability involved crafting MQTT messages misinterpreted as direct text messages. However, it did not bypass PKI but caused packets to be displayed as received via PKI when actually sent using the channel key.</p></li></ul></li><li><p>EvilLoader: Android Telegram vulnerability enables malicious APK distribution through fake video files [<a href="https://www.mobile-hacker.com/2025/03/05/evilloader-unpatched-telegram-for-android-vulnerability-disclosed/">Mobile Hacker</a>]</p><ul><li><p>It works by manipulating HTML files with MP4 extensions, causing Telegram to misidentify them as legitimate videos. When users attempt to play these files, they are prompted to install external applications that could contain malware.</p></li></ul></li><li><p>Russian hackers exploit Signal&#8217;s device-linking feature for espionage [<a href="https://cloud.google.com/blog/topics/threat-intelligence/russia-targeting-signal-messenger">Google Threat Intelligence Group</a>]</p><ul><li><p>Attackers send phishing messages with spoofed QR codes, tricking victims into linking their Signal accounts to devices controlled by the hackers, enabling real-time message interception without full device compromise.</p></li><li><p>Google&#8217;s Threat Intelligence Group warns that these techniques may be used against other encrypted messaging services like WhatsApp and Telegram.</p></li></ul></li></ul></li><li><p>01:17:56 GitVenom: A cryptocurrency theft campaign using fake GitHub projects [<a href="https://securelist.com/gitvenom-campaign/115694/">Secure List</a>]</p><ul><li><p>Threat actors have created hundreds of fake GitHub repositories, posing as legitimate projects like Instagram automation tools and Bitcoin wallet managers.</p></li><li><p>These repositories contain malicious code that deploys stealers and backdoors, to compromise users&#8217; systems.</p></li><li><p>A clipboard hijacker within the malicious code replaces copied cryptocurrency wallet addresses with attacker-controlled ones.</p></li></ul></li><li><p>01:18:10 Stablecoin payment firm Infini loses $50M in exploit, developer deception suspected [<a href="https://cointelegraph.com/news/infini-loses-50-m-in-exploit-developer-deception-suspected">Coin Telegraph</a>]</p><ul><li><p>The firm lost $50 million in USDC due to an exploit by a rogue developer who retained administrative privileges after project completion.</p></li></ul></li><li><p>01:18:18 Five dollar wrench attacks:</p><ul><li><p><a href="https://www.enca.com/business/cryptocurrency-adds-new-twist-kidnapping-ransom-demands">eNCA Report</a>: Cryptocurrency is becoming a more common method for ransom demands in modern kidnappings</p><ul><li><p>Crime expert Yusuf Abramjee reports a rise in kidnapping cases with many involving express kidnappings or ransom demands.</p></li><li><p>Kidnapping operations have become more sophisticated, with specialized teams handling different stages such as tracking, abduction, and ransom negotiations.</p></li></ul></li><li><p>Streamer Amouranth, reports being attacked in a home invasion by armed intruders demanding cryptocurrency [<a href="https://www.dailystar.co.uk/news/us-news/streamer-amouranth-covered-blood-after-34784758">Daily Star</a>]</p><ul><li><p>She says they pulled her from bed, pistol-whipped her, and forced her to log into her phone at gunpoint.</p></li><li><p>Amouranth previously <a href="https://gamerant.com/amouranth-bitcoin-balance/">revealed</a> her $20 million bitcoin holdings to her audience.</p></li></ul></li><li><p>In Vietnam, a Chinese man was successfully rescued from kidnappers by Ho Chi Minh City police [<a href="https://tuoitrenews.vn/news/society/20250306/ho-chi-minh-city-police-free-chinese-man-from-chinese-kidnapping-ring/85050.html">Tuoi Tre News</a>]</p><ul><li><p>The criminal group, consisting of three Chinese nationals and three Vietnamese accomplices, attempted to extort 600,000 USDT from their victim, who was held in a remote area.</p></li></ul></li><li><p>Six men are accused of kidnapping and holding hostage a family and a nanny for five days, in October 2024, demanding $15 million in cryptocurrency. [<a href="https://archive.ph/pavf4#selection-1765.4-2105.32">Chicago Tribune</a>]</p><ul><li><p>The FBI arrested one suspect in January, while others are believed to have fled to China. Around $9 million of the ransom remains unaccounted for.</p></li></ul></li><li><p>South Korean police arrest four individuals linked to the murder of a Chinese man in Jeju Island [<a href="https://decrypt.co/307859/south-korea-police-arrest-four-murder-stabbing">Decrypt</a>]</p><ul><li><p>The victim had traveled to Jeju Island to conduct a private cryptocurrency transaction of about $52,500.</p></li></ul></li></ul></li></ul><h3><strong>Audience Questions</strong></h3><ul><li><p>Thanks to everyone who sent in questions. Remember to send yours to questions@bitcoin.review.</p><ul><li><p>01:20:00 Audience question for guests to comment on a flaw in Bitcoin Core regarding mining pools and their vulnerability against block withholding attacks, referring to <a href="https://x.com/sgbarbour/status/1892213052030038148">this post</a> -@anon</p></li></ul></li></ul><h3><strong>Privacy &amp; Other Related Bitcoin Projects</strong></h3><h4><strong>Software Releases &amp; Project Updates</strong></h4><ul><li><p>SimpleX</p><ul><li><p><a href="https://github.com/simplex-chat/simplex-chat/releases/tag/v6.3.0">v6.3.0</a></p><ul><li><p>Better groups:</p><ul><li><p>Mention members and get notified when mentioned</p></li><li><p>Send private reports to moderators</p></li><li><p>Delete, block and change role for multiple members at once (Android and desktop only)</p></li><li><p>Faster sending messages and faster deletion</p></li><li><p>Better chat navigation</p></li></ul></li><li><p>Organize chats into lists to keep track of what&#8217;s important:</p><ul><li><p>Jump to found and forwarded messages</p></li><li><p>Better privacy and security</p></li></ul></li><li><p>Private media file names:</p><ul><li><p>Message expiration in chats</p></li></ul></li></ul></li><li><p><a href="https://github.com/simplex-chat/simplex-chat/commit/7471fd2af5838dc0467aebc570b5ea75e5df3209">Privacy policy Update</a></p><ul><li><p>Add content license in groups, and stated that NO LICENSE is granted to the server operators or ourselves</p></li><li><p>Add the conditions of access to preconfigured servers via modified 3rd party applications (The previous policy version prohibited it, unintentionally)</p></li><li><p>Clarify definitions:</p><ul><li><p>&#8220;Aggregate statistics&#8221; explicitly excludes any stats that can be related to particular users</p></li><li><p>The content that can be removed changed from &#8220;identified illegal content&#8221; to &#8220;illegal content identified in publicly accessible resources&#8221;</p></li></ul></li></ul></li></ul></li><li><p>Sideband <a href="https://github.com/markqvist/Sideband/releases/tag/1.4.0">v1.4.0</a></p><ul><li><p>Add ability to export telemetry to MQTT brokers</p></li><li><p>Add MQTT renderers for all telemetry types</p></li><li><p>Add LXMF Propagation Node statistics sensor type to Telemeter</p></li><li><p>Add RNS Transport statistics sensor type to Telemeter</p></li><li><p>Add Connection Map sensor type to Telemeter</p></li><li><p>Add periodic cleaning of old telemetry data from the database</p></li></ul></li><li><p>NomadNet <a href="https://github.com/markqvist/NomadNet/releases/tag/0.6.1">v0.6.1</a></p><ul><li><p>Add tabs to the announce stream</p></li><li><p>Improve LXMF propagation node list UI</p></li><li><p>Add acceptance rate stat to propagation node list entries</p></li></ul></li><li><p>Rdsys <a href="https://gitlab.torproject.org/tpo/anti-censorship/rdsys/-/tags/1.0">v1.0</a> - First Rdsys table version</p><ul><li><p>The Tor Project replaces BridgeDB with Rdsys for distributing bridges</p><ul><li><p>moat: the type of the captcha bridge response is &#8216;moat-bridges&#8217;</p></li><li><p>bridgedb-metrics: use country if available</p></li></ul></li></ul></li><li><p>Mullvad partners with Obscura VPN and launches a &#8220;two-party VPN service that uses our WireGuard VPN servers as its exit hop&#8221;. [<a href="https://mullvad.net/en/blog/mullvad-partnered-with-obscura-vpn">Announcement</a>]</p><ul><li><p>Obscura&#8217;s custom protocol, based on QUIC, mimics HTTP/3 to bypass firewalls and censorship.</p></li></ul></li><li><p>Mynymbox launches email hosting service [<a href="https://x.com/mynymbox/status/1889084204643733741">Announcement</a>]</p><ul><li><p>Mynymbox introduces a privacy-oriented email hosting service supporting POP3, IMAP, SMTP, and webmail. Users can bring their own domain and are not restricted to a specific email client.</p></li></ul></li><li><p>Kagi now offers Privacy Pass, a cryptographic protocol that ensures user authentication without tracking personal data or searches [<a href="https://blog.kagi.com/kagi-privacy-pass">Announcement</a>]</p><ul><li><p>The protocol adds an extra privacy layer by unlinking user searches from their identity.</p></li></ul></li></ul><h4><strong>Project spotlight</strong></h4><ul><li><p>Rayhunter: Rust tool to detect cell site simulators on an orbic mobile hotspot [<a href="https://github.com/EFForg/rayhunter">Github</a>]</p><ul><li><p>Rayhunter is an open-source tool that runs on affordable Orbic RC400L mobile hotspots to detect cell-site simulators used for mobile surveillance.</p></li><li><p>The tool monitors control traffic between mobile networks and hotspots, alerting users to suspicious activities through a simple color-coded interface and storing detailed logs for expert analysis.</p></li></ul></li><li><p>RAVA: an Open Hardware True Random Number Generator based on Avalanche Noise [<a href="https://github.com/gabrielguerrer/rng_rava">Github</a>]</p><ul><li><p>RAVA is an open-source True Random Number Generator offering high-quality entropy with independent random bit generation.</p></li><li><p>It features dual entropy cores, differential design, and full transparency with accessible hardware and software for customizability and integration.</p></li></ul></li><li><p><a href="https://privx.li/">PrivX</a>: A secure, private pastebin alternative without JavaScript [<a href="https://github.com/TorDotWatch/privx">Github</a>]</p><ul><li><p>It features AES-256 encryption, assigning unique keys to each paste, and employs a zero-knowledge architecture, preventing administrators from accessing stored data.</p></li><li><p>PrivX is a fork of <a href="https://github.com/IncognitoBin/IncognitoBin">IncognitoBin</a>, and is also available on Tor <a href="http://5ubt5q7iirvcgrdeykiul77lvu5gnw3fsdhrh2jhrdn2kq35l4qoetyd.onion/">Onion</a>.</p></li></ul></li><li><p><a href="https://cypherhub.onrender.com/">CypherHub</a>: A verifiably secure dead drop for sharing Bitcoin addresses and other secrets [<a href="https://stacker.news/items/901870">Description</a>]</p><ul><li><p>A tool for sharing Bitcoin addresses and confidential information without logging into accounts</p></li><li><p>Data encryption happens client-side in the browser, ensuring the server never receives unencrypted information. The recipient decrypts it using a shared password.</p></li></ul></li></ul><h3><strong>Nostr</strong></h3><h4><strong>Project spotlight</strong></h4><ul><li><p>01:22:32 24242.io</p></li><li><p>01:22:49 nostr.media</p></li><li><p>01:22:58 <a href="https://www.frostr.org/">Frostr</a>: Simple t-of-n remote signing and key rotation protocol for nostr, using the powers of FROST [<a href="https://github.com/FROSTR-ORG">Github</a>]</p><ul><li><p>FROSTR enables users to split their secret key into decentralized, distributable shares, enhancing security.</p></li><li><p>Users can sign messages using t-of-n signing devices; if one share is compromised, the secret key remains safe.</p></li><li><p>Shares can be discarded and replaced without changing the secret key or identity.</p></li></ul></li><li><p>01:23:33 <a href="https://nostr-double-ratchet.iris.to/">nostr-double-ratchet</a>: Implementing double ratchet encryption in nostr [<a href="https://github.com/mmalmi/nostr-double-ratchet">Github</a>]</p><ul><li><p>The implementation includes features such as invite links for secure session key exchange, with installation available via npm or yarn. (The project is currently a work in progress)</p></li></ul></li><li><p>01:23:44 DVMCP: Bridging MCP servers to Nostr&#8217;s data vending machine ecosystem [<a href="https://github.com/gzuuus/dvmcp/">Github</a>]</p><ul><li><p>DVMCP enables the integration of Model Context Protocol (MCP) servers with Nostr&#8217;s decentralized Data Vending Machine (DVM) ecosystem.</p></li><li><p>The project includes packages for bridge implementation, discovery service for MCP tools, and shared utilities across components.</p></li></ul></li><li><p>01:23:53 Samiz: BLE mesh for nostr notes when the internet is down [<a href="https://github.com/KoalaSat/samiz">Github</a>]</p><ul><li><p>Samiz is a Bluetooth mesh system for sharing Nostr notes without internet, relying on local synchronization between devices.</p></li><li><p>The system works by creating a session where devices near each other can automatically share and store notes, even in remote areas or during internet outages.</p></li></ul></li><li><p>01:24:00 <a href="https://welshman.coracle.social/">Welshman</a>: A nostr toolkit focused on creating highly a configurable client system, extracted from the Coracle nostr client [<a href="https://github.com/coracle-social/welshman">Github</a>]</p><ul><li><p>&#8220;A series of independent libraries for managing every aspect of your Nostr application.&#8221;</p></li></ul></li><li><p>01:24:09 <a href="https://norma.network/">Norma</a>: A Nostr Relay Management Panel [<a href="https://github.com/Vin-it/norma">Github</a>]</p><ul><li><p>Norma (Nostr Relay Manager), is a nostr client based on NIP-86 (Relay Management API)</p></li></ul></li><li><p>01:24:20 Wallet Relay: High performance relay for enabling NWC &amp; Cashu Wallets [<a href="https://github.com/bitvora/wallet-relay">Github</a>]</p><ul><li><p>&#8220;Wallet Relay is a specialized relay for wallet service providers to process NWC and Cashu Wallet events.&#8221;</p></li></ul></li><li><p>01:24:27 <a href="https://nostr0.vercel.app/">Nostr0</a>: A web application that allows you to search and visualize Nostr events using npubs [<a href="https://github.com/Negr087/Nostr0">Github</a>]</p></li><li><p>01:24:35 nAuth Protocol: decentralized two-party Authentication and secure document transmission [<a href="https://github.com/trbouma/safebox/blob/nauth-refactor/docs/NAUTH-PROTOCOL.md">Github</a>]</p><ul><li><p>The nAuth protocol enables two parties to authenticate each other and securely share documents without third-party involvement</p></li><li><p>Designed for scenarios like patient-physician interactions, nAuth allows either party to initiate authentication, accommodating devices with limitations such as the absence of a camera.</p></li></ul></li><li><p>01:24:43 Hostr: Rental accommodation using purely peer-to-peer technologies such as Nostr [<a href="https://github.com/sudonym-btc/hostr">Github</a>]</p><ul><li><p>The projects implements several NIPs: NIP-01 for event creation and subscription, NIP-05 for mapping Nostr keys to DNS-based identifiers, and NIP-33 for creating and updating listings and bookings.</p></li></ul></li></ul><h4><strong>Software Releases &amp; Project Updates</strong></h4><ul><li><p>Primal</p><ul><li><p><a href="https://github.com/PrimalHQ/primal-android-app/releases/tag/2.1.9">v2.1.9</a></p><ul><li><p>Multi-account feature</p></li><li><p>Deep-linking</p></li><li><p>Articles pagination</p></li><li><p>Share photo/video via Primal app</p></li><li><p>Bigger previews for Github links</p></li><li><p>Legends contributions</p></li><li><p>nevent with relay hints when copy note id</p></li><li><p>nevent and nprofile when creating primal share links</p></li><li><p>nevent and nprofile in the note editor for mentioned notes and users</p></li><li><p>Ellipsis links in note content</p></li></ul></li><li><p><a href="http://njump.me/nevent1qgspywh6ulgc0w3k6mwum97m7jkvtxh0lcjr77p9jtlc7f0d27wlxpsqypp92r7m4dnd9t2sf8uzju3l0wp3jhte5nx4lc7vjey2m4txq46r7lgzg8p">v2.1.6</a></p><ul><li><p>Improved feeds</p></li><li><p>Deep linking threads, articles, profiles</p></li></ul></li></ul></li><li><p>Coracle</p><ul><li><p><a href="https://github.com/coracle-social/coracle/releases/tag/0.6.8">v0.6.8</a></p><ul><li><p>Correctly fetch and render NIP 22 comments</p></li></ul></li><li><p><a href="https://github.com/coracle-social/coracle/releases/tag/0.6.7">v0.6.7</a></p><ul><li><p>Add note info to DMs</p></li><li><p>Make lnurl parsing more robust</p></li></ul></li><li><p><a href="https://github.com/coracle-social/coracle/releases/tag/0.6.6">v0.6.6</a></p><ul><li><p>Show complete website/lnurl</p></li><li><p>Scan images for sensitive content</p></li><li><p>Make muting on feeds more strict</p></li><li><p>Apply muted words to nip05</p></li></ul></li><li><p><a href="https://github.com/coracle-social/coracle/releases/tag/0.6.1">v0.6.1</a></p><ul><li><p>Use wasted space on mobile notes</p></li><li><p>Show PoW difficulty in settings</p></li></ul></li><li><p><a href="https://github.com/coracle-social/coracle/releases/tag/0.6.0">v0.6.0</a></p><ul><li><p>Add support for tor/local relays</p></li><li><p>Use nstart for onboarding process</p></li><li><p>Show more details on reaction notifications</p></li><li><p>Improve mutes, add setting to completely hide muted people</p></li><li><p>Add kind 20 rendering support</p></li><li><p>Add pinned note support</p></li><li><p>Remove broadcasting of note parents</p></li><li><p>Add note scheduling via DVM</p></li></ul></li></ul></li><li><p>Flotilla</p><ul><li><p><a href="https://github.com/coracle-social/flotilla/releases/tag/0.2.12">v0.2.12</a></p><ul><li><p>Make error reporting and analytics optional</p></li><li><p>Replace long press with tap target</p></li><li><p>Add reply to chat on mobile</p></li></ul></li><li><p><a href="https://github.com/coracle-social/flotilla/releases/tag/0.2.11">v0.2.11</a></p><ul><li><p>Add in-app signup flow on ios</p></li><li><p>Add profile deletion</p></li></ul></li></ul></li><li><p>Iris <a href="https://njump.me/nevent1qqsvw58hj63rmlnmzvmv5nsrge9rfy8ghpx5ws2r4gh27afvt6s3ksspzemhxue69uhhyetvv9ujumn0wd68ytnzv9hxgq3qg53mukxnjkcmr94fhryzkqutdz2ukq4ks0gvy5af25rgmwsl4ngqywfgs9">Update</a></p><ul><li><p>Deploy double ratchet messaging (See Iris software release)</p></li></ul></li><li><p>Yakihonne</p><ul><li><p>Web <a href="https://njump.me/nevent1qgszpxr0hql8whvk6xyv5hya7yxwd4snur4hu4mg5rctz2ehekkzrvcqyr8alk7afvm2waes4wuhpq44rhdw49mn95k9asc7gqj2mmcf7n8d6shdg4n">v4.4.0</a></p><ul><li><p>Zap polls can now be added directly from the list or created instantly within notes and comments</p></li><li><p>Muting users is now more reliable</p></li><li><p>Users can download and export their NWC secret for wallets</p></li><li><p>Wallets and account credentials are automatically saved upon signup and logout</p></li><li><p>Faster login and signup when interacting with Yakihonne while logged out</p></li></ul></li><li><p>Mobile <a href="https://njump.me/nevent1qgszpxr0hql8whvk6xyv5hya7yxwd4snur4hu4mg5rctz2ehekkzrvcqyr8alk7afvm2waes4wuhpq44rhdw49mn95k9asc7gqj2mmcf7n8d6shdg4n">v1.6.6</a></p><ul><li><p>Ability to export your NWC wallets and your keys</p></li><li><p>Blink wallet is now available as one of the external wallets that can be used</p></li><li><p>Private messages drafts are now available</p></li><li><p>Notes stats optimised</p></li><li><p>Wallet management overall performance has been improved</p></li></ul></li></ul></li><li><p>nos.social</p><ul><li><p><a href="https://github.com/planetary-social/nos/releases/tag/v1.2.1-305">v1.2.1</a></p><ul><li><p>Add Lists view and two ways to navigate to it</p></li><li><p>Add view for editing a list&#8217;s title and description</p></li><li><p>Add List detail view</p></li><li><p>Add view for managing users in a list</p></li><li><p>Add ability to delete lists</p></li><li><p>Add analytics for feed source selection and lists</p></li><li><p>Internal Changes:</p><ul><li><p>Add function for creating a new list and a test verifying list editing</p></li><li><p>Localized strings on the feed filter drop-down view</p></li><li><p>Audit codebase for strict access control and mutability annotations</p></li></ul></li></ul></li></ul></li><li><p>Keychat App</p><ul><li><p><a href="https://github.com/keychat-io/keychat-app/releases/tag/1.27.2">v1.27.2</a> - Amber Login</p><ul><li><p>Support for logging in or importing accounts using amber app</p></li><li><p>Support for amber&#8217;s signMessage, signEvent, nip04, and nip44</p></li><li><p>Refactored routing for the room settings page</p></li><li><p>Browser support for sharing URLs to rooms</p></li></ul></li><li><p><a href="https://github.com/keychat-io/keychat-app/releases/tag/1.26.8%2B6322">v1.26.8</a></p><ul><li><p>Add a scan button to the Cashu page</p></li><li><p>Remove pubkeys from listening when disabling the chat identity</p></li></ul></li></ul></li><li><p>Amber</p><ul><li><p><a href="https://github.com/greenart7c3/Amber/releases/tag/v3.2.5">v3.2.5</a></p><ul><li><p>Add scroll bars</p></li></ul></li><li><p><a href="https://github.com/greenart7c3/Amber/releases/tag/v3.2.3">v3.2.3</a></p><ul><li><p>Add translation string for sign_message method</p></li><li><p>Add a log when encryption/decryption fails</p></li></ul></li><li><p><a href="https://github.com/greenart7c3/Amber/releases/tag/v3.2.2">v3.2.2</a></p><ul><li><p>Allow to always reject permissions on the multi event screen</p></li><li><p>Allow copying the bunker uri after connected</p></li><li><p>Don&#8217;t try to url decode requests by native apps</p></li></ul></li></ul></li><li><p>Algo Relay</p><ul><li><p><a href="https://github.com/bitvora/algo-relay/releases/tag/v0.2.0">v0.2.0</a></p><ul><li><p>User Dashboard:</p><ul><li><p>Allows any npub to login to the relay</p></li><li><p>Ability to view the data used by the algorithm to generate a feed</p></li><li><p>Ability to customize the weights to curate your own feed</p></li></ul></li></ul></li><li><p><a href="https://github.com/bitvora/algo-relay/releases/tag/v0.1.5">v0.1.5</a></p><ul><li><p>Switch import back to 30 days</p></li><li><p>Default to kind 1 if empty filter</p></li><li><p>Sequential Migrations</p></li><li><p>Page Handlers: introduces a new pattern to define static pages and api endpoints with a mux router</p></li></ul></li></ul></li><li><p>0xChat App <a href="https://github.com/0xchat-app/0xchat-app-main/releases/tag/v1.4.7-beta">v1.4.7-beta</a></p><ul><li><p>Major Updates:</p><ul><li><p>Private chat implementation changed to NIP-104 Nostr MLS (NIP-104 MLS is still in beta and should be used for testing purposes only.)</p></li></ul></li><li><p>Other Updates:</p><ul><li><p>NIP-17 and NIP-29 messages now support <code>q</code> tags</p></li><li><p>You can swipe left to reply on your own messages</p></li><li><p>Chat messages now support code block display</p></li><li><p>Copy images from the clipboard</p></li></ul></li></ul></li><li><p>Nostur <a href="https://github.com/nostur-com/nostur-ios-public/releases/tag/1.18.1">v1.18.1</a></p><ul><li><p>Floating mini video player</p></li><li><p>Videos:</p><ul><li><p>Save to library</p></li><li><p>Copy video URL</p></li><li><p>Add bookmark</p></li></ul></li><li><p>Improve video stream / chat view</p></li><li><p>Top zaps on live chat</p></li><li><p>Posting to Picture-first</p></li><li><p>Profile view:</p><ul><li><p>Show interactions with you (conversations, reactions, zaps, reposts)</p></li><li><p>Show actual reactions instead of only Likes</p></li></ul></li><li><p>Improve search + Bookmark search</p></li><li><p>Detect nsfw / content-warning in posts</p></li><li><p>&#8216;Show more&#8217; to show reactions outside Web of Trust</p></li><li><p>&#8216;Show more&#8217; to show zaps outside Web of Trust</p></li><li><p>Support .avif image format, .mp3, and .m4v video format</p></li><li><p>Improve zap verification for changed wallets</p></li><li><p>Improve outbox support</p></li><li><p>Show label on restricted posts</p></li><li><p>Low data mode: load media in app on tap instead of external browser</p></li></ul></li><li><p>Nowser <a href="https://github.com/haorendashu/nowser/releases/tag/1.0.0">v1.0.0</a></p><ul><li><p>Linux webview support</p></li><li><p>NIP46 encrypt and decrypt method change to NIP44</p></li><li><p>i18n support</p></li><li><p>Android signer try to get code by currentUser</p></li><li><p>URL input support direct search someting</p></li><li><p>Web URl input add suggestion</p></li></ul></li><li><p>BitBanana</p><ul><li><p><a href="https://github.com/michaelWuensch/BitBanana/releases/tag/v0.9.1">v0.9.1</a></p><ul><li><p>Pick first hop on lightning payments (LND)</p></li><li><p>Rebalance channels (LND, use first and last hop in a self-payment)</p></li><li><p>Inspect LND and Core Lightning logs</p></li><li><p>Add search and verbosity filter to log view</p></li></ul></li><li><p><a href="https://github.com/michaelWuensch/BitBanana/releases/tag/v0.9.0">v0.9.0</a></p><ul><li><p>Add Coin Control support</p></li><li><p>&#8220;Send all&#8221; option</p></li><li><p>Support for custom BlockExplorers on Regtest nodes</p></li><li><p>Fixes for nodes with more than 500 outgoing lightning payments</p></li><li><p>Performance improvements for nodes with lots of payments</p></li></ul></li></ul></li><li><p>Kyoto <a href="https://github.com/rustaceanrob/kyoto/releases/tag/v0.9.0">v0.9.0</a></p><ul><li><p>Introduce log level and optimize release builds to remove heap allocations for debug messages</p></li><li><p>Configure a custom DNS resolver</p></li></ul></li><li><p>Mostro <a href="https://github.com/MostroP2P/mostro/releases/tag/0.13.2">v0.13.2</a></p><ul><li><p>Feat: Put the user&#8217;s reputation updated in the events</p></li><li><p>Feat: Do not allow a taker to take multiple orders at once</p></li><li><p>Shows relay list on relay list event job</p></li><li><p>Fix on some full privacy cases</p></li><li><p>Correct full privacy mode check when orders arrives</p></li></ul></li><li><p>Grain <a href="https://github.com/0ceanSlim/grain/releases/tag/v0.3.0">v0.3.0</a></p><ul><li><p>Nostr Login &amp; Profile Page:</p><ul><li><p>Introduce Nostr login to the front end, allowing users to authenticate using their Nostr key.</p></li><li><p>Future updates will add more front-end functionality, including event management, delete requests, relay configuration for operators, and a dashboard with relay statistics.</p></li></ul></li><li><p>User Sync (Experimental):</p><ul><li><p>New user sync functionality allows the relay to sync events for its users from their outboxes.</p></li><li><p>Add configurable sync options: define which event kinds to sync, define a limit of how many events to retrieve, and exclude non-whitelisted users from sync.</p></li></ul></li></ul></li><li><p>Nostrmo <a href="https://github.com/haorendashu/nostrmo/releases/tag/2.9.6">v2.9.6</a></p><ul><li><p>This release mainly change remote signer (NIP-46) &#8216;s encrypt method from NIP-04 to NIP-44.</p></li></ul></li><li><p>OpenLibrarian <a href="https://github.com/RydalWater/OpenLibrarian/releases/tag/v0.1.7">v0.1.7</a></p><ul><li><p>Add Book reviews</p></li><li><p>NIP-07 Login</p></li><li><p>Extensive client-side rebuild</p></li><li><p>Add retries of <code>get_default_pages</code> on progress objects</p></li></ul></li><li><p>GitPlaza: Nostr git stuff client for Desktop [<a href="https://codeberg.org/dluvian/gitplaza">Codeberg</a>]</p><ul><li><p>GitPlaza is a Desktop Nostr client specialized in handling git stuff</p></li><li><p><a href="https://codeberg.org/dluvian/gitplaza/releases/tag/v0.1.0">V0.1.0</a> - First release</p><ul><li><p>Login via nsec</p></li><li><p>Show activity feed of people you follow</p></li><li><p>Create issues</p></li><li><p>Comment on issues</p></li></ul></li></ul></li></ul><h3><strong>Lightning + L2+</strong></h3><h4><strong>Project spotlight</strong></h4><ul><li><p>Chantools: Tools for managing LND and Lightning Network channels [<a href="https://github.com/lightninglabs/chantools">Github</a>]</p><ul><li><p>Chantools is a collection of tools for managing LND and Lightning Network channels, especially in case of failures.</p></li><li><p>It provides recovery options for scenarios like node crashes, missing backups, or issues with unconfirmed channels.</p></li></ul></li><li><p><a href="https://hashpool.dev/">Hashpool</a>: An accountless mining pool that represents mining shares as ecash tokens [<a href="https://github.com/vnprc/hashpool">Github</a>]</p><ul><li><p>The system utilizes &#8220;eHash&#8221; tokens, which are ecash tokens backed by proof of work rather than bitcoin. These tokens mature over time and can be traded as mining futures, allowing miners to hedge risks and buyers to purchase bitcoin at discounted rates.</p></li><li><p>While Hashpool operates on a custodial basis through ecash mints, it offers perfect privacy through blind signatures. The platform enables small-scale miners to participate without KYC requirements and maintains no minimum withdrawal thresholds.</p></li></ul></li><li><p><a href="https://t.me/zap_gram_bot">ZapGram</a>: Bitcoin Lightning Wallet on Telegram [<a href="https://github.com/mozharov/zapgram">Github</a>]</p><ul><li><p>ZapGram integrates a Bitcoin Lightning wallet directly into Telegram, permits transactions within the messaging platform.</p></li></ul></li><li><p><a href="https://questforsats.com/">Quest for Sats</a>: Geocaching with Bitcoin</p><ul><li><p>Quest for Sats combines geocaching with Bitcoin, allow users to find hidden containers in their area and withdraw their earnings using a Lightning wallet.</p></li></ul></li></ul><h4><strong>Software Releases &amp; Project Updates</strong></h4><ul><li><p>CLN <a href="https://github.com/ElementsProject/lightning/releases/tag/v25.02">v25.02</a></p><ul><li><p>Highlights for users:</p><ul><li><p>Channel backup turns our peers into watchtowers by now allowing your node to generate penalty transactions</p></li><li><p>Blacklisted runes can now be restored via <code>relist</code></p></li><li><p>xpay has many, many bugfixes, and is now almost seamlessly compatible when <code>xpay-handle-pay</code> is used</p></li><li><p><code>lightning-cli</code> has neater help output, and doesn&#8217;t crash occasionally on xpay notifications</p></li><li><p><code>setconfig</code> does more safety checks and uses a separate &#8220;config.setconfig&#8221; file for runtime changes</p></li></ul></li><li><p>Highlights for the network:</p><ul><li><p>Splicing: stricter checking for better interoperability with Eclair.</p></li></ul></li><li><p>Highlights for developers:</p><ul><li><p>clnrest is now a rust plugin</p></li><li><p><code>listpeerchannels</code> now contains fields<code>their_max_htlc_value_in_flight</code> and <code>our_max_htlc_value_in_flight</code> to better calculate channel limits</p></li><li><p>New notifications <code>plugin_stopped</code> and <code>plugin_started</code></p></li><li><p><code>fetchinvoice</code> now has BIP353 DNS payment instruction support</p></li></ul></li></ul></li><li><p>Lightning Terminal <a href="https://github.com/lightninglabs/lightning-terminal/releases/tag/v0.14.1-alpha">v0.14.1</a></p><ul><li><p>This version of Lightning Terminal (LiT) ships the first update to the non-experimental version of Taproot Asset Channels</p></li><li><p>Breaking changes</p><ul><li><p>Taproot Asset Channels: Taproot Asset channels are NOT backward compatible with any previous version of Lightning Terminal</p></li><li><p>Oracle RPC: The RPC protobuf definitions for the Price Oracle have changed. Asset exchange rates are now expressed as FixedPoint to achieve better precision</p></li><li><p>Configuration changes: The configuration value and command line flag now needs a value and is no longer a boolean. The value now controls whether the node&#8217;s universe database can be accessed over RPC and either read or written to or both.</p></li><li><p><code>litcli</code> changes: The Taproot Asset Channel related sub commands of <code>litcli ln</code> no longer require a custom macaroon to be specified, they now work with the default <code>lit.macaroon</code></p></li></ul></li></ul></li><li><p>Phoenix Wallet <a href="https://github.com/ACINQ/phoenix/releases/tag/android-v2.5.0">v2.5.0</a></p><ul><li><p>(android) Improved scanner performances: The scanner should be able to read QR codes faster, and do so on a wider range of devices</p></li><li><p>Access to Tor now requires a third-party Tor Proxy VPN app (e.g. Orbot): With the Tor connection managed as a persistent VPN by a dedicated app, the connection is more stable, and background payments work much better.</p></li><li><p>(ios) Display the final wallet balance in the home screen: Pending on-chain funds are now displayed in an updated window in the Home screen ; it also shows the funds available in the final wallet.</p></li><li><p>(android) Removed legacy app: The old legacy app has now been removed. Along with other optimisations, this means the APK is now much smaller (16.5 MB instead of 72.5 MB).</p></li><li><p>Note that there has been a major database rework in this version, which is not visible to the user but impacted many files in the project.</p></li></ul></li><li><p>Phoenixd <a href="https://github.com/ACINQ/phoenixd/releases/tag/v0.5.0">v0.5.0</a></p><ul><li><p>Major rework of the internal payments db</p></li><li><p>No more linux native build issues due to old toolchain, should build with no dependency on most recent distributions</p></li><li><p>Rolling log file</p></li><li><p>Fixed a memory leak in the TCP reconnection logic</p></li><li><p>New <code>--seed-path</code> configuration option</p></li><li><p>Ability to lookup outgoing payment by payment hash</p></li></ul></li><li><p>Zeus <a href="https://github.com/ZeusLN/zeus/releases/tag/v0.10.0-rc5">v0.10.0-rc5</a></p><ul><li><p>Renewable channels</p></li><li><p>NWC client support</p></li><li><p>Ability to create multiple Embedded LND &#8216;node in the phone&#8217; wallets</p></li><li><p>Ability to delete Embedded LND wallets</p></li><li><p>Embedded LND: v0.18.5-beta</p></li><li><p>New share button (share ZEUS QR images)</p></li><li><p>Activity: highlight filter icon when filters active</p></li><li><p>Tools: Export Activity CSVs, Developer tools</p></li><li><p>Activity: filter by max amount, memo, and note</p></li><li><p>CLNRest: add payment timeout setting</p></li><li><p>Receive: add advanced settings toggle</p></li><li><p>ZEUS Pay: ability to delete addresses</p></li></ul></li><li><p>Fedimint <a href="https://github.com/fedimint/fedimint/releases/tag/v0.6.0">v0.6.0</a> - On-Chain for Everyone</p><ul><li><p>The on-chain wallet is no longer considered &#8220;expert-only&#8221;</p></li><li><p>Other highlights since v0.5</p><ul><li><p>Federation will now reject attempt to reuse ecash blind nonces, preventing possibility of loss of funds even in the event of client-side bugs and data corruption</p></li><li><p>Fedimint will now query (configurable) external sources for feerate information to improve real time fee estimation</p></li><li><p>On-chain feerate multiplier have been lowered, as it no longer needs to be as conservative</p></li><li><p>LN payment events are now tracked, allowing tracking profit and fees statistics</p></li><li><p>It&#8217;s now possible to customize LNv2 gateway fees</p></li><li><p>Client recovery has been optimized and should be faster and use less data</p></li><li><p>Core lightning gateway is no longer supported</p></li><li><p>Work has been started on Iroh networking integration</p></li><li><p>Fedimintd should use less memory now</p></li></ul></li></ul></li><li><p>Alby</p><ul><li><p>Hub</p><ul><li><p><a href="https://github.com/getAlby/hub/releases/tag/v1.15.0">v1.15.0</a> - Ian Goldberg</p><ul><li><p>One-click connections for self-hosted hubs</p></li><li><p>Add pagination to tx list</p></li><li><p>Add peer and return_to query parameters to peer connection page</p></li><li><p>Show app creation time in connection summary</p></li><li><p>Show wallet pubkey on connection summary</p></li><li><p>Add app cleanup page</p></li><li><p>Add swap alert</p></li><li><p>Show total and reserved balance in spending balance tooltip</p></li></ul></li><li><p><a href="https://github.com/getAlby/hub/releases/tag/v1.14.2">v1.14.2</a> - Mike Godwin</p><ul><li><p>In this release we also add some cool new widgets to the home screen and many new apps to the app store. Alby Hub now has a healthcheck indicator, better fiat support, NIP-44 encryption, and a way for self-hosters to support Alby! We&#8217;ve also added basic swap functionality to the node page so you can more easily manage your liquidity without having to open new channels.</p></li><li><p>The Cashu backend was also updated - you can now recover stuck funds, and for new users you will have a recovery phrase which you can recover your funds in other wallets.</p></li><li><p>New features:</p><ul><li><p>Add boltz.exchange swap out option</p></li><li><p>Add boltz swap in dialog</p></li><li><p>Use nip44 and versioning</p></li><li><p>PostgreSQL support</p></li><li><p>Enable multi-path payments in LND</p></li><li><p>Node page revamp for web and mobile</p></li><li><p>Display specific notes about counterparty above open channel buttons on increase incoming/outgoing flows</p></li><li><p>Show failure reason on transaction modal in transaction list</p></li><li><p>Add nostrcheck-server to Appstore</p></li><li><p>Add new apps to Hub&#8217;s Store (nostter, btcpay, coracle, lnbits)</p></li><li><p>Add new apps to appstore</p></li><li><p>Phoenixd subwallets</p></li><li><p>Add same counterparty alerts while opening channels</p></li><li><p>Currency switcher</p></li></ul></li></ul></li></ul></li><li><p>Go <a href="https://github.com/getAlby/go/releases/tag/v1.10.0">v1.10.0</a></p><ul><li><p>Support for PicknPay QRs</p></li><li><p>BTC Map to find places to spend sats</p></li><li><p>Improve Skeleton animations across the app</p></li></ul></li><li><p>bitcoin-connect <a href="https://github.com/getAlby/bitcoin-connect/releases/tag/v3.7.0">v3.7.0</a></p><ul><li><p>Add alby hub</p></li><li><p>Add coinos connector</p></li><li><p>Add connection success screen</p></li><li><p>Add slide up animation on modal open in mobile</p></li><li><p>Add disconnect button while connecting a wallet</p></li><li><p>Add NWA &amp; Alby Go</p></li></ul></li><li><p>js-sdk</p><ul><li><p><a href="https://github.com/getAlby/js-sdk/releases/tag/v4.1.0">v4.1.0</a></p><ul><li><p>Simplify NWA flow</p></li><li><p>Add sign message method to Alby OAuth Client</p></li></ul></li><li><p><a href="https://github.com/getAlby/js-sdk/releases/tag/v4.0.0">v4.0.0</a></p><ul><li><p>In this release the NWC deeplink flow is improved to better support different kinds of http-accessible wallets</p></li><li><p>We also remove a dependency on an ESM event emitter package which was causing build errors in some projects</p></li><li><p>New features</p><ul><li><p>New NWC deeplink flow to support other relays and wallet pubkeys</p></li><li><p>Add custom-timeout-values-for-requester-method</p></li><li><p>Custom <code>EventEmitter</code> classes</p></li><li><p>Add optional metadata field to <code>get_info</code> response</p></li></ul></li></ul></li></ul></li></ul></li><li><p>Ark Labs HQ wallet-sdk <a href="https://github.com/ArkLabsHQ/wallet-sdk/releases/tag/v0.0.7">v0.0.7</a></p><ul><li><p>export <code>ArkAddress</code> and <code>VtxoTapscript</code></p></li><li><p>Make the lib compatible with webpack</p></li><li><p><code>Settle</code> implementation</p></li></ul></li><li><p>Ark <a href="https://github.com/ark-network/ark/releases/tag/v0.5.0">v0.5.0</a> - Branch-only Signing Sessions and Connector Trees</p><ul><li><p>New Features</p><ul><li><p>Branch-only VTXO Tree Signing: Optimizes VTXO tree signing; drastically cuts down on the number of signatures you have to produce, making rounds quicker and less resource-intensive.</p></li><li><p>Connector trees: Another notable addition is the move from a linear connector chain to a tree structure.</p></li></ul></li><li><p>Optimizations</p><ul><li><p>Network compatibility and transaction costs</p></li><li><p>Round processing and client interaction</p></li><li><p>Scalability improvements</p></li><li><p>Client SDK API update</p></li></ul></li></ul></li><li><p>Taproots assets <a href="https://github.com/lightninglabs/taproot-assets/releases/tag/v0.5.1">v0.5.1</a></p><ul><li><p>Database Migrations: <code>tapd</code> v0.5.1 contains non-revertible database migrations.</p></li><li><p>Breaking changes</p><ul><li><p>Downstream Projects: <code>litd</code> v0.14.x-alpha enhancements require both channel peers to upgrade to a <code>litd</code> version &gt;= v0.14.0-alpha to continue Lightning Channel functionality</p></li><li><p><code>tapd</code> v0.5.x changes</p><ul><li><p>Oracle RPC: The RPC protobuf definitions for the Price Oracle have changed</p></li><li><p>Configuration changes: The configuration value and command line flag now needs a value and is no longer a boolean</p></li></ul></li></ul></li></ul></li><li><p>lightning-kmp <a href="https://github.com/ACINQ/lightning-kmp/releases/tag/v1.9.0">v1.9.0</a></p><ul><li><p>Rename<code>OfferIssuerId</code></p></li><li><p>Simplify outgoing payment state machine</p></li><li><p>Remove support for <code>push_amount</code></p></li><li><p>Use shared input&#8217;s txOut in <code>shouldSignFirst</code></p></li><li><p>Make the project multi-modules</p></li><li><p>Correctly set <code>next_commitment_number</code> during splice reconnect</p></li><li><p>Add <code>require_confirmed_input</code> to RBF messages</p></li><li><p>Add a <code>succeededAt</code> timestamp to payments</p></li></ul></li><li><p>validating-lightning-signer <a href="https://gitlab.com/lightning-signer/validating-lightning-signer/-/releases/v0.13.0">v0.13.0</a> - Celestial Citadel</p><ul><li><p>Added:</p><ul><li><p>configure SimplePolicy values using vlsd2.toml</p></li><li><p>fuzz: basic fuzzing of the vls-core crate</p></li><li><p>developer flag for dev messages and fields</p></li><li><p>core: oid derivation for ldk channel id</p></li><li><p>protocol: implement sign_holder_htlc_tx for LDK / phase-2 code path</p></li></ul></li><li><p>Changed:</p><ul><li><p>core: Add new and oid methods to ChannelId and remove the oid/channel_id utility methods</p></li><li><p>LSS: split lightning-storage-server into library and lssd</p></li></ul></li></ul></li><li><p>SideSwap <a href="https://github.com/sideswap-io/sideswapclient/releases/tag/v1.7.0">v1.7.0</a></p><ul><li><p>New swaps API</p></li><li><p>Fee discount</p></li><li><p>Cross-wallet swaps</p></li><li><p>Peg-in/peg-out wallet balance</p></li></ul></li><li><p>CDK <a href="https://github.com/cashubtc/cdk/releases/tag/v0.7.1">v0.7.1</a></p><ul><li><p>Mint builder add ability to set custom derivation paths</p></li></ul></li><li><p>eNuts is no longer maintained [<a href="https://njump.me/nevent1qqs0jn2f7g4sm4s9gu9umq5gw8jr0wa3jg4vafhsjrxk4y2tl7yaj5spz4mhxue69uhhyetvv9ujuerpd46hxtnfduhsygzsm98u9kzcp35zkpc62shck8335gqtq5yt4w26xwl0pp2a72qavvpsgqqqqqqsjlh343">Note</a>]</p></li></ul><h3><strong>Boosts</strong></h3><ul><li><p>01:25:36 Thanks to everyone who streamed sats, and shoutout to our top boosters:</p><ul><li><p>[&#127942; TOP BOOSTER] @sean (3,000 sats) &#8220;Open sourced decentralized CIA? Sounds like y&#8217;all need to tap into the intellectual Silk Road &#128684;&#8221;</p></li><li><p>@pink monkey (2,000 sats)</p></li><li><p>@Anonymous (2,000 sats)</p></li><li><p>@martinbarilik (750 sats) &#8220;Short AI intro &#128513; right &#8230;&#8221;</p></li><li><p>@Momo Tahmasbi (100 sats) &#8220;Arkansas Traveler was a great song recommendation!&#8221;</p></li><li><p>@jespada (100 sats) &#8220;Zzzzap&#8221;</p></li></ul></li></ul><h3><strong>Tech Tips of the Day</strong></h3><ul><li><p>Encoding data within emoji using unicode variation selectors [<a href="https://paulbutler.org/2025/smuggling-arbitrary-data-through-an-emoji/">Paul Butler&#8217;s Blog post</a>]</p><ul><li><p>A demonstration on how to encode arbitrary data within a single emoji by utilizing Unicode variation selectors, which modify character presentation without visible changes.</p></li><li><p>By appending sequences of these selectors to a base character, data can be concealed within any Unicode character.</p></li></ul></li><li><p>Bypassing hotspot restrictions for data [<a href="https://juraj.bednar.io/en/blog-en/2025/03/07/bypassing-hotspot-restrictions-for-data/">Article by Juraj Bednar</a>]</p><ul><li><p>Mobile carriers often detect tethering by monitoring Time to Live (TTL) values in data packets. Standard mobile devices send packets with TTL of 64, while tethered devices show TTL of 63.</p></li><li><p>The solution involves setting device TTL to 65, making tethered traffic appear as direct phone traffic with TTL 64.</p></li></ul></li><li><p>WA-Tunnel: Tunneling Internet traffic over Whatsapp [<a href="https://github.com/aleixrodriala/wa-tunnel">Github</a>]</p><ul><li><p>WA-Tunnel allows TCP data tunneling via WhatsApp, useful for bypassing network restrictions such as limited carrier data.</p></li><li><p>The system works by sending network packages as WhatsApp messages, splitting large data into files or text to avoid message limits.</p></li></ul></li></ul><h3><strong>Bitcoin Optech Newsletter</strong></h3><ul><li><p>Highlights from recent Bitcoin Optech Newsletters</p><ul><li><p><a href="https://bitcoinops.org/en/newsletters/2025/03/07/">344</a></p><ul><li><p>Disclosure of fixed LND vulnerability allowing theft: Matt Morehouse <a href="https://delvingbitcoin.org/t/disclosure-lnd-excessive-failback-exploit/1493">posted</a> to Delving Bitcoin to announce the responsible disclosure of a vulnerability that affected LND versions before 0.18.</p></li><li><p>Discussion about Bitcoin Core&#8217;s priorities: several blog posts by Antoine Poinsot about the future of the Bitcoin Core project were linked in a <a href="https://delvingbitcoin.org/t/antoine-poinsot-on-bitcoin-cores-priorities/1470/">thread</a> on Delving Bitcoin</p></li></ul></li><li><p><a href="https://bitcoinops.org/en/newsletters/2025/02/28/">343</a></p><ul><li><p>Ignoring unsolicited transactions: Antoine Riard <a href="https://mailing-list.bitcoindevs.xyz/bitcoindev/e98ec3a3-b88b-4616-8f46-58353703d206n@googlegroups.com/">posted</a> to Bitcoin-Dev two draft BIPs that would allow a node to signal that it will no longer accept tx messages that it had not requested using an inv message, called unsolicited transactions.</p></li></ul></li><li><p><a href="https://bitcoinops.org/en/newsletters/2025/02/21/">342</a></p><ul><li><p>Allowing mobile wallets to settle channels without extra UTXOs: Bastien Teinturier <a href="https://delvingbitcoin.org/t/zero-fee-commitments-for-mobile-wallets/1453">posted</a> to Delving Bitcoin about an opt-in variation of v3 commitments for LN channels that would allow mobile wallets to settle channels using the funds within the channel for all cases where theft is possible.</p></li><li><p>Continued discussion about an LN quality of service flag: Joost Jager <a href="https://delvingbitcoin.org/t/highly-available-lightning-channels-revisited-route-or-out/1438">posted</a> to Delving Bitcoin to continue discussion about adding a quality of service flag to the LN protocol to allow nodes to signal that one of their channels was highly available.</p></li></ul></li><li><p><a href="https://bitcoinops.org/en/newsletters/2025/02/14/">341</a></p><ul><li><p>Continued discussion about probabilistic payments: following Oleksandr Kurbatov&#8217;s <a href="https://delvingbitcoin.org/t/emulating-op-rand/1409">post</a> to Delving Bitcoin last week about emulating an OP_RAND opcode</p></li><li><p>Continued discussion about ephemeral anchor scripts for LN: Matt Morehouse <a href="https://delvingbitcoin.org/t/which-ephemeral-anchor-script-should-lightning-use/1412/8">replied</a> to the thread about what ephemeral anchor script LN should use for future channels</p></li><li><p>Stats on orphan evictions: developer 0xB10C <a href="https://delvingbitcoin.org/t/stats-on-orphanage-overflows/1421/">posted</a> to Delving Bitcoin with statistics about the number of transactions evicted from the orphan pools for his nodes</p></li><li><p>Updated proposal for updated BIP process: Mark &#8220;Murch&#8221; Erhardt <a href="https://mailing-list.bitcoindevs.xyz/bitcoindev/25449597-c5ed-42c5-8ac1-054feec8ad88@murch.one/">posted</a> to the Bitcoin-Dev mailing list to announce that his draft BIP for a revised BIP process has been assigned the identifier BIP3 and is ready for additional review</p></li></ul></li></ul></li></ul><h3><strong>News &amp; Noteworthy</strong></h3><h4><strong>Bitcoin</strong></h4><ul><li><p>The Satoshi Nakamoto Institute <a href="https://news.nakamotoinstitute.org/p/introducing-the-reorg">introduces</a> <a href="https://nakamotoinstitute.org/podcasts/the-reorg/">The Reorg</a>, a new podcast hosted by @Bitstein, exploring &#8220;the SNI archives to reexamine our ideas after years of accumulated proof-of-work.&#8221;</p></li></ul><h4><strong>Business &amp; Finance</strong></h4><ul><li><p>Proton Wallet officially launches and is now accessible on iOS, Android, and web platforms, for all users [<a href="https://x.com/ProtonWallet/status/1888971248652235009">Announcement</a>]</p></li><li><p>Custodial Lightning wallet service LifPay temporarily suspends operations to align with regulatory requirements [<a href="https://njump.me/nevent1qqszqgqwv503cax3hsue00savklqdqygsd52590s6emnqsy7304djaspzdmhxue69uhhwmm59e6hg7r09ehkuef0qgsq3v3kr3sqxtmr4zr6wnwc4cjrpn3ksfu7hc30am2vpcfu68jucqqrqsqqqqqpt3x780">Announcement</a>]</p><ul><li><p>Users are advised to withdraw their bitcoin within 60 days by submitting a withdrawal request.</p></li></ul></li><li><p>Orange Pill App introduces Lightning-enabled bitcoin wallet [<a href="https://www.orangepillapp.com/blog/orange-pill-app-wallet">Announcement</a>]</p><ul><li><p>The wallet aims to enhance community engagement through features like mass zapping, and plans to introduce geo-zapping, enabling users to send Bitcoin to others based on geographic locations.</p></li></ul></li><li><p>Brazilian financial solutions company Transfero partners with Lightspark to add speed and cost efficiency to Bitcoin transactions using the Lightning Network [<a href="https://www.lightspark.com/news/transfero-lightspark-partnership">Press release</a>]</p></li><li><p>Tropic Square introduces pre-production samples of TROPIC01, an open architecture RISC-V secure element [<a href="https://www.cnx-software.com/2025/03/01/tropic-square-tropic01-is-an-auditable-open-architecture-tamper-proof-risc-v-secure-element-se-for-iot-and-microcontrollers/">CNX Software&#8217;s Article</a>]</p><ul><li><p>TROPIC01 ensures tamper-proof hardware Root of Trust, enabling secure cryptographic key management and data storage in devices like hardware wallets and IoT products. [<a href="https://cdn.prod.website-files.com/67a4b8a23096bc77d4d941a8/67b82bd3b7f60bebae45104e_TROPIC01_Data_Brief_25.pdf">Product brief</a>]</p></li></ul></li><li><p>Fold introduces its Bitcoin Rewards Credit Card, offering cashback in bitcoin [<a href="https://blog.foldapp.com/fold-bitcoin-rewards-credit-card-waitlist/">Press release</a>]</p></li><li><p>Canaan announces the Avalon Q, a home mining device with a hash rate of 90 TH/s. [<a href="https://x.com/canaanio/status/1895481373487669575">Announcement</a>]</p></li></ul><h4><strong>Funding</strong></h4><ul><li><p>OpenSats receives $250,000 donation from HRF&#8217;s Bitcoin Development Fund, directed at its Operations Budget [<a href="https://opensats.org/blog/additional-ops-budget-from-hrf">Announcement</a>]</p></li><li><p>Vinteum announces its fifth grant to Pins for their work on LND [<a href="https://medium.com/vinteum-org/announcing-our-fifth-grant-pins-and-lnd-b37dbe004eae">Blog post</a>]</p><ul><li><p>The donation has been divided for three non-profit organizations Brink, OpenSats, and the Human Rights Foundation</p></li></ul></li><li><p>Blockstream opens its grant application portal for Bitcoin L2 projects, taking place on-site at the Lugano Research Hub [<a href="https://blockstream.typeform.com/to/KLeflywl">Portal</a>]</p></li><li><p>Brink receives a $50,000 contribution to their open source Bitcoin development efforts from <a href="https://x.com/bitcoinbrink/status/1892915462926705003">VanEck</a>, and another $50,000 contribution from <a href="https://x.com/River/status/1897332682436305233">River</a></p></li><li><p>Bitwise donates $150,000 to support Bitcoin open-source developers [<a href="https://x.com/BitwiseInvest/status/1891865302729883754">Announcement</a>]</p></li><li><p>The University of Austin invests $5 million of its endowment in Bitcoin, partnering with Unchained for the initiative. [<a href="https://bitcoinnews.com/adoption/university-of-austin-5m-bitcoin-fund/">Announcement</a>]</p></li></ul><h4><strong>Mining</strong></h4><ul><li><p>Bitaxe miner with 3.3Th of hashrate successfully mines a Bitcoin block, defying odds of 1 in 250,000,000 [<a href="https://mempool.space/block/000000000000000000006414aea39be567cf1d5ff6cbf2d77254fe7c714b0d81">Block 887212</a>]</p><ul><li><p>The device found a block with 719T difficulty, exceeding current difficulty levels, and has <a href="https://x.com/denverbitcoin/status/1899217414237123022">reportedly</a> been operating for less than a month, generating approximately 350M shares.</p></li></ul></li><li><p>Braiins reveals plans to open-source its BCB 100 control board [<a href="https://x.com/BraiinsMining/status/1895463159894302837">Announcement</a>]</p><ul><li><p>The release includes software (OpenWrt-based distribution, Linux support, and firmware source code) and hardware specifications (schematics, BOM, and CAD data), excluding the mining software.</p></li><li><p>All materials will be available under GPLv3 on the Braiins GitHub repository by the end of March.</p></li></ul></li></ul><h4><strong>Privacy</strong></h4><ul><li><p><a href="https://njump.me/naddr1qqxnzden8ymrjvf5xscnzde4qgsv83cj9336755plm3mjvudzzhxtvtxlln0w0cuyuk9cyfqvpmnr4crqsqqqa28hp0snm">Bisq trade trends</a>: An analysis of trading trends on the Bisq protocol in 2024</p><ul><li><p>The number of trades on Bisq decreased in 2024, but USD volume per trade increased, indicating higher value per transaction.</p></li><li><p>Payment methods like Strike, Zelle, and Cash By Mail showed different trends in the volume and average value of trades in 2024.</p></li><li><p>Bisq&#8217;s surveillance discount was typically smaller than expected, with Cash By Mail offering the best rate and Strike the worst in 2024.</p></li></ul></li><li><p>UK Government orders Apple to create backdoor for encrypted iCloud accounts [<a href="https://techcrunch.com/2025/02/10/uks-secret-apple-icloud-backdoor-order-is-a-global-emergency-say-critics/">TechCrunch</a>]</p><ul><li><p>The UK Home Secretary&#8217;s office has issued a secret order under the Investigatory Powers Act of 2016, requiring Apple to provide access to user data protected by its Advanced Data Protection for iCloud.</p></li><li><p>In response, Apple has withdrawn support for Advanced Data Protection in the UK, and <a href="https://appleinsider.com/articles/25/03/04/apple-goes-to-court-to-fight-uk-demand-for-icloud-encryption-backdoor">goes to court to fight UK&#8217;s demand</a>.</p></li></ul></li><li><p>Mozilla revises Firefox terms after user backlash over data usage [<a href="https://techcrunch.com/2025/03/03/mozilla-rewrites-firefoxs-terms-of-use-after-user-backlash/">TechCrunch</a>]</p><ul><li><p>Mozilla has revised its Firefox Terms of Use, removing the explicit promise to &#8220;never sell personal data&#8221;, citing evolving legal definitions of data sales.</p></li><li><p>In response to feedback, Mozilla updates the terms to clarify that they do not claim ownership of user data and that data usage is limited to operating Firefox as described in the Privacy Notice.</p></li></ul></li><li><p>Kraken&#8217;s 2024 <a href="https://blog.kraken.com/news/2024-kraken-transparency-report">Transparency Report</a>: Kraken received 6,826 data requests from law enforcement and government agencies across 71 countries, marking a 38.6% increase from 2023</p><ul><li><p>U.S. agencies accounted for 28.6% of these requests, with the FBI submitting 614. Kraken provided data for 57% of all requests, covering 10,369 accounts, primarily linked to clients in the U.S. (34.5%), the U.K. (8.8%), and Germany (8.5%).</p></li></ul></li><li><p>X blocks Signal.me links, prompts error messages indicating potential harm or spam [<a href="https://www.disruptionist.com/p/elon-musks-x-blocks-links-to-signal">Disruptionist</a>]</p><ul><li><p>The company cites security issues with the domain, threatening to user safety.</p></li></ul></li></ul><h4><strong>Protocol</strong></h4><ul><li><p>Bitcoin Core #25832: tracing: network connection tracepoints [<a href="https://github.com/bitcoin/bitcoin/pull/25832">Merged</a>]</p><ul><li><p>&#8220;This adds five new tracepoints with documentation and tests for network connections&#8221;</p></li></ul></li><li><p>Bitcoin Core #27432: contrib: add tool to convert compact-serialized UTXO set to SQLite database [<a href="https://github.com/bitcoin/bitcoin/pull/27432">Merged</a>]</p></li><li><p>BIP #1712: BIP3: Updated BIP Process [<a href="https://github.com/bitcoin/bips/pull/1712">Merged</a>]</p></li><li><p>Rust Bitcoin #4114: Policy: Relax MIN_STANDARD_TX_NONWITNESS_SIZE to 65 [<a href="https://github.com/rust-bitcoin/rust-bitcoin/pull/4114">Merged</a>]</p></li><li><p>Rust Payjoin #434: Multiparty Senders: NS1R [<a href="https://github.com/payjoin/rust-payjoin/pull/434/">Merged</a>]</p></li><li><p>LND #9491: Allow coop closing a channel with HTLCs on it via lncli [<a href="https://github.com/lightningnetwork/lnd/pull/9491">Merged</a>]</p></li><li><p>LDK #3440: Support receiving async payments [<a href="https://github.com/lightningdevkit/rust-lightning/pull/3440">Merged</a>]</p></li><li><p>LDK #3575: PeerStorage: Add feature and store peer storage in ChannelManager [<a href="https://github.com/lightningdevkit/rust-lightning/pull/3575">Merged</a>]</p></li><li><p>Eclair #2989: Add router support for batched splices [<a href="https://github.com/ACINQ/eclair/pull/2989">Merged</a>]</p></li><li><p>Eclair #2979: Check peer features before attempting wake-up [<a href="https://github.com/ACINQ/eclair/pull/2979">Merged</a>]</p></li><li><p>BOLT #1228: Zero-fee commitments using v3 transactions [<a href="https://github.com/lightning/bolts/pull/1228">Draft</a>]</p></li><li><p>NIP #1807: Add On-Chain Send/Receive to NWC #1807 [<a href="https://github.com/nostr-protocol/nips/pull/1807">Open</a>]</p></li><li><p>NIP #1777: NWC Deep Links: a standard for using deeplinks to communicate between a wallet and a nostr client [<a href="https://github.com/nostr-protocol/nips/pull/1777">Open</a>]</p></li></ul><h4><strong>Government &amp; Political</strong></h4><ul><li><p>President Trump confirms the creation of a U.S. Strategic Crypto Reserve, including BTC, ETH, XRP, SOL, and ADA [<a href="https://truthsocial.com/@realDonaldTrump/114093526901586124">Truth social post</a>]</p></li><li><p>U.S. President brokers a prisoner swap, releasing BTC-e founder Alexander Vinnik [<a href="https://www.theblock.co/post/340474/president-trump-swaps-btc-e-operator-money-laundering-alexander-vinnik-prisoner-exchange-russia">The Block</a>]</p><ul><li><p>Vinnik, co-founder of BTC-e, pleaded guilty to money laundering charges in the U.S. and France.</p></li></ul></li><li><p>The U.S. SEC&#8217;s Division of Corporation Finance states that meme coins are akin to collectibles, not securities [<a href="https://www.sec.gov/newsroom/speeches-statements/staff-statement-meme-coins">Statement</a>]</p><ul><li><p>Consequently, transactions involving meme coins do not require registration with the SEC, leaving purchasers and holders unprotected by federal securities laws.</p></li></ul></li><li><p>Bitcoin asset seizure and civil contempt order [<a href="https://storage.courtlistener.com/recap/gov.uscourts.prd.186103/gov.uscourts.prd.186103.20.0.pdf">Court order</a>]</p><ul><li><p>A U.S.federal judge holds Mr. Reynoso in civil contempt for violating a seizure warrant requiring him to transfer 119.65 BTC to a government-controlled wallet within 24 hours. Within hours of the warrant being served, Reynoso moved the bitcoin through multiple wallets, invalidating any claims of inability to access the funds. [<a href="https://mempool.space/tx/5316e2292019c12d17fe29a8c83880393edcc3bee0e45dd075aea4be4214b17e">Transaction</a>]</p></li><li><p>The FBI discovered Ledger software on Reynoso&#8217;s laptop, and authorities confirmed his Bitcoin address through both the software interface and a text file in his Apple account.</p></li></ul></li><li><p>U.S. Marshals Service struggles with managing seized cryptocurrencies [<a href="https://www.coindesk.com/policy/2025/02/20/u-s-marshals-service-managing-seized-assets-can-t-say-how-much-crypto-it-holds">CoinDesk</a>]</p><ul><li><p>Previous reports and audits have criticized the agency&#8217;s inability to track forked assets and its reliance on insecure methods like unencrypted email for sharing bitcoin deposit addresses.</p></li></ul></li><li><p>Nigeria&#8217;s release of Binance Executive Tigran Gambaryan linked to U.S. surveillance assistance deal [<a href="https://www.therage.co/the-cost-of-gambaryan/">The Rage</a>]</p><ul><li><p>In October 2024, Nigeria released Binance executive Tigran Gambaryan, who had been detained since February 2024 on money laundering charges.</p></li><li><p>The same day, the U.S. and Nigeria announced a &#8220;Bilateral Liaison Group on Illicit Finance and Cryptocurrencies&#8221;, providing Nigeria with US &#8220;resources and expertise&#8221; in investigating cybercrimes.</p></li></ul></li><li><p>Argentina&#8217;s President Javier Milei faces legal and political backlash over failed LIBRA memecoin launch [<a href="https://www.reuters.com/world/americas/argentinas-opposition-threatens-impeachment-trial-after-milei-touts-crypto-coin-2025-02-16/">Reuters</a>]</p><ul><li><p>Milei denies any involvement, claiming he had no prior knowledge of the token&#8217;s issues and is now calling for an internal investigation.</p></li></ul></li><li><p>CBP intensifies ASIC miner seizures, expands scope to MicroBT and Canaan units [<a href="https://blockspace.media/insight/cbp-ramps-up-asic-miner-crackdown-with-seizures-new-import-holds/">Blockspace</a>]</p><ul><li><p>U.S. Customs and Border Protection (CBP) is seizing Bitcoin mining ASICs at ports of entry, including Bitmain, MicroBT, and Canaan units, at the request of the Federal Communications Commission.</p></li></ul></li></ul><h4><strong>Central Banking</strong></h4><ul><li><p>The IMF requests El Salvador&#8217;s public sector to halt Bitcoin purchases as part of a $1.4 billion loan agreement [<a href="https://atlas21.com/imf-and-el-salvador-request-to-halt-bitcoin-accumulation-plan/">Atlas21</a>] [<a href="https://www.imf.org/en/News/Articles/2025/02/26/pr25043-el-salvador-imf-approves-new-40-month-us1-bn-eff-arr">Press release</a>]</p><ul><li><p>The IMF&#8217;s conditions include banning public sector Bitcoin accumulation and mining, restricting issuance of Bitcoin-linked tokenized debt, and revoking Bitcoin&#8217;s legal tender status.</p></li></ul></li><li><p>The European Central Bank announced an expansion of the Eurosystem initiative for settling transactions using distributed ledger technology in central bank money [<a href="https://www.ecb.europa.eu/press/pr/date/2025/html/ecb.pr250220_1~ce3286f97b.en.html">Press release</a>]</p><ul><li><p>The initiative will explore how DLT can settle transactions within the Eurosystem.</p></li></ul></li><li><p>Heraclius: A Byzantine fault tolerant database system with potential for modern payments systems [<a href="https://www.federalreserve.gov/econres/feds/files/2025012pap.pdf">Research paper</a>]</p><ul><li><p>Heraclius is a project by the U.S. Federal Reserve which attempts to replicate Bitcoin&#8217;s decentralized security while keeping control in central hands.</p></li><li><p>The Fed paper acknowledges Bitcoin as &#8220;the longest running electronic payment system that tolerates byzantine faults today&#8221;</p></li></ul></li></ul><h4><strong>Events</strong></h4><ul><li><p><a href="https://bcc8333.com/">Barcelona Cyphers Conference</a>: Unleashing Decentralized Freedom</p><ul><li><p>June 6-7, 2025 in Barcelona, Spain</p></li></ul></li></ul><h3><strong>Reads</strong></h3><ul><li><p>Here&#8217;s a list of our top recently published reads:</p><ul><li><p>How Big Brother can attack Bitcoin without spending a dime, by Harsha Goli [<a href="https://blockspace.media/insight/the-boring-banal-way-big-brother-can-shackle-bitcoin/">Opinion</a>]</p></li><li><p>Prosecuting Privacy: Examining Samourai Wallet, Money Transmitters, and the Criminalization of Innovation, by Spencer Peek [<a href="https://www.defieducationfund.org/_files/ugd/84ba66_87dfb370e81a4766811bf16e5293c6da.pdf">Research paper</a>]</p></li><li><p>Atlas Mined, by Jon [<a href="https://www.ungovernablemisfits.com/atlas-mined/">Article</a>]</p></li><li><p>The Logic of Spending Bitcoin, by Parker Lewis [<a href="https://x.com/parkeralewis/status/1897340988772819036">Read</a>]</p></li><li><p>What&#8217;s Driving Bitcoin Adoption in 2025?, by Sam Baker [<a href="https://blog.river.com/bitcoin-adoption-2025/">River&#8217;s Research report</a>]</p></li><li><p>Every App Needs Bitcoin, by Miljan [<a href="https://primal.net/miljan/Every-App-Needs-Bitcoin-cy3uvd">Note</a>]</p></li><li><p>Why Keys Matter, by Holdbod [<a href="https://njump.me/naddr1qvzqqqr4gupzp978pfzrv6n9xhq5tvenl9e74pklmskh4xw6vxxyp3j8qkke3cezqqxnzde5xycnjdeex5mrwwp406f0z0">Note</a>]</p></li><li><p>Bybit&#8217;s $1.4b breach started with stock invest malware [<a href="https://crypto.news/bybits-1-4b-breach-started-with-stock-invest-malware-investigation-reveals/">Crypto.news</a>]</p></li></ul></li></ul><h3><strong>Episode submission ideas</strong></h3><ul><li><p>We&#8217;re looking for ideas for interesting panel conversations. To send Bitcoin related questions, just go to <a href="https://bitcoin.review/">bitcoin.review</a> and follow the contact links at the bottom of the page.</p></li></ul><h3><strong>Get in touch with the pod</strong></h3><ul><li><p><a href="https://twitter.com/bitcoinreviewhq">Podcast Twitter</a></p></li><li><p><a href="https://twitter.com/nvk">NVK Twitter</a></p></li><li><p><a href="https://t.me/BitcoinReviewPod">Telegram</a></p></li><li><p><a href="mailto:producer@coinkite.com">Email</a></p></li><li><p>Nostr &amp; LN &#9889;nvk@nvk.org (not an email!)</p></li></ul>]]></content:encoded></item><item><title><![CDATA[BR092 - Nostr Wallet Connect, DeepSeek, AI Coding, Sparrow, Bitcoin Keeper, Maple AI, Calculating Tx Sizes + MORE ft. Future Paul]]></title><description><![CDATA[I&#8217;m joined by guest Future Paul to go through the list.]]></description><link>https://substack.bitcoin.review/p/br092-nostr-wallet-connect-deepseek</link><guid isPermaLink="false">https://substack.bitcoin.review/p/br092-nostr-wallet-connect-deepseek</guid><dc:creator><![CDATA[STACK TO THE FUTURE]]></dc:creator><pubDate>Tue, 11 Feb 2025 16:28:18 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a95ac75-ac77-4167-9383-9930a48690bb_1080x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I&#8217;m joined by guest <a href="https://twitter.com/futurepaul">Future Paul</a> to go through the list.</p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://bitcoin.review/podcast/episode-56/&quot;,&quot;text&quot;:&quot;Listen on your favorite podcast app&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://bitcoin.review/podcast/episode-56/"><span>Listen on your favorite podcast app</span></a></p><div><hr></div><h3><strong>Prelude to the list</strong></h3><ul><li><p>00:01:00 Conversation on AI and building with AI</p></li></ul><h3><strong>Housekeeping</strong></h3><ul><li><p>00:22:02 New Coldcard Q tutorial by Lo&#239;c Morel on Plan B Network: <a href="https://planb.network/en/tutorials/wallet/hardware/coldcard-q-73e86d1a-6fe6-4d8b-bb15-8690298020e3">Getting Started with COLDCARD Q</a></p></li><li><p>00:22:10 We are still looking for bitcoin builders to come on the show!</p></li><li><p>00:23:13 Unleashed.Chat <a href="https://njump.me/nevent1qqsdzsm760uk0yjh07q84mppvezjp3dfjd55rv235kvl52m3ducqvvgpyfmhxue69uhkummnw3ez6an9wf5kv6t9vsh8wetvd3hhyer9wghxuet5qgsw3znfr6vdnxrujezjrhlkqqjlvpcqx79ys7gcph9mkjjsy7zsgyg67eke6">Update</a> - Deepseek R1 32B</p><ul><li><p>Users can now access the DeepSeek R1 32B model on Unleashed.chat, all data remaining stored locally in the user&#8217;s browser.</p></li><li><p>Future updates aim to integrate it as a DVM, API, and enhance its ability to search Nostr and the web while improving speed.</p></li></ul></li><li><p>00:23:19 NWC and Olas/Primal</p></li></ul><h3><strong>Urgent Vulnerability Disclosures</strong></h3><ul><li><p>00:37:17 Replacement Cycling Attacks on Bitcoin Miners Block Templates [<a href="https://groups.google.com/g/bitcoindev/c/ZspZzO4sBys">Antoine Riard&#8217;s Disclosure</a>]</p><ul><li><p>A variant of replacement cycling attacks allows adversarial miners to censor transactions in block templates, manipulating the Bitcoin fee distribution. This attack, tested on Bitcoin Core 26.0 and 29.0, exploits mempool mechanisms to gain an economic advantage over honest miners.</p></li><li><p>The attack leverages non-UTXO transaction traffic and mempool policies like replace-by-fee to reorder transactions in block templates.</p></li></ul></li></ul><h3><strong>Bitcoin</strong></h3><h4><strong>Software Releases &amp; Project Updates</strong></h4><ul><li><p>00:37:34 Sparrow Wallet</p><ul><li><p><a href="https://github.com/sparrowwallet/sparrow/releases/tag/2.1.2">v2.1.2</a></p><ul><li><p>Indicate historical rates support in Exchange Source drop-down on General Settings</p></li><li><p>Prefill the derivation to the default path for the chosen script type on watch only keystores</p></li><li><p>Add local network usage description in Info.plist for macOS 15</p></li><li><p>Support Coldcard P2TR address display over USB (Edge firmware only)</p></li><li><p>Set the script type selection import button as the default button after BIP39 wallet discovery returns empty</p></li></ul></li><li><p><a href="https://github.com/sparrowwallet/sparrow/releases/tag/2.1.0">v2.1.0</a></p><ul><li><p>Use Lark for USB hardware wallet communication (replaces HWI)</p></li><li><p>Store and send multisig wallet registrations on Ledger devices to avoid re-registration</p></li><li><p>Perform native pairing with the BitBox02 to avoid reliance on a previous external pairing configuration</p></li><li><p>Support Jade Plus over USB</p></li><li><p>Restore any adjusted table column widths and sort preferences on wallet load</p></li><li><p>Support loading PSBTv2 files</p></li><li><p>Skip labelled addresses when retrieving an unused address from the Receive tab, and the Send tab pay to wallet selection</p></li><li><p>Always select a new address when sending multiple payments to the same open wallet</p></li><li><p>Allow camera image mirroring to be changed from scanned image context menu and the application View menu</p></li><li><p>Only show CPFP rate if child fee increases effective fee rate</p></li><li><p>Add option to Bitcoin Core and Private Electrum server selection to scan a URL from a QR code</p></li><li><p>Allow server URLs to be pasted into the server settings Host fields</p></li><li><p>Enable Electrum RPC batching on mempool-electrs servers</p></li><li><p>Add blackie.c3-soft.com testnet4 Public Electrum servers</p></li><li><p>Add mempool.space exchange rate source</p></li><li><p>Retrieve fee rates from configured source on non-mainnet networks where available</p></li><li><p>Switch from paynym.is to paynym.rs and Tor equivalents</p></li><li><p>Update child wallet labels to available paynyms on displaying the Paynym dialog</p></li><li><p>Set transaction tab label to transaction label on opening transaction if available</p></li><li><p>Show input label in the input tooltip on the transaction diagram if present</p></li><li><p>Truncate labels in table columns to max persistable label length and notify the user via a tooltip</p></li><li><p>Disable broadcast progress bar if disconnected, and re-enable if connected again</p></li><li><p>Remove payjoin v1 verification step to check there is no previous UTXO information in the PSBT as per BIP78 change</p></li><li><p>Exclude Taproot wallets and Jade, Tapsigner and Satochip HWWs from requiring the non witness tx field in PSBTs</p></li><li><p>Improve socket address resolution handling when using a proxy</p></li><li><p>Improve keystore import panel spacing in Linux</p></li><li><p>Add Specter DIY multisig option to wallet import menu</p></li><li><p>Replace forward slash with underscore in file names when saving PSBTs</p></li><li><p>Improve Jade QR keystore import descriptions</p></li><li><p>And many more</p></li></ul></li></ul></li><li><p>00:41:08 BDK <a href="https://github.com/bitcoindevkit/bdk/releases/tag/wallet-1.1.0">v1.1.0</a></p><ul><li><p>In this release of bdk_wallet v1.1.0 the tx builder is updated to use transaction version 2 by default, and support for wallets using testnet4 is now live.</p></li><li><p>This release also includes important updates to bdk_electrum which has a new MSRV of 1.75.0 to stay current with the latest security fixes, bdk_bitcoind_rpc introduces a new compact block filter module, as well as various bug fixes and improvements.</p></li></ul></li><li><p>00:41:35 Bitcoin Keeper</p><ul><li><p>Mobile <a href="https://github.com/bithyve/bitcoin-keeper/releases/tag/v2.0.1">v2.0.1</a></p><ul><li><p>Fresh new design across the app</p></li><li><p>Support Enhanced Vaults with Inheritance Key for BitBox02, Coldcard, Jade, and Ledger</p></li><li><p>In app concierge support system</p></li><li><p>Onboarding calls for Diamond Hands subscribers</p></li><li><p>Coldcard Q QR support</p></li></ul></li><li><p>Desktop <a href="https://github.com/bithyve/keeper-desktop/releases/tag/keeper-desktop-v0.2.0">v0.2.0</a></p><ul><li><p>Add support for Miniscript with Bitbox02, ColdCard, Jade, and Ledger</p></li><li><p>Add support for BitBox02 pairing code</p></li></ul></li></ul></li><li><p>00:42:40 Wasabi Wallet <a href="https://github.com/WalletWasabi/WalletWasabi/releases/tag/v2.5.0">v2.5.0</a></p><ul><li><p>Fee rate estimations and exchange rate providers are now configurable</p></li><li><p>Quality of Life Features: address old bugs and feature requests</p></li><li><p>Backend and Coordinator packaged for Linux: The Debian package now includes two extra binaries: one for the backend (Wallet API) and one for the coordinator (Coinjoin API).</p></li></ul></li><li><p>00:42:43 Blockstream</p><ul><li><p>Green QT</p><ul><li><p><a href="https://github.com/Blockstream/green_qt/releases/tag/release_2.0.20">v2.0.20</a></p><ul><li><p>Enable Liquid discounted fees for Confidential Transactions</p></li></ul></li><li><p><a href="https://github.com/Blockstream/green_qt/releases/tag/release_2.0.19">v2.0.19</a></p><ul><li><p>Create support tickets from the application</p></li></ul></li></ul></li><li><p>Green iOS / Android</p><ul><li><p><a href="https://github.com/Blockstream/green_ios/releases/tag/release_4.1.5">iOS v4.1.5</a> / <a href="https://github.com/Blockstream/green_android/releases/tag/release_4.1.5">Android v4.1.5</a></p><ul><li><p>Liquid network: enabled discount fees</p></li></ul></li><li><p><a href="https://github.com/Blockstream/green_ios/releases/tag/release_4.1.4">iOS v4.1.4</a> / <a href="https://github.com/Blockstream/green_android/releases/tag/release_4.1.4">Android v4.1.4</a></p><ul><li><p>Create support requests from the app</p></li></ul></li></ul></li></ul></li><li><p>00:43:06 Electrs <a href="https://github.com/romanz/electrs/blob/master/RELEASE-NOTES.md#0109-feb-01-2025">v0.10.9</a></p><ul><li><p>Allow concurrent DB background operations for SSDs</p></li><li><p>Update bitcoin_slices to 0.10.0</p></li></ul></li><li><p>Nunchuk Android <a href="https://github.com/nunchuk-io/nunchuk-android/releases/tag/android.1.9.62">v1.9.62</a></p><ul><li><p>Support android 15</p></li></ul></li><li><p>00:43:44 Umbrel <a href="https://github.com/getumbrel/umbrel/releases/tag/1.4.0-beta.1">v1.4.0-beta.1</a></p><ul><li><p>umbrelOS 1.4 Beta 1 introduces Files, a new file manager that turns your Umbrel into a full-blown home cloud, along with Korean language support and various bug fixes.</p></li><li><p>Create, upload, and organize files and documents.</p></li><li><p>Share folders over your local network, and easily add them as network drives on macOS, Windows, iOS, or Android.</p></li><li><p>Set up a shared folder as a Time Machine backup location on macOS</p></li><li><p>Preview all your photos, videos, PDFs, and audio files</p></li><li><p>Access app data folders</p></li><li><p>External (USB) storage support for Umbrel Home arriving in umbrelOS 1.4 Beta 2.</p></li></ul></li><li><p>00:44:29 Bisq <a href="https://github.com/bisq-network/bisq/releases/tag/v1.9.19">v1.9.19</a></p><ul><li><p>Produce exclusively low-R signatures from wallet keys</p></li><li><p>&#8220;Transfer Same Bank&#8221; &amp; &#8220;Transfer Specific Banks&#8221; match case-insentitivity</p></li><li><p>Create payment method &#8220;Faster Payments System (SBP)&#8221; for Russian Ruble</p></li><li><p>New option in <code>PhoneNumberValidator</code> to enforce exact number of digits</p></li><li><p>Add 500+ string translations to Russian language file</p></li><li><p>Implement <code>BitcoinCoreSeedListDiscovery</code> method</p></li><li><p>getoffers (api): Return all offers by default</p></li><li><p>Add <code>suddenwhipvapor</code> mediator instance onion</p></li><li><p>Improve resync handling</p></li><li><p>Add missing snapshot creation in full DAO mode</p></li></ul></li><li><p>00:44:40 Bisq2 <a href="https://github.com/bisq-network/bisq2/releases/tag/v2.1.5">v2.1.5</a></p><ul><li><p><strong>A bug has been discovered in that release. Please do not install it and wait until a new version is available.</strong></p></li><li><p>Security update: To enhance security for buyers, sellers must have sufficient reputation to secure a trade for the specified amount.</p></li><li><p>New features:</p><ul><li><p>The new Profile Card comes with many features. Find the user profile details, trade terms, reputation, offers created and the public messages posted by clicking on the profile icon or profile name anywhere in the app.</p></li><li><p>To improve on privacy, sensitive trade data will be automatically deleted after a certain period of time</p></li><li><p>See trade details in the trade process window by clicking on the &#8220;Show details&#8221; button</p></li></ul></li></ul></li><li><p>00:44:51 Zaprite <a href="https://help.zaprite.com/en/articles/10504186-zaprite-release-notes-2025-02-03">v2025-02-03</a></p><ul><li><p>Add: New <a href="https://blog.zaprite.com/how-to-connect-btcpay-server/">BTCPay integration</a>, allowing users to accept bitcoin and lightning payments alongside fiat using self-hosted infrastructure.</p></li><li><p>Update:</p><ul><li><p>Transactions CSV: Add a new Customer Note column to our Transactions CSV export</p></li><li><p>Square ACH: Update Square ACH payment flow to adhere to new requirements from Square</p></li></ul></li><li><p>Remove: Transaction Canceled: Temporarily disabled the Transaction Canceled notification emails until we can resolve their over-sensitivity.</p></li></ul></li><li><p>00:45:54 Mempal</p><ul><li><p><a href="https://github.com/aeonBTC/Mempal/releases/tag/v1.5.1">v1.5.1</a></p><ul><li><p>Disable APK dependency metadata</p></li></ul></li><li><p><a href="https://github.com/aeonBTC/Mempal/releases/tag/v1.5.0">v1.5.0</a></p><ul><li><p>Tapping the Mempal logo now opens a web browser to mempool.space or equivalent custom mempool server</p></li><li><p>Rework widget implementation to solve update issues</p></li><li><p>Customize proguard-rules file to shrink app size and increase overall performance</p></li></ul></li></ul></li><li><p>00:46:04 Bitcoin Safe</p><ul><li><p><a href="https://github.com/andreasgriffin/bitcoin-safe/releases/tag/1.0.6">v1.0.6</a></p><ul><li><p>bitbox02: Added initial device setup option &#8220;restore from seed&#8221; without needing vendor software</p></li><li><p>Jade: Bugfix for unlocking a newly initialized device</p></li><li><p>Stricter tests for clean wallet shutdowns</p></li></ul></li><li><p><a href="https://github.com/andreasgriffin/bitcoin-safe/releases/tag/1.0.3">v1.0.3</a></p><ul><li><p>Add Tor support through proxy</p></li></ul></li></ul></li><li><p>BTC Map <a href="https://github.com/teambtcmap/btcmap-android/blob/master/CHANGELOG.md">v0.9.2</a></p><ul><li><p>Add merchant boosts</p></li><li><p>Add comments screen</p></li><li><p>Speed up element search within an area</p></li><li><p>Show user location marker</p></li><li><p>Show more info on deleted elements</p></li><li><p>Add Polish and Brazilian translation</p></li><li><p>Allow users to post merchant comments</p></li></ul></li><li><p>00:48:50 ESP Miner <a href="https://github.com/skot/ESP-Miner/releases/tag/v2.6.0b2">v2.6.0b2</a></p><ul><li><p>Is SPIRAM Available?</p></li><li><p>Keep old pool config synchronized until reboot</p></li><li><p>Add support for extranonce2_len&lt;4</p></li><li><p>SSID WiFi lookup</p></li></ul></li></ul><h4><strong>Project spotlight</strong></h4><ul><li><p>00:49:02 cbip32: A fast, secure, low-dependency C implementation of BIP32 [<a href="https://github.com/jamesob/cbip32">Github</a>]</p><ul><li><p>The library depends only on libsecp256k1 and libsodium, for minimal dependency.</p></li><li><p>Extensive testing includes cross-implementation fuzz testing against python-bip32 and verystable.</p></li></ul></li><li><p>00:49:15 <a href="https://stackstates.com/">StackStates</a>: A map of the United States that shows legislation of official Bitcoin adoption [<a href="https://github.com/marksftw/stackstates">Github</a>]</p></li><li><p>00:49:21 <a href="https://instamouse.com/kanzure/bitcoin">Instamouse bitcoin</a>: A full Bitcoin Core development environment accessible directly through a web browser</p><ul><li><p>The environment includes pre-compiled Bitcoin Core software, with options to recompile if desired. Tools like Visual Studio Code and Qt Creator are pre-installed for development purposes.</p></li><li><p>The setup operates in regtest mode, with the Bitcoin configuration file located at ~/.bitcoin/bitcoin.conf. An autolaunch script is available and can be modified or deleted as needed.</p></li></ul></li><li><p>00:50:24 Iris Wallet Desktop: RGB on Lightning from a simple interface [<a href="https://github.com/RGB-Tools/iris-wallet-desktop">Github</a>]</p><ul><li><p>The wallet enables users to manage RGB assets, including issuance, spending, and receiving, within a familiar wallet application.</p></li><li><p>Releases its first experimental release with the <a href="https://github.com/RGB-Tools/iris-wallet-desktop/releases/tag/0.1.0">v0.1.0</a></p></li></ul></li><li><p>00:50:43 <a href="https://explorer.timechainindex.com/">Explorer.timechainindex</a>: An address and transaction explorer by Timechainindex, powered by Mempool.space API</p><ul><li><p>Users can save the explorer&#8217;s webpages locally and run them from their own mempool instance by changing the &#8220;api_endpoint&#8221; to their local mempool directory.</p></li></ul></li><li><p>00:50:54 <a href="https://thebullishbitcoiner.github.io/tx-tree/">txTree</a>: A tool to explore UTXO connections</p><ul><li><p>txTree is a tool that visualizes Bitcoin transactions by fetching and displaying transaction data in a tree structure</p></li></ul></li><li><p>00:50:58 <a href="https://supertestnet.github.io/hurricash/">HurriCash</a>: A multisig tool for collaborative bitcoin transactions [<a href="https://github.com/supertestnet/hurricash">Github</a>]</p><ul><li><p>The platform guides users through an initial transaction to allocate necessary funds, followed by a coinjoin process to collectively fund the multisig wallet.</p></li></ul></li><li><p>00:51:29 <a href="https://thebitcointrail.space/">The Bitcoin Trail</a>: A community-driven bitcoin-themed game in development</p><ul><li><p>The Bitcoin Trail began as a fun, stacking-themed game concept. Players can fund new features by zapping sats, including custom tombstones, news events, sound effects, new characters, and game mechanics.</p></li><li><p>The game aims to evolve dynamically, with features like in-game stops, custom graphics, and even original music&#8212;all dependent on user contributions.</p></li></ul></li><li><p>00:51:41 <a href="https://bitcoinlaws.io/">Bitcoin Laws</a>: A dedicated platform that monitors legislative measures related to Bitcoin and digital assets across various jurisdictions.</p></li><li><p>00:51:50 <a href="https://coinmarketcrap.co/">CoinMarketCrap</a>: A website that provides bitcoin &amp; shitcoins market cap rankings, and more. [<a href="https://github.com/sha-265/coinmarketcrap.co">Github</a>]</p></li></ul><h3><strong>Vulnerability Disclosures</strong></h3><ul><li><p>00:54:19 Researchers uncover two security flaws, FLOP and SLAP, in Apple&#8217;s A and M-series chips, enabling attackers to steal sensitive data through speculative execution attacks [<a href="https://arstechnica.com/security/2025/01/newly-discovered-flaws-in-apple-chips-leak-secrets-in-safari-and-chrome/">ArsTechnica</a>]</p><ul><li><p>FLOP exploits the Load Value Predictor to access memory contents, while SLAP manipulates the Load Address Predictor to intercept JavaScript strings in Safari. Affected devices include iPhones (13&#8211;16 series), iPads, and Macs from 2021 onwards.</p></li><li><p>Researchers demonstrate that FLOP can steal saved credit card information from Square storefronts, while SLAP can recover email data from ProtonMail, Amazon purchase details, and Reddit comments. [<a href="https://predictors.fail/">Demo</a>]</p></li></ul></li><li><p>00:54:33 Cybersecurity firm Kaspersky identifies &#8220;SparkCat&#8221; malware in both Google Play and Apple&#8217;s App Store targeting cryptocurrency owners [<a href="https://cyberinsider.com/sparkcat-malware-found-in-google-play-and-apple-app-store/">CyberInsider</a>]</p><ul><li><p>SparkCat employs OCR technology to extract sensitive information, including cryptocurrency wallet passwords from users&#8217; photos. Infected apps request access to photo galleries under the guise of chat support features.</p></li></ul></li><li><p>00:54:40 A reported exploit is targeting users who access adult websites through their Phantom or Trust Wallet browser [<a href="https://x.com/dom_lucre/status/1886552067059195928">Twitter post</a>]</p><ul><li><p>Users are advised to avoid viewing adult content using these wallet-integrated browsers to prevent potential security breaches and loss of funds.</p></li></ul></li><li><p>00:56:30 Lazarus Group deploys electron-based malware to steal cryptocurrency data [<a href="https://securityonline.info/lazarus-group-deploys-electron-based-malware-to-target-cryptocurrency-enthusiasts/">Security Online</a>]</p><ul><li><p>The Lazarus Group embeds malware into an open-source project, Uniswap Sniper Bot, to target cryptocurrency advanced users. This attack follows similar strategies where they exploited Python and Node.js repositories.</p></li></ul></li><li><p>00:56:36 Coinbase users lose millions to social engineering scams amid security failures [<a href="https://x.com/zachxbt/status/1886411879939031530">ZachXBT Analysis</a>]</p><ul><li><p>Coinbase users have lost over $65 million between December 2024 and January 2025 due to social engineering scams. These scams involve attackers spoofing Coinbase phone numbers and emails to trick victims into transferring funds.</p></li></ul></li><li><p>00:56:57 Singapore-based cryptocurrency exchange Phemex suffers $85 million hack, halts withdrawals [<a href="https://www.securityweek.com/hackers-drain-over-85-million-from-crypto-exchange-phemex/">Security Week</a>]</p><ul><li><p>On January 23, 2025, the platform detected unusual activity in its hot wallets, leading to the theft of over $85 million in various cryptocurrencies.</p></li><li><p>Phemex is collaborating with third-party security firms and law enforcement agencies to investigate the breach and has announced plans to compensate affected users.</p></li></ul></li><li><p>00:57:56 Peer-to-peer cryptocurrency trading platform NoOnes suffers $8 million exploit due to Solana bridge vulnerability [<a href="https://cryptoslate.com/noones-acknowledges-8-million-exploit-after-zachxbt-raises-concerns/">CryptoSlate</a>]</p><ul><li><p>The breach involved multiple small transactions, each under $7,000, across various networks, then subsequently funneled through Tornado Cash.</p></li></ul></li><li><p>Bug in Solana-based wallet Solflare exposes 4,800 email addresses onchain, links them to more than 6,700 distinct wallets [<a href="https://njump.me/nevent1qqsgtzhthmkxjnmupvxukd5hguwudnzwa2drxa2m03p8l8ma2srz7rqpz4mhxue69uhkummnw3ezummcw3ezuer9wchsyg8h9rv7decysdvwwzfs7h9xfvyhwuxe38xds6z5lescak5u3gupqcpsgqqqqqqsdzw0gf">Note by Jameson Lopp</a>]</p><ul><li><p>A bug in Solflare&#8217;s transaction signing process caused users&#8217; email profiles to be sent onchain during a &#8216;claim&#8217; event. This issue specifically affected users who used Solflare with Ledger hardware wallets.</p></li></ul></li><li><p>WhatsApp reports Paragon Solutions&#8217; spyware targeting journalists and civil society members [<a href="https://www.reuters.com/technology/cybersecurity/metas-whatsapp-says-israeli-spyware-company-paragon-targeted-scores-users-2025-01-31/">Reuters</a>]</p><ul><li><p>WhatsApp detects hacking attempts on approximately 90 users, including journalists and civil society members, by Israeli spyware company Paragon Solutions.</p></li><li><p>Despite Paragon&#8217;s claims of ethical practices and selling only to stable democratic governments, WhatsApp&#8217;s findings raise concerns about the commercial spyware industry&#8217;s impact.</p></li></ul></li><li><p>00:58:40 Chinese AI startup Deepseek exposes over a million plaintext chat records, API keys, and internal logs due to unsecured ClickHouse databases. [<a href="https://www.bleepingcomputer.com/news/security/deepseek-exposes-database-with-over-1-million-chat-records/">Bleeping Computer</a>]</p><ul><li><p>Security firm Wiz discovers the vulnerability, noting that the publicly accessible databases allowed arbitrary SQL queries without authentication.</p></li></ul></li><li><p>00:58:16 Five dollars wrench attacks:</p><ul><li><p>Russian national released after being cleared of involvement in kidnapping in Indonesia [<a href="https://news.faharas.net/239481/penampakan-bos-geng-rusia-perampok/">News Farahas</a>]</p><ul><li><p>The incident was made public in early February 2025, more than a month after the kidnapping occurred, when a Ukrainian national and his driver were ambushed in Bali, Indonesia. Four masked attackers, armed with weapons, forced them into a villa and stole cryptocurrency worth approximately ~$220,000. Authorities are still searching for eight other suspects.</p></li></ul></li><li><p>Criminal gang jailed for kidnapping and extorting cryptocurrency from victim [<a href="https://www.gmp.police.uk/news/greater-manchester/news/news/2025/january/criminal-gang-who-kidnapped-vulnerable-man-for-cryptocurrency-jailed-for-76-years/">Police report</a>]</p><ul><li><p>On 2 December 2023, police discovered a kidnapped man in an Irlam flat. He had been assaulted, tied up, and forced to transfer cryptocurrency under duress.</p></li><li><p>The investigation revealed the gang had targeted the victim multiple times, using violence, threats, and even drugging him to obtain cryptocurrency. They had extorted over &#163;100,000 before the final kidnapping.</p></li></ul></li><li><p>Three individuals are charged with kidnapping and assault over a failed cryptocurrency investment in Accra, Ghana [<a href="https://www.graphic.com.gh/news/general-news/ghana-news-cryptocurrency-fiasco-businessman-appeals-to-a-g-over-assault-kidnapping.html">Graphic Online</a>]</p><ul><li><p>The alleged assault occurred on December 19, 2024, when the victim was handcuffed, beaten, and electrocuted at one of the assaillant&#8217;s office for about 13 hours.</p></li><li><p>The attack followed claims that the victim held $600,000 linked to a misappropriated $1.6 million investment. Police intelligence intervened after a tip-off.</p></li></ul></li><li><p>Criminals steal cryptocurrencies after invading family&#8217;s home in S&#227;o Paulo, Brazil [<a href="https://livecoins.com.br/bandidos-roubam-criptomoedas-apos-render-familia-dentro-de-sua-propria-residencia-em-sao-paulo/">Livecoins</a>]</p><ul><li><p>A group of criminals broke into a home in S&#227;o Paulo, held a family hostage, and stole their cryptocurrencies. The attackers stayed in contact with a third accomplice by phone.</p></li><li><p>The stolen amount is estimated at $16,000, and the criminals also took the victims&#8217; cell phones. The Civil Police have launched an investigation but have not yet identified any suspects, nor how the criminals discovered the family&#8217;s holdings.</p></li></ul></li><li><p>A 30-year-old entrepreneur active in cryptocurrencies is kidnapped near Troyes, France during a staged client meeting [<a href="https://archive.is/1ULsg">JDD</a>]</p><ul><li><p>Four individuals, including a fake client, hold him hostage and demand a &#8364;20,000 ransom.</p></li></ul></li><li><p>Australian billionaire Tim Heath fights off kidnappers at his luxury apartment in Tallinn, Estonia [<a href="https://www.dailymail.co.uk/news/article-13995147/Aussie-billionaire-Tim-Heath-kidnapping.html">DailyMail</a>]</p><ul><li><p>The attackers, reportedly disguised as painters, had planned to abduct him and take him to a remote location. Heath, a cryptocurrency gambling entrepreneur, was targeted just before his new casino&#8217;s grand opening.</p></li></ul></li></ul></li></ul><h3><strong>Audience Questions</strong></h3><ul><li><p>01:00:55 Why, when you sign a transaction on the COLDCARD, does it generate 2 files. A &#8220;signed&#8221; and a &#8220;final&#8221; transaction. What&#8217;s the difference between the 2?</p></li><li><p>01:01:50 P1: What&#8217;s the maximum number of outputs there can be for a bitcoin transaction?</p></li><li><p>01:03:43 P2: Is there any way to estimate what the size that a transaction will be depending on it&#8217;s number of outputs? For example is a 1 input, 3 output tx 33% bigger than a 1 input, 2 output tx? Is it a linear calculation, or a curve?</p></li><li><p>01:04:13 Does using a passphrase offer any protection against a malicious hardware wallet? Or is it the same level as risk as just generating a regular seed?</p></li></ul><h3><strong>Privacy &amp; Other Related Bitcoin Projects</strong></h3><h4><strong>Software Releases &amp; Project Updates</strong></h4><ul><li><p>01:06:10 Maple AI by OpenSecret, is an end-to-end encrypted chat tool that enables private conversations with a general-purpose AI assistant, is now publicly available [<a href="https://github.com/OpenSecretCloud/opensecret">Github</a>] [<a href="https://blog.opensecret.cloud/opensecret-technicals/">Technical primer</a>]</p></li><li><p>01:06:20 SimpleX <a href="https://github.com/simplex-chat/simplex-chat/releases/tag/v6.3.0-beta.2">v6.3.0-beta.2</a></p><ul><li><p>Send mentions, mentions-only notification mode for groups</p></li><li><p>Support on-device message expiration per chat</p></li><li><p>Send reports to group moderators</p></li><li><p>Fast group deletion</p></li><li><p>To keep original filename private, use timestamp as video filename</p></li><li><p>Support connecting to SMP servers via port 443 (via Advanced network settings)</p></li></ul></li><li><p>01:11:00 TailsOS <a href="https://tails.net/news/version_6.12/">v6.12</a></p><ul><li><p>Prevent an attacker from monitoring Tor circuits:</p><ul><li><p>In Tails 6.11 or earlier, an attacker who has already taken control of an application in Tails could then exploit vulnerabilities in Onion Circuits and our Tor Browser wrapper that might lead to deanonymization.</p></li></ul></li><li><p>Prevent an attacker from changing the Persistent Storage settings</p></li></ul></li><li><p>01:13:24 Reticulum MeshChat <a href="https://github.com/liamcottle/reticulum-meshchat/releases/tag/v1.20.0">v1.20.0</a></p><ul><li><p>Add ability to manage additional interface types and settings thanks to @RFnexus in #60</p></li><li><p>Add ability to double click lxmf.delivery nodes in network visualiser to launch conversation</p></li><li><p>Add ability to double click nomadnetwork.node nodes in network visualiser to launch page browser</p></li><li><p>Add ability to reload ports when adding or editing an interface</p></li><li><p>Add IFAC network name to interface info when enabled</p></li></ul></li><li><p>NomadNet <a href="https://github.com/markqvist/NomadNet/releases/tag/0.6.0">v0.6.0</a></p><ul><li><p>Add ability to configure LXMF PN max_peers and static_peers</p></li><li><p>Update required RNS to 0.9.1 and LXMF to 0.6.1</p></li></ul></li><li><p>Signal now allows users to transfer their message history and the last 45 days of media when linking a new Desktop or iPad device to their primary account [<a href="https://signal.org/blog/a-synchronized-start-for-linked-devices/">Announcement</a>]</p><ul><li><p>Signal bundles the user&#8217;s data into a compressed, encrypted archive, which is then sent to the new device through Signal&#8217;s servers.</p></li></ul></li><li><p>01:25:26 VPN provider Mullvad updates payment method options and adds Lightning payment as experimental beta feature with a 10% discount [<a href="https://mullvad.net/en/account/payment/lightning">Payment portal</a>]</p><ul><li><p>Previously, a third-party <a href="https://vpn.sovereign.engineering/">service</a> was available to top-up Mullvad accounts, or purchase vouchers, using Lightning.</p></li></ul></li></ul><h4><strong>Project spotlight</strong></h4><ul><li><p><a href="https://zextras.com/carbonio">Carbonio</a>: A self-hosted digital workplace solution [<a href="https://github.com/Zextras">Github</a>]</p><ul><li><p>It features modern tools for email management, calendar coordination, video meetings, and collaborative document editing, designed for scalability and security.</p></li><li><p>The platform supports mobile access and provides businesses with a secure alternative to hyperscale cloud providers while offering robust file management and privacy controls.</p></li></ul></li><li><p><a href="https://www.stoutner.com/privacy-browser-android/">Privacy browser android</a>: An open-source browser designed to minimize data sent to the internet and stored on devices [<a href="https://gitweb.stoutner.com/">Code repository</a>]</p><ul><li><p>By default, it disables privacy-sensitive features like JavaScript and cookies, allowing users to enable them as needed per site.</p></li><li><p>Currently utilizing Android&#8217;s built-in WebView, future versions plan to adopt a forked version called Privacy WebView.</p></li></ul></li></ul><h3><strong>Lightning + L2+</strong></h3><h4><strong>Project spotlight</strong></h4><ul><li><p>01:26:17 Ark Wallet SDK: A TypeScript library for building Bitcoin wallets with support for both on-chain and off-chain transactions via Ark protocol. [<a href="https://github.com/arklabshq/wallet-sdk">Github</a>]</p><ul><li><p>The SDK offers JavaScript developers a secure, portable solution for implementing Bitcoin functionality without WebAssembly dependencies.</p></li></ul></li><li><p><a href="https://www.raycast.com/saunter/vortex">Vortex</a>: A Raycast extension that lets you control you bitcoin lightning wallet directly from MacOS [<a href="https://github.com/raycast/extensions/tree/5bda66fb25f9e0ad1ecf537cd7e354ac3f92cd7e/extensions/vortex/">Code repository</a>]</p><ul><li><p>The latest update introduces a Redeem command, allowing users to convert Cashu tokens into their Nostr Wallet Connect connected wallets.</p></li><li><p>Users can now withdraw satoshis from any LNURL-withdraw invoice into their connected wallets swiftly.</p></li></ul></li><li><p><a href="https://mnt.cash/">MNT</a>: Cashu mint with admin dashboard [<a href="https://github.com/gandlafbtc/mint">Github</a>]</p><ul><li><p>MNT introduces a new Cashu mint featuring an integrated admin dashboard.</p></li><li><p>The platform simplifies the management of ecash transactions by providing a user-friendly interface.</p></li></ul></li><li><p><a href="https://paywally.pages.dev/">Paywally</a>: A standalone web app with a lightning paywall powered by Cashu</p><ul><li><p>The application fetches a 19-satoshi invoice from a specified Lightning Network address, creates a melt quote with this invoice, and upon payment, grants access to the protected content.</p></li></ul></li><li><p><a href="https://supertestnet.github.io/mint_marketcap/">Mint Marketcap</a>: A stats website that tries to guess how much money bitcoiners store on ecash mints [<a href="https://github.com/supertestnet/mint_marketcap">Github</a>]</p><ul><li><p>It queries each cashu mint for an invoice, extracts the public key, and retrieves associated data to approximate holdings.</p></li></ul></li></ul><h4><strong>Software Releases &amp; Project Updates</strong></h4><ul><li><p>Rust Lightning <a href="https://github.com/lightningdevkit/rust-lightning/releases/tag/v0.1.1">v0.1.1</a> - &#8220;Onchain Matters&#8221;</p><ul><li><p>API Updates:</p><ul><li><p>Re-Add a <code>ChannelManager::send_payment_with_route</code></p></li><li><p>Add <code>RawBolt11Invoice::{to,from}_raw</code></p></li></ul></li><li><p>Security: 0.1.1 fixes a denial-of-service vulnerability allowing channel counterparties to cause force-closure of unrelated channels.</p></li></ul></li><li><p>Zeus <a href="https://github.com/ZeusLN/zeus/releases/tag/v0.9.5">v0.9.5</a></p><ul><li><p>Embedded LND: Seed: allow export of ypriv/zpriv (export to external wallets like Sparrow)</p></li><li><p>CLNRest: add ability to use all funds for channel open</p></li><li><p>Activity list: performance improvements</p></li><li><p>Lurker mode improvements</p></li><li><p>Improve display of memos and keysend messages</p></li><li><p>Allow return key for password login</p></li><li><p>Automatically include routing hints if node has only unannounced channels</p></li><li><p>Wallets list: better highlighting of active mode</p></li><li><p>Enhance on-chain receive workflow and address type selection</p></li><li><p>Migration to new storage system</p></li></ul></li><li><p>Alby</p><ul><li><p>Alby Go <a href="https://github.com/getAlby/go/releases/tag/v1.9.0">v1.9.0</a></p><ul><li><p>Real-time push notifications of sent and received payments</p></li><li><p>Support to pay 0-amount invoices</p></li><li><p>Update LN address flow to avoid confusion</p></li><li><p>Increase button touch area in header for ease of use</p></li></ul></li><li><p>Lightning-browser-extension <a href="https://github.com/getAlby/lightning-browser-extension/releases/tag/v3.11.0">v3.11.0</a> - Pleiades over Half Dome</p><ul><li><p>Separate card for just importing nostr key</p></li><li><p>Add sinhalese to language switcher</p></li><li><p>Add tamil and russian language to locale switcher</p></li><li><p>Show pending and failed transactions for NWC</p></li></ul></li></ul></li><li><p>Aqua Wallet <a href="https://github.com/AquaWallet/aqua-wallet/releases/tag/0.2.7">v0.2.7</a></p><ul><li><p>New Features:</p><ul><li><p>Select from different price feeds</p></li><li><p>Set a passcode</p></li><li><p>Toggle between the Bitcoin Price, Total Account Balance, and hide account balance on the header</p></li><li><p>Send and receive Liquid USDt on 4 new chains</p></li><li><p>Add a button to clear inputs in address entry fields</p></li><li><p>Add new Share Logs features in settings to help debug errors</p></li></ul></li><li><p>Integrations:</p><ul><li><p>Add Changelly for USDt swaps in the US and Thailand</p></li><li><p>Add BTC Direct to buy Bitcoin in Europe</p></li><li><p>Add Money Badger support for Lightning payments at Pick n Pay</p></li></ul></li></ul></li><li><p>CDK <a href="https://github.com/cashubtc/cdk/tree/main/releases/tag/v0.7.0">v0.7.0</a></p><ul><li><p><code>Token::to_raw_bytes</code> serializes generic token to raw bytes</p></li><li><p><code>Token::try_from</code> for <code>Vec&lt;u8&gt;</code> constructs a generic token from raw bytes</p></li><li><p><code>TokenV4::to_raw_bytes()</code> serializes a TokenV4 to raw bytes following the spec</p></li><li><p><code>Wallet::receive_raw</code> which receives raw binary tokens</p></li><li><p>cdk-mint-rpc: Mint management gRPC client and server</p></li><li><p>cdk-common: cdk specific types and traits</p></li><li><p>cashu: Core types and functions defined in NUTs</p></li></ul></li><li><p>Cashu-ts <a href="https://github.com/cashubtc/cashu-ts/releases/tag/v2.2.0">v2.2.0</a></p><ul><li><p>Move to vite for bundling (updated target + typescript, added standalone builds)</p></li><li><p>Add custom output data for consumers to take control over the output data used for proof creation</p></li><li><p>Use <code>sendOption</code> type in function argument</p></li></ul></li><li><p>Nutshell <a href="https://github.com/cashubtc/nutshell/releases/tag/0.16.5">v0.16.5</a></p><ul><li><p>This maintenance release contains various bug fixes for the mint and the wallet. Most notably, overpaid Lightning fees are now issued to the user at the next restart of the mint in cases where the mint has crashed or turned off while an outgoing Lightning payment was still pending.</p><ul><li><p>Add restart policy for Redis Docker container</p></li><li><p>Issue NUT-08 overpaid Lightning fees for melt quote checks on startup</p></li></ul></li></ul></li><li><p>Clams Remote <a href="https://github.com/clams-tech/Remote/releases/tag/remote-2.6.0">v2.6.0</a></p><ul><li><p>Add TipModal component to settings screen</p></li></ul></li><li><p>Plan B Network [<a href="https://planb.network/en/public-communication/blogs-and-news/feature/jan-new-features">January update</a>]</p><ul><li><p>Brand-new student dashboard</p></li><li><p>Add course conclusion pages</p></li><li><p>Expand resources section</p></li><li><p>Announce future search portal</p></li><li><p>Plan B Network launches Plan &#8383; Labs - Lightning, a biweekly live session focusing on the Lightning Network&#8217;s developments and technical intricacies [<a href="https://x.com/planb_network/status/1883909506993913966">Announcement</a>]</p></li></ul></li></ul><h3><strong>Nostr</strong></h3><h4><strong>Project spotlight</strong></h4><ul><li><p><a href="https://roz.coracle.social/">Roz</a>: A notary for nostr events [<a href="https://github.com/coracle-social/roz">Github</a>]</p><ul><li><p>Roz is a proof-of-concept notary for nostr events, providing timestamp verification for event authenticity.</p></li></ul></li><li><p><a href="https://vertexlab.io/">Vertex</a>: A fast, reliable and open source Web of Trust DVM service based on the Personalized Pagerank algorithm [<a href="https://github.com/vertex-lab">Github</a>]</p><ul><li><p>The service features a custom-designed data structure for rapid access to Pagerank and Personalized Pagerank within nostr, with all responses cryptographically signed by Vertex&#8217;s key.</p></li></ul></li><li><p><a href="https://lockbox.fiatjaf.com/">Lockbox</a>: A Nostr relay that accepts notes that should only be read by people you follow [<a href="https://git.fiatjaf.com/lockbox">Code repository</a>]</p><ul><li><p>Lockbox allows users to publish notes visible only to those they follow, using specific nostr protocols like NIP-70 and NIP-42</p></li><li><p>Notes can be shared from any client, but require the inclusion of a &#8220;-&#8220; tag and support for authentication.</p></li></ul></li><li><p>nostrdb-mcp: A Model Context Protocol server for nostrdb [<a href="https://github.com/damus-io/nostrdb-mcp">Github</a>]</p><ul><li><p>nostrdb-mcp enables LLMs to interact with the nostrdb command-line tool for local queries. The server uses your Notedeck directory by default, allowing it to search your notes.</p></li></ul></li><li><p><a href="https://freeflow.app/">Freeflow</a>: A TikTok clone in Flutter and Nostr [<a href="https://github.com/nostrlabs-io/freeflow">Github</a>]</p><ul><li><p>Users willing to post content can use zap.stream or olas to create shorts.</p></li></ul></li><li><p><a href="https://www.pinja.in/">Pinja</a>: A decentralized social media using the Nostr protocol</p><ul><li><p>The platform offers features such as messaging, notifications, and search functionality.</p></li></ul></li><li><p><a href="https://bitvid.network/">BitVid</a>: A decentralized platform where users can share videos and follow creators with privacy and freedom [<a href="https://github.com/PR0M3TH3AN/bitvid">Github</a>]</p><ul><li><p>The platform employs WebTorrent for peer-to-peer video streaming and Nostr for secure, password-free user authentication</p></li></ul></li><li><p>Crawler: A nostr crawler that generates random walks used for computing monte-carlo pagerank and personalized pagerank [<a href="https://github.com/vertex-lab/crawler">Github</a>]</p><ul><li><p>Vertex-lab&#8217;s crawler continuously scans the nostr network, focusing on follow lists (kind3s), to maintain an updated database.</p></li></ul></li></ul><h4><strong>Software Releases &amp; Project Updates</strong></h4><ul><li><p>rust-nostr <a href="https://github.com/rust-nostr/nostr/releases/tag/v0.39.0">v0.39.0</a></p><ul><li><p>Add NIP96 support</p></li><li><p>Add NIP22 helpers</p></li><li><p>Adjust NIP01</p></li><li><p>Add <code>try_connect</code> and <code>wait_for_connection</code> methods for better connection handling</p></li><li><p>Add support for custom WebSocket clients (both in Rust, Python, Kotlin and Swift)</p></li><li><p>New JVM bindings</p></li><li><p>Huge reduction of UniFFI bindings binaries size</p></li></ul></li><li><p>Primal <a href="https://github.com/PrimalHQ/primal-android-app/releases/tag/2.1.4">v2.1.4</a></p><ul><li><p>This update implemented the following:</p><ul><li><p>Primal Wallet NWC</p></li><li><p>Primal Legend cards</p></li><li><p>Legends &amp; Primal OG Leaderboards</p></li><li><p>Updated Legends Settings with leaderboard toggle and shoutout edits</p></li><li><p>Deep links for primal.net notes</p></li><li><p>Spotify and Tidal link previews</p></li><li><p>Embedded web player for YouTube, Spotify and Tidal</p></li><li><p>Rendering referenced note zaps</p></li><li><p>Support for kind20 referenced events in feeds</p></li><li><p>Showing top zaps in all note feeds (incl. thread screen)</p></li><li><p>Clikcable zap links in Reactions screen &amp; Wallet TX details</p></li></ul></li></ul></li><li><p>Olas <a href="https://njump.me/nevent1qqspwvafemvmthp2f6qh67h3zt0xftvwzfsrx626rn3fmx8lph83stcppamhxue69uhkummnw3ezumt0d5q3wamnwvaz7tmwdaehgu3wvekhgtnhd9azucnf0gq3gamnwvaz7tmjv4kxz7fwdehhxarj9e3xwqguwaehxw309ahx7um5wghxy6t5vdhkjmn9wgh8xmmrd9skc3kw6kx">Update</a></p><ul><li><p>Multiple images per post</p></li><li><p>Pause videos when switching away from the video feed</p></li><li><p>Add Instagram-like filters</p></li><li><p>Improve Nostr-native wallet</p></li><li><p>Improve NWC reliability</p></li><li><p>Add setting to toggle between displaying posts squared or full-length</p></li></ul></li><li><p>Damus</p><ul><li><p><a href="https://njump.me/naddr1qqjrjvtxvc6nwcee95unvv3e956rsef495unxep495ekzv3exa3kycnpx56nvq3q8m76awca3y37hkvuneavuw6pjj4525fw90necxmadrvjg0sdy6qsxpqqqp65w2r5vyn">v1.12</a> App Store release</p><ul><li><p>Render Gif and video files while composing posts</p></li><li><p>Add profile info text in stretchable banner with follow button</p></li><li><p>Paste Gif image similar to jpeg and png files</p></li></ul></li><li><p>Launch of the Alpha version of <a href="https://damus.io/notedeck/">Notedeck</a> for all users, Damus&#8217; multiplatform Nostr client [<a href="https://x.com/damusapp/status/1885504397721166167">Announcement</a>]</p></li></ul></li><li><p>Futr <a href="https://njump.me/note1709sh6ltc7y4emjfmtqd2970egcltwu5thr2rpvr2g03xnflh58q0swqve">v0.2.0</a></p><ul><li><p>Comment support with threaded discussions (NIP-10)</p></li><li><p>Repost and quote repost functionality (NIP-18)</p></li><li><p>Improve post rendering and content display</p></li><li><p>Event deletion support (NIP-09)</p></li><li><p>Persistent LMDB-based storage for all data</p></li><li><p>LRU caching system for improved performance</p></li><li><p>Optimize timeline storage and retrieval</p></li><li><p>Better subscription handling and event processing</p></li><li><p>Improve relay connection stability with websocket ping/pong</p></li><li><p>Better relay discovery through NIP-65 (Inbox &amp; Outbox Model)</p></li><li><p>Optimize subscription management</p></li><li><p>Enhance relay authentication</p></li><li><p>Reference post display</p></li><li><p>Comment threading and counts</p></li><li><p>Better notification handling for post updates</p></li><li><p>Consolidate LMDB operations</p></li><li><p>Improve subscription lifecycle management</p></li><li><p>Enhance tag parsing and handling</p></li><li><p>Optimize event caching and invalidation</p></li></ul></li><li><p>Flotilla</p><ul><li><p><a href="https://github.com/coracle-social/flotilla/releases/tag/0.2.7">v0.2.7</a></p><ul><li><p>Add calendar events</p></li><li><p>Make reply indicator nicer</p></li><li><p>Make share indicator nicer</p></li><li><p>Improve feed loading</p></li></ul></li><li><p><a href="https://github.com/coracle-social/flotilla/releases/tag/0.2.6">v0.2.6</a></p><ul><li><p>Add reply to long-press menu</p></li><li><p>Replace nsec.app signup with njump.me</p></li><li><p>Add new messages button in rooms</p></li><li><p>Add media server settings</p></li><li><p>Add build hash to about page</p></li></ul></li><li><p><a href="https://github.com/coracle-social/flotilla/releases/tag/0.2.5">v0.2.5</a></p><ul><li><p>Improve room and data loading</p></li><li><p>Drop support for legacy event kinds</p></li><li><p>Add support for back button navigation on android</p></li><li><p>Remove note to self page (still available via chat)</p></li><li><p>Improve chat conversation search</p></li><li><p>Change how reply UI works</p></li></ul></li></ul></li><li><p>Yakihonne</p><ul><li><p>Web <a href="https://njump.me/nevent1qqs2nrvrhypwvqdmjd9aq7z3y2mcg2yjp8ztvzvflchdl969pxsqacszyqsfsmac8em4m9k33r99e803pnndvylqadl9w69q7zcjkd7d4ssmxqcyqqqqqqgg6vglk">v4.3.0</a> / Mobile <a href="https://njump.me/nevent1qqs2nrvrhypwvqdmjd9aq7z3y2mcg2yjp8ztvzvflchdl969pxsqacszyqsfsmac8em4m9k33r99e803pnndvylqadl9w69q7zcjkd7d4ssmxqcyqqqqqqgg6vglk">v1.6.4</a></p><ul><li><p>Yakihonne wallet name customization for newly created wallets</p></li><li><p>Option to toggle between collapsed or expanded notes in the feed for a personalized experience</p></li><li><p>Notification preferences can now be managed directly from the settings page</p></li><li><p>Quick access to your profile with the newly added profile button</p></li><li><p>Native poll rendering and voting functionality within notes</p></li></ul></li></ul></li><li><p>Nak <a href="https://njump.me/nevent1qqsqqqqk8p2q42fd6r4apt38gfcs735vw3f27c7g097zl4dm39l46vgzyqalp33lewf5vdq847t6te0wvnags0gs0mu72kz8938tn24wlfze688776h">Update</a></p><ul><li><p>Nak wallet: Implement NIP-60 token receiving, sending and swapping</p></li><li><p>Nak curl: Wrap the actual curl command and add a NIP-98 header to it, allowing APIs calls with Nostr authorization</p></li><li><p>Nak mcp: Allow AIs to search people on Nostr, publish notes, mention people, read notes with built-in outbox model</p></li><li><p>Nak outbox: List NIP-65 relays for a given pubkey</p></li><li><p>Add option to pipe multiline JSON into &#8216;nak event&#8217; or &#8216;nak req&#8217;</p></li></ul></li><li><p>Narr <a href="https://github.com/fiatjaf/narr/releases/tag/v0.3.3">v0.3.3</a></p><ul><li><p>Setup amd64 and arm64 docker image builds</p></li><li><p>Increase article fetching limit to 300.</p></li></ul></li><li><p>Njump.me <a href="https://njump.me/nevent1qqsqqqrf9qpefte5fepz3wmz3u4uf022zrsj0m0lw0nara2g3ys0kvspp4mhxue69uhkummn9ekx7mqzyqalp33lewf5vdq847t6te0wvnags0gs0mu72kz8938tn24wlfze6frtjlt">Update</a></p><ul><li><p>Add support for kind:20 photos</p></li></ul></li><li><p>Keycast <a href="https://njump.me/note18rmtnvwectesnkk06u99qgxh0h48ce3mp3p0m8twpkvpvupetp2q6juv5z">Update</a></p><ul><li><p>Docker now actually builds properly</p></li><li><p>Simplify own domain setup</p></li><li><p>Simplify config via a single .env file</p></li><li><p>Add config for &#8220;allowed pubkeys&#8221;</p></li></ul></li><li><p>Citrine <a href="https://github.com/greenart7c3/Citrine/releases/tag/v0.7.1">v0.7.1</a></p><ul><li><p>Add the restore follows button back</p></li><li><p>Show notification when backing up database</p></li><li><p>Listen for pokey broadcasts</p></li></ul></li><li><p>nos.social <a href="https://github.com/planetary-social/nos/releases/tag/v1.1.1-299">v1.1.1</a></p><ul><li><p>Add Lists view and two ways to navigate to it</p></li><li><p>Add view for editing a list&#8217;s title and description</p></li><li><p>Add List detail view</p></li><li><p>Add view for managing users in a list</p></li><li><p>Add ability to delete lists</p></li><li><p>Add analytics for feed source selection and lists</p></li></ul></li><li><p>Amber</p><ul><li><p><a href="https://github.com/greenart7c3/Amber/releases/tag/v3.2.1">v3.2.1</a></p><ul><li><p>Add some details when signing a contact list</p></li><li><p>Refactor check for logged in account</p></li><li><p>After granting notification permissions show the notification</p></li></ul></li><li><p><a href="https://github.com/greenart7c3/Amber/releases/tag/v3.2.0">v3.2.0</a></p><ul><li><p>Add profile picture in the incoming requests screen when using a large screen device</p></li><li><p>Add more event kinds translations</p></li><li><p>Add a log with the bunker request response</p></li><li><p>Use the relay from the request to send the response when no app is found</p></li></ul></li><li><p><a href="https://github.com/greenart7c3/Amber/releases/tag/v3.1.9">v3.1.9</a></p><ul><li><p>Add missing logs for relay errors</p></li><li><p>Change listen for new connections button text and icons</p></li></ul></li></ul></li><li><p>Macadamia <a href="https://github.com/zeugmaster/macadamia/releases/tag/0.2.1">v0.2.1</a></p><ul><li><p>This release is the first to be published to the App Store:</p><ul><li><p>UI Improvements and project structure</p></li><li><p>Token V4 support, drop multi mint token redeem capability</p></li><li><p>Hide Mints instead of deleting</p></li><li><p>SwiftData thread safety &amp; melt recoverability</p></li><li><p>Add Onboarding</p></li></ul></li></ul></li><li><p>KeyChat App <a href="https://github.com/keychat-io/keychat-app/releases/tag/1.26.5%2B6319">v1.26.5</a></p><ul><li><p>Add browser tab</p></li><li><p>Support nip07 to login websites</p></li></ul></li><li><p>Fountain <a href="https://njump.me/nevent1qqsd9q6rc6wtql3l0rzpvg95sqxnyav99u65l3an676sxfq7amdgrjqzypjn3yj7h7mxraqcmrraqa97ut52l4mcwqwa3yrsctdfxm2hre2uxqcyqqqqqqgpj28fp">v1.1.14</a></p><ul><li><p>Improve Nostr connect</p></li><li><p>Add ability to switch between NIP55 and nsec</p></li><li><p>Add the ability to seek while paused</p></li></ul></li><li><p>Pokey <a href="https://github.com/KoalaSat/pokey/releases/tag/v0.1.4-alpha">v0.1.4-alpha</a></p><ul><li><p>Features</p><ul><li><p>Permanent and note notifications are now separated in 2 groups to be managed by Android settings</p></li><li><p>Number of connected relays now displays as part of the permanent notification</p></li></ul></li><li><p>What&#8217;s Changed</p><ul><li><p>Create a group for the service notification</p></li><li><p>Show connected relays</p></li></ul></li></ul></li><li><p>Haven</p><ul><li><p><a href="https://github.com/bitvora/haven/releases/tag/v1.0.5">v1.0.5</a></p><ul><li><p>Support for DB backup with Digital Ocean Spaces</p></li></ul></li><li><p><a href="https://github.com/bitvora/haven/releases/tag/v1.0.4">v1.0.4</a></p><ul><li><p>feat(lmdb): make LMDB map size configurable</p></li><li><p>NIP-40 and ReplaceableEvents</p></li></ul></li></ul></li><li><p>Algo Relay <a href="https://github.com/bitvora/algo-relay/releases/tag/v0.1.4">v0.1.4</a></p><ul><li><p>Ranking any note type: support for NIP-20 &amp; NIP-23</p></li></ul></li><li><p>nos2x-fox <a href="https://github.com/diegogurpegui/nos2x-fox/releases/tag/v1.17.0">v1.17.0</a></p><ul><li><p>Unique unified prompt popup to avoid flooding windows</p></li><li><p>New kind description in prompt popup</p></li></ul></li><li><p>Plebeian app launches the MVP of Plebeian.Market, its decentralized marketplace dedicated to goods and services tailored for the Bitcoin and Nostr communities [<a href="https://www.nobsbitcoin.com/plebeian-app-launches-mvp-of-plebeian-market-platform/">No BS Bitcoin</a>]</p><ul><li><p>After four years of development and multiple pivots, the Plebeian app has settled on NOSTR to demonstrate a proof of concept that is poised to disrupt traditional commerce.</p></li></ul></li></ul><h3><strong>Boosts</strong></h3><ul><li><p>01:26:35 Thanks to everyone who streamed sats, and shoutout to our top boosters:</p><ul><li><p>@Anonymous (2,100 sats) &#8220;Second best bitcoin show!&#8221;</p></li><li><p>@Anonymous (2,100 sats) &#8220;Created Bip85 seed for friend. Exported xpub to his bluewallet for deposits, and he recorded seed phrase. After listening to pod I freaked&#8230; SUCCESS!!! Seed words were good, on hardware wallet.&#8221;</p></li><li><p>@AVERAGE_GARY (100 sats) &#8220;&#129309;&#129782;&#129730;&#129292;&#129761;&#128079;&#128293;&#129395;&#128583;&#127995;&#8205;&#9794;&#65039;&#8221;</p></li></ul></li></ul><h3><strong>Tech Tips of the Day</strong></h3><ul><li><p><a href="https://linkcleaner.app/">Link cleaner</a>: An open-source progressive web app for removing tracking parameters from URLs [<a href="https://github.com/corbindavenport/link-cleaner">Github</a>]</p><ul><li><p>It works offline, can bulk process multiple links and integrate with device share menus.</p></li></ul></li></ul><h3><strong>Bitcoin Optech Newsletter</strong></h3><ul><li><p>Highlights from recent Bitcoin Optech Newsletters</p><ul><li><p><a href="https://bitcoinops.org/en/newsletters/2025/02/07/">340</a></p><ul><li><p>Channel force closure vulnerability in LDK</p></li><li><p>Zero-knowledge gossip for LN channel announcements</p></li><li><p>Discovery of previous research for finding optimal cluster linearization</p></li><li><p>Erlay update</p></li><li><p>Tradeoffs in LN ephemeral anchor scripts</p></li><li><p>Emulating OP_RAND</p></li><li><p>Discussion about lowering the minimum transaction relay feerate</p></li></ul></li><li><p><a href="https://bitcoinops.org/en/newsletters/2025/01/31/">339</a></p><ul><li><p>Vulnerability in LDK claim processing</p></li><li><p>Replacement cycling attacks with miner exploitation</p></li><li><p>Updated stats on compact block reconstruction</p></li></ul></li><li><p><a href="https://bitcoinops.org/en/newsletters/2025/01/24/">338</a></p><ul><li><p>Draft BIP for unspendable keys in descriptors</p></li><li><p>PSBTv2 integration testing</p></li><li><p>Correction about offchain DLCs</p></li></ul></li></ul></li></ul><h3><strong>News &amp; Noteworthy</strong></h3><h4><strong>Lightning + L2+</strong></h4><ul><li><p>Tether announces the integration of USDT on bitcoin&#8217;s Lightning Network, utilizing the Taproot Assets protocol developed by Lightning Labs [<a href="https://lightning.engineering/posts/2025-01-30-Tether-on-Lightning/">Announcement</a>]</p><ul><li><p>With over 350 million users, Tether aims to enable instant, low-cost cross-border USDT transactions on Lightning.</p></li><li><p>Developers are encouraged to integrate USDT on Lightning by downloading the latest version of the litd suite, which combines necessary services into a single binary for an easy integration.</p></li></ul></li><li><p>Core Lightning now offers bounties for open-source contributions on the CLN Build on L2 platform [<a href="https://x.com/Core_LN/status/1884867145743716774">Announcement</a>]</p><ul><li><p>Developers can browse <a href="https://community.corelightning.org/c/cln-bounties/">issues</a>, claim bounties, and contribute to CLN&#8217;s development.</p></li></ul></li></ul><h4><strong>Business &amp; Finance</strong></h4><ul><li><p>Blockstream launches Blockstream Asset Management and announces two Bitcoin-based investment funds: the Blockstream Income Fund and the Blockstream Alpha Fund, both set to open in Q1 2025. [<a href="https://blockstream.com/press-releases/2025-01-23-blockstream-asset-management-launch-bitcoin-funds/">Press release</a>]</p><ul><li><p>The Blockstream Income Fund aims to generate stable, predictable USD-based income by lending against Bitcoin collateral with conservative loan-to-value ratios.</p></li><li><p>The Blockstream Alpha Fund is designed to capitalize on Bitcoin&#8217;s ecosystem through diverse strategies, offering institutions and accredited investors exposure to Bitcoin&#8217;s growth potential.</p></li></ul></li><li><p>Casa launches Casa Business, enabling companies to hold digital assets in a 3-key vault for self-custody [<a href="https://blog.casa.io/introducing-casa-business/">Blog post</a>]</p><ul><li><p>The platform offers team signing, allowing multiple key holders within a company to manage the treasury securely</p></li></ul></li><li><p>Galoy launches Lana, a lending platform enabling banks to offer fiat loans secured by bitcoin collateral [<a href="https://www.galoy.io/galoy-blog/galoy-launches-lana-to-unlock-digital-asset-collateralized-lending-for-challenger-community-banks">Blog post</a>]</p><ul><li><p>Bitcoin-backed loans allow customers to access liquidity without selling assets, avoiding capital gains taxes.</p></li></ul></li><li><p>European fintech company Bringin launches its debit card [<a href="https://x.com/bringinxyz/status/1884948259833016386">Announcement</a>]</p><ul><li><p>The card integrates with Google Pay and Apple Pay via the Curve app, and enables tap-and-pay functionality at global merchants.</p></li></ul></li><li><p>Trivago integrates with Travala, allowing users to book hotels using over 100 cryptocurrencies, including bitcoin [<a href="https://www.theblock.co/post/338722/trivago-travala-integration-crypto-payments">The Block</a>]</p></li><li><p>Braiins Mining introduces <a href="https://solo.braiins.com/stats">Braiins Solo</a>, a dedicated solo pool designed for miners who want to mine independently, to avoid diluting the hashrate of the original Braiins Mining pool.</p></li><li><p>Bitcoin financial services company River announces zero-fee status for U.S.-based open-source Bitcoin developers and non-profits funding such development [<a href="https://blog.river.com/open-source-zero-fee/">Announcement</a>]</p></li><li><p>Rumble announces the development of Rumble Wallet, aiming to provide creators with a new way to transact using Bitcoin and Tether [<a href="https://cryptoslate.com/rumble-bets-on-bitcoin-with-new-creator-payment-wallet/">CryptoSlate</a>]</p><ul><li><p>Rumble has also entered a cloud services agreement with the Government of El Salvador, providing cloud storage, computing, databases, load balancers, and Kubernetes integration.</p></li></ul></li><li><p>FTX Recovery Trust to begin distributing funds to creditors in the convenience class (claims under $50,000) in February 2025 [<a href="https://x.com/FTX_Official/status/1886889964073373711">Announcement</a>]</p></li><li><p>Open House Group introduces bitcoin payments for property purchases in Japan [<a href="https://www.prnewswire.com/apac/news-releases/open-house-group-launches-real-estate-sales-via-cryptocurrency-302365274.html">PR Newswire</a>]</p><ul><li><p>The company collaborates with Diamond Hands, Japan&#8217;s largest Lightning Network community, to explore applications in real estate.</p></li><li><p>Research areas include operating full nodes for businesses and utilizing the Lightning Network for IoT micropayments.</p></li></ul></li><li><p>Digital Currency Group (DCG) launches Fortitude Mining, a wholly-owned subsidiary focusing on venture mining across various digital assets [<a href="https://www.businesswire.com/news/home/20250129138884/en/DCG-Launches-Fortitude-Mining-A-New-Venture-Mining-Subsidiary-Targeting-High-Growth-Digital-Assets">Business Wire</a>]</p></li></ul><h4><strong>AI</strong></h4><ul><li><p>Block introduces <a href="https://block.github.io/goose/docs/quickstart/">codename goose</a>: An open-source, extensible AI agent that goes beyond code suggestions [<a href="https://github.com/block/goose">Github</a>]</p><ul><li><p>Goose is compatible with a wide range of large language model providers, allowing users to choose and integrate their preferred model.</p></li></ul></li></ul><h4><strong>Funding</strong></h4><ul><li><p>OpenSats <a href="https://opensats.org/blog/ninth-wave-of-bitcoin-grants">announces</a> the Ninth Wave of Bitcoin Grants, supporting four projects that enhance open-source innovation, privacy, and accessibility within the Bitcoin ecosystem: Kibo, El Tor, Nutstash, and rust-bitcoin.</p></li><li><p>The 256 Foundation raises a total of 3.146 BTC for open-source bitcoin mining during its Telehash fundraiser [<a href="https://x.com/econoalchemist/status/1884756993312698567">Twitter post</a>]</p><ul><li><p>Supporters contributed hashrate to a self-hosted mining pool, which successfully solved block 881423 during the event.</p></li></ul></li><li><p>Brink renews its financial support for all of its 8 Bitcoin Core engineers through 2025: @fanquake, @glozow, @hhebasto, @theStack, @dergoegge, @stphnvlstk, @fjahr and @marcofleon [<a href="https://x.com/bitschmidty/status/1887559865050018285">Announcement</a>]</p></li><li><p>HRF announces all 11 bounties of its Bitcoin Bounty Challenge have been claimed by developers [<a href="https://njump.me/nevent1qqsyjvkr2gzs8yrsq2actl0xrj7cstng8gsgy26fuwla4q9s2jmz74qpzemhxue69uhhyetvv9ujumn0wd68ytnzv9hxgq3q7xvf49kht23cddxgw92rvfktkd3vqvjgkgsdexh9847wl0927tqsyhpwhy">Announcement</a>]</p></li><li><p>Spiral renews grant to Justin Moeller (@m1sterc001guy) for his work on Fedimint [<a href="https://x.com/spiralbtc/status/1884292908049920136">Announcement</a>]</p></li><li><p>Bitcoin association Einundzwanzig announces a 0.021 bitcoin donation to both <a href="https://x.com/_einundzwanzig_/status/1886794610703220825">Sparrow Wallet</a> and <a href="https://x.com/_einundzwanzig_/status/1886412747836969194">Alby</a>, and 0.1 bitcoin to the <a href="https://njump.me/nevent1qqsq08pc8x4gx7yu9uye2rpesexpn7w8a95zshmxq2thuepcfgfk5fqpzemhxue69uhhyetvv9ujumn0wd68ytnzv9hxgq3qqv02xpsc3lhxxx5x7xswf88w3u7kykft9ea7t78tz7ywxf7mxs9qad0sl4">legal defense of the Samourai Wallet developers</a>.</p></li><li><p>Breez secures $5 million to expand bitcoin payment integration [<a href="https://medium.com/breez-technology/breez-has-been-building-momentum-and-were-just-getting-started-06cf97c272ab">Blog post</a>]</p></li><li><p>Taproot Wizards raises $30 million in a post-seed funding round to enhance OP_CAT [<a href="https://www.theblock.co/post/338805/taproot-wizards-raises-30-million-to-expand-op_cat-functionality-on-bitcoin">The Block</a>]</p></li></ul><h4><strong>Mining</strong></h4><ul><li><p><a href="https://proto.xyz/">Proto</a> announces a long-term partnership with <a href="https://256foundation.org/">The 256 Foundation</a>, donating 256,000 Intel BZM2 chips to support decentralized bitcoin mining initiatives [<a href="https://www.mining.build/blog/decentralization-is-bigger-than-any-one-entity/">Announcement</a>]</p></li><li><p>Braiins Mining open sources its BCB 100 bitcoin mining control board as a contribution to the open-source mining initiative led by the 256 Foundation [<a href="https://x.com/BraiinsMining/status/1885036577702703232">Announcement</a>]</p><ul><li><p>The BCB 100, designed for Bitmain S19 series and Mini Miner, is now available for public use and development.</p></li></ul></li><li><p>Decentralization concerns grow as Bitcoin mining pools consolidate [<a href="https://x.com/JStefanop1/status/1887235853312757968">Twitter post</a>]</p><ul><li><p>The Bitcoin mempool displays live centralized mining pools that share the same Stratum jobs, reflecting increased consolidation. These pools collectively account for over 35% of the total network hashrate.</p></li><li><p>Antpool leads the consolidation, while other major Chinese pools like F2Pool and ViaBTC&#8212;known to collaborate with Antpool&#8212;are not included in this count. This suggests that over 51% of the hashrate is controlled by a few entities.</p></li></ul></li><li><p>Stolen identities lead to $1.9m bitcoin mining power theft in Malaysia [<a href="https://theminermag.com/news/2025-01-24/bitcoin-mining-identity-power-theft/">The Miner Mag</a>]</p><ul><li><p>Forty-five homeowners and business operators in Malaysia received power bills after tenants allegedly stole their identities to mine Bitcoin illegally.</p></li></ul></li></ul><h4><strong>Privacy</strong></h4><ul><li><p>France bans crypto mixers to combat money laundering [<a href="https://www.senat.fr/amendements/commissions/2023-2024/735/Amdt_COM-59.html">Amendment N&#176;COM-59</a>]</p><ul><li><p>The ban anticipates a similar European regulation effective from July 10, 2027. The French Senate&#8217;s legal commission adopted the amendment to address the alledgedly increasing use of mixers in laundering illicit funds.</p></li></ul></li><li><p>DARPA to launch pre-crime anti-money laundering program [<a href="https://www.therage.co/darpa-aml-precrime/">The Rage</a>]</p><ul><li><p>The Defense Advanced Research Projects Agency (DARPA) announces the Anticipatory and Adaptive Anti-Money Laundering (A3ML) program, aiming to develop algorithms that detect suspicious financial patterns to anticipate and prevent money laundering activities.</p></li><li><p>The objective of the program is to &#8220;eliminate global money laundering by replacing the current manual, reactive, and expensive analytic practices with agile, algorithmic methods&#8221;.</p></li></ul></li><li><p>Swiss FinMa accused of overstepping authority in implementing new KYC rule [<a href="https://www.therage.co/leaked-email-finma-abused-authority-to-implement-new-kyc-rule-based-on-tabloid-news-2/">The Rage</a>]</p><ul><li><p>A leaked email reveals that Switzerland&#8217;s Financial Market Supervisory Authority (FINMA) instructed Self-Regulatory Organizations to enforce a monthly 1,000 CHF limit on no-KYC transactions for Virtual Asset Service Providers. Critics argue that FINMA overstepped its authority, as it is permitted to issue guidance but not direct instructions to SROs.</p></li></ul></li><li><p>United Kingdom demands Apple to provide global backdoor access to encrypted data [<a href="https://archive.ph/M7I2C">The Washington Post</a>]</p><ul><li><p>The UK government has secretly ordered Apple to grant blanket access to users&#8217; encrypted cloud backups under the Investigatory Powers Act. This unprecedented demand applies worldwide, forcing Apple to either compromise encryption or withdraw the service in the UK. Apple has refused to comment but is expected to challenge the order.</p></li></ul></li><li><p>Digital rights group EFF urges dismissal of charges against Tornado Cash developer Roman Storm [<a href="https://www.coindesk.com/policy/2025/01/29/digital-rights-group-eff-calls-for-roman-storm-dismissal-in-tornado-cash-case">CoinDesk</a>]</p><ul><li><p>The Electronic Frontier Foundation emphasizes that many privacy tools are dual-use, serving legitimate purposes but potentially misused by bad actors. They argue that holding developers liable for misuse of their open-source software threatens innovation and privacy rights.</p></li></ul></li><li><p>Poland proposes changes to EU Chat Control, but concerns remain [<a href="https://www.patrick-breyer.de/en/half-good-new-polish-chat-control-proposal-to-be-discussed-on-wednesday/">Blog post</a>]</p><ul><li><p>Poland proposes making chat content searches voluntary instead of mandatory, aiming to protect encryption while still allowing surveillance.</p></li><li><p>The proposed ban on anonymous communication would require users to present an ID or facial verification to set up email or messaging accounts.</p></li></ul></li><li><p>The EU&#8217;s Artificial Intelligence Act prohibits real-time remote biometric identification by law enforcement in public spaces, except under specific circumstances. [<a href="https://reclaimthenet.org/eu-ai-act-effectively-legalizes-biometric-mass-surveillance">Reclaim The Net</a>]</p><ul><li><p>Exceptions include situations involving a present or foreseeable terrorist threat, allowing law enforcement to use such technology under certain conditions.</p></li><li><p>Critics argue that these exceptions effectively legalize biometric mass surveillance, as they provide legal avenues for its deployment.</p></li></ul></li><li><p>The Reserve Bank of India teams up with fintech firms MobiKwik, Cred, and Yes Bank to pilot the digital rupee [<a href="https://www.businesstoday.in/personal-finance/news/story/mobikwik-cred-join-hands-with-rbi-to-fully-launch-cbdc-ers-for-android-check-features-usage-462318-2025-01-28">Business Today</a>]</p><ul><li><p>The e&#8377; wallet app requires video verification and enforces daily limits of &#8377;50,000 ($577) and &#8377;10,000 ($115) per transaction. These platforms, with a combined user base of 180 million, will provide public access via the e&#8377; wallet app.</p></li></ul></li><li><p>Google revises AI principles, removes pledge against weaponization [<a href="https://techcrunch.com/2025/02/04/google-removes-pledge-to-not-use-ai-for-weapons-from-website/">TechCrunch</a>]</p><ul><li><p>Google has updated its AI principles, removing previous commitments to avoid developing AI for weapons and surveillance. This change aligns Google with other tech companies like Meta and OpenAI, which permit certain military applications of their technologies.</p></li></ul></li></ul><h4><strong>Security</strong></h4><ul><li><p>Tropic Square releases TROPIC01 RISC-V-based secure element samples for testing [<a href="https://www.tropicsquare.com/tropic01-samples">Announcement</a>]</p><ul><li><p>TROPIC01 is an open and auditable secure element designed to safeguard hardware systems.</p></li></ul></li></ul><h4><strong>Protocol</strong></h4><ul><li><p>Bitcoin Core #21590: Safegcd-based modular inverses in MuHash3072 [<a href="https://github.com/bitcoin/bitcoin/pull/21590">Merged</a>]</p></li><li><p>Bitcoin Core #31397: p2p: track and use all potential peers for orphan resolution [<a href="https://github.com/bitcoin/bitcoin/pull/31397">Merged</a>]</p></li><li><p>Bitcoin Core #31376: Miner: never create a template which exploits the timewarp bug [<a href="https://github.com/bitcoin/bitcoin/pull/31376">Merged</a>]</p></li><li><p>LDK #3408: Add static invoice creation utils to <code>ChannelManager</code> [<a href="https://github.com/lightningdevkit/rust-lightning/pull/3408">Merged</a>]</p></li><li><p>BOLT #1110: Peer storage for nodes to distribute small encrypted blobs [<a href="https://github.com/lightning/bolts/pull/1110">Merged</a>]</p></li><li><p>Eclair #2982: Add liquidity griefing protection for liquidity ads [<a href="https://github.com/ACINQ/eclair/pull/2982">Merged</a>]</p></li><li><p>Eclair #2968: Send <code>channel_announcement</code> for splice transactions on public channels [<a href="https://github.com/ACINQ/eclair/pull/2968">Merged</a>]</p></li><li><p>NIP #1713: Add NIP-4A Event Onion Routing [<a href="https://github.com/nostr-protocol/nips/pull/1713">Open</a>]</p></li><li><p>NIP #1718: NIP-101 - Decentralized Trust System for Nostr [<a href="https://github.com/nostr-protocol/nips/pull/1718">Open</a>]</p></li><li><p>NIP #1728: Re-write NIP 89 to accommodate relays/dvms [<a href="https://github.com/nostr-protocol/nips/pull/1728">Open</a>]</p></li></ul><h4><strong>Government &amp; Political</strong></h4><ul><li><p>Czech President Petr Pavel signs a bill exempting Bitcoin and other digital assets from capital gains tax if held for more than three years [<a href="https://www.coindesk.com/policy/2025/02/06/czech-republic-to-eliminate-taxes-on-long-term-crypto-gains">CoinDesk</a>]</p><ul><li><p>Individual transactions up to CZK 100,000 (approximately $4,136) per year will not need to be reported to tax authorities</p></li></ul></li><li><p>Czech National Bank Governor plans to propose investing up to 5% of the bank&#8217;s &#8364;140 billion reserves in bitcoin [<a href="https://www.coindesk.com/markets/2025/01/29/czech-central-bank-governor-to-present-plan-to-add-bitcoin-to-its-reserve-ft">CoinDesk</a>]</p><ul><li><p>The governor emphasizes that diversifying assets with bitcoin is beneficial, stating that the cryptocurrency&#8217;s value is likely to rise independently of U.S. President Donald Trump&#8217;s backing.</p></li><li><p>European Central Bank President Christine Lagarde dismisses the proposal, asserting that bitcoin will not be part of central bank reserves due to concerns over its liquidity, safety, and security. [<a href="https://www.reuters.com/markets/europe/ecbs-lagarde-slaps-down-czech-proposal-bitcoin-reserves-2025-01-30/">Reuters</a>]</p></li></ul></li><li><p>Tornado Cash developer Alexey Pertsev released from prison to prepare appeal [<a href="https://www.coindesk.com/policy/2025/02/07/tornado-cash-developer-alexey-pertsev-set-to-be-released-from-prison">CoinDesk</a>]</p><ul><li><p>In May 2024, Pertsev was sentenced to 64 months in prison for money laundering.</p></li></ul></li><li><p>U.S. government argues money isn&#8217;t property to justify seizure [<a href="https://reason.com/2025/01/31/the-government-says-money-isnt-property-so-it-can-take-yours">Reason</a>]</p><ul><li><p>The U.S. Department of Justice contends that confiscating $50,000 from small business doesn&#8217;t violate property rights, asserting that &#8220;money is not necessarily &#8216;property&#8217; for constitutional purposes.&#8221;</p></li><li><p>The DOJ&#8217;s argument includes three points: the government creates money, so individuals can&#8217;t own it; the government can tax money, indicating lack of ownership; and the Constitution permits government spending for the &#8220;general welfare.&#8221;</p></li></ul></li><li><p>El Salvador amends Bitcoin law following IMF agreement [<a href="https://www.reuters.com/world/americas/lawmakers-el-salvador-rush-new-bitcoin-reform-after-imf-deal-2025-01-30/">Reuters</a>]</p><ul><li><p>On January 29, 2025, El Salvador&#8217;s Congress approved a bill to amend the nation&#8217;s bitcoin law, aligning with a $1.4 billion loan agreement made with the IMF in December 2024.</p></li></ul></li><li><p>U.S. President Trump establishes working group on digital assets [<a href="https://www.whitehouse.gov/presidential-actions/2025/01/strengthening-american-leadership-in-digital-financial-technology/">Press release</a>]</p><ul><li><p>The group aims to develop a federal regulatory framework for digital assets, including stablecoins, and will evaluate establishing a national digital asset reserve.</p></li></ul></li></ul><h4><strong>Events</strong></h4><ul><li><p><a href="https://www.bitcoin-renaissance.com/">Bitcoin Renaissance</a>: A pioneering &#8203;thought leadership summit that marks a new &#8203;chapter in the evolution of the Bitcoin &#8203;ecosystem.</p><ul><li><p>February 27-28, 2025 in Denver, U.S</p></li></ul></li><li><p><a href="https://apres.tech/v40-bitcoin-ski-summit-2025">Bitcoin Ski Summit</a>: The Bitcoin Ski Summit is an immersive, invite-only gathering in the heart of the Tetons.</p><ul><li><p>March 5-9, 2025 in Teton Village, U.S</p></li></ul></li><li><p><a href="https://optoutconf.com/">Opt Out Conf</a>: A Bitcoin only conference about Philosophy, Freedom, Economy, Open Source, Privacy, Individual Sovereignty, Nostr, Layer 2 and more!</p><ul><li><p>March 29, 2025 in Buenos Aires, Argentina</p></li></ul></li><li><p><a href="https://swiss-bitcoin-conference.com/">Swiss Bitcoin Conference</a>: Bitcoin only conference in Kreuzlingen on Lake Constance</p><ul><li><p>April 24-27, 2025 in Creuzlings, Switzerland</p></li></ul></li><li><p><a href="https://bitcareforum.it/">BitCare Forum</a>: The Italian Bitcoin Conference</p><ul><li><p>May 10, 2025 in Brescia, Italy</p></li></ul></li><li><p><a href="https://budapestbitcoin.com/">Budapest Bitcoin</a>: The Bitcoin Conference with a bit of difference</p><ul><li><p>August 8-9, 2025 in Budapest, Hungary</p></li></ul></li><li><p><a href="https://www.learningbitcoin.ca/">Learning Bitcoin</a>: A Bitcoin Education Conference</p><ul><li><p>August 16-17, 2025 in Vancouver, Canada</p></li></ul></li></ul><h3><strong>Reads</strong></h3><ul><li><p>Here&#8217;s a list of our top recently published reads:</p><ul><li><p>Bitcoin Payments: From Digital Gold to Everyday Currency, by Breez &amp; 1A1z [<a href="https://breez.technology/report/">Report</a>]</p></li><li><p>Block Size Report, by Orange Surf [<a href="https://research.mempool.space/block-size-report/">Mempool Research</a>]</p></li><li><p>What <em>is</em> a nostr app anyway?, by hodlbod [<a href="https://njump.me/naddr1qvzqqqr4gupzp978pfzrv6n9xhq5tvenl9e74pklmskh4xw6vxxyp3j8qkke3cezqqxnzden8qer2desx5mnzv3cs2k68w">Note</a>]</p></li><li><p>Is It the Money or Is It the People?, by Don Olanrewaju [<a href="https://mises.org/mises-wire/it-money-or-it-people">Mises Institute</a>]</p></li><li><p>Everyone knows your location, by Tim Sh [<a href="https://timsh.org/tracking-myself-down-through-in-app-ads/">Blog post</a>]</p></li></ul></li></ul><h3><strong>Episode submission ideas</strong></h3><ul><li><p>We&#8217;re looking for ideas for interesting panel conversations. To send Bitcoin related questions, just go to <a href="https://bitcoin.review/">bitcoin.review</a> and follow the contact links at the bottom of the page.</p></li></ul><h3><strong>Get in touch with the pod</strong></h3><ul><li><p><a href="https://twitter.com/bitcoinreviewhq">Podcast Twitter</a></p></li><li><p><a href="https://twitter.com/nvk">NVK Twitter</a></p></li><li><p><a href="https://t.me/BitcoinReviewPod">Telegram</a></p></li><li><p><a href="mailto:producer@coinkite.com">Email</a></p></li><li><p>Nostr &amp; LN &#9889;nvk@nvk.org (not an email!)</p></li></ul>]]></content:encoded></item><item><title><![CDATA[BR091 - AnchorWatch Trident Vault, Ledger Co-founder Kidnapped, Blue Wallet, M17, The Case for Multi-vendor Setups, Tails removes HWW Support + MORE ft. Craig & Rob]]></title><description><![CDATA[I&#8217;m joined by guests Craig Raw and Rob Hamilton to go through the list.]]></description><link>https://substack.bitcoin.review/p/br091-anchorwatch-trident-vault-ledger</link><guid isPermaLink="false">https://substack.bitcoin.review/p/br091-anchorwatch-trident-vault-ledger</guid><dc:creator><![CDATA[STACK TO THE FUTURE]]></dc:creator><pubDate>Fri, 24 Jan 2025 19:36:29 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a95ac75-ac77-4167-9383-9930a48690bb_1080x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I&#8217;m joined by guests <a href="https://twitter.com/craigraw">Craig Raw</a> and <a href="https://twitter.com/Rob1Ham">Rob Hamilton</a> to go through the list.</p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://bitcoin.review/podcast/episode-56/&quot;,&quot;text&quot;:&quot;Listen on your favorite podcast app&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://bitcoin.review/podcast/episode-56/"><span>Listen on your favorite podcast app</span></a></p><div><hr></div><h3><strong>Housekeeping</strong></h3><ul><li><p>00:01:11 Ross Ulbricht receives &#8216;a full and unconditional pardon&#8217; from U.S President Donald Trump [<a href="https://freeross.org/donate/">Fundraiser</a>]</p></li><li><p>00:03:44 New <a href="https://coinkite.com/careers#Marketing%20Manager">Marketing Manager position</a> open at Coinkite</p></li><li><p>00:03:48 Exchanges BullBitcoin, River, Strike, Relai, CashApp, and Swan were added to <a href="https://bitcoinsecurity.guide/">BitcoinSecurity.guide</a></p></li><li><p>00:04:15 Check out <a href="https://olas.app/">Olas</a> Awesome new nostr app from Pablo</p></li><li><p>00:04:48 Call for guests: If you are a maker, working on bitcoin projects, we would love to have you on the show. Reach out at producer@coinkite.com</p></li></ul><h3><strong>Urgent Vulnerability Disclosures</strong></h3><ul><li><p>00:05:58 Ledger co-founder David Balland released after kidnapping [<a href="https://www.bloomberg.com/news/articles/2025-01-23/co-founder-of-french-crypto-startup-freed-after-kidnapping">Bloomberg</a>]</p><ul><li><p>David Balland, co-founder of French crypto wallet startup Ledger SAS, was kidnapped from his home in central France on Tuesday, kidnappers demandning a substantial ransom in cryptocurrency.</p></li><li><p>Balland was freed on Wednesday night following a police operation and being rescued by the GIGN. He is currently receiving treatment from emergency services.</p></li><li><p>The kidnappers are said to have sent a finger as part of their request for money.</p></li></ul></li><li><p>00:12:28 AxeOS CSRF Vulnerability: Using CSRF Attack to update the Payout Address on BitAxe Bitcoin Miners [<a href="https://snotra.uk/axeos-csrf-vulnerability.html">Snotra&#8217;s disclosure</a>]</p><ul><li><p>AxeOS, the firmware for Bitaxe Bitcoin miners, lacks authentication and CSRF protections in its web interface, enabling unauthorized users on the same network to alter settings, including the stratum user, which determines the Bitcoin address for payouts.</p></li><li><p>A <a href="https://poc.snotra.cloud/bitaxe.html">proof-of-concept</a> demonstrates that visiting a malicious website can change a Bitaxe&#8217;s settings without user consent, redirecting mining rewards to an attacker&#8217;s Bitcoin address.</p></li><li><p>The web server&#8217;s permissive CORS headers further exacerbate the vulnerability, possibly allowing attackers to change hardware settings or upload malicious firmware.</p></li></ul></li></ul><h3><strong>Bitcoin</strong></h3><h4><strong>Software Releases &amp; Project Updates</strong></h4><ul><li><p>00:12:58 AnchorWatch launches U.S. service for bitcoin holders [<a href="https://x.com/AnchorWatch/status/1876297172204888193">Announcement</a>]</p><ul><li><p>AnchorWatch offers a bitcoin custody service with insurance from Lloyd&#8217;s of London, targeting U.S. customers holding between $250K and $100M in bitcoin.</p><ul><li><p>Key features of AnchorWatch&#8217;s service:</p></li><li><p>Insured custody for bitcoin without requiring users to give up their keys</p></li><li><p>Lloyd&#8217;s of London Coverholder</p></li><li><p>Trident Vault provides protection through signing transactions while insured</p></li><li><p>Seamless transition to self-custody when policy ends</p></li><li><p>AnchorWatch aims to provide protection against various risks, including theft, loss of keys, and death.</p></li></ul></li></ul></li><li><p><a href="https://github.com/Blockstream/miniscript-templates/blob/main/mint-005.md">Mint-005</a></p><ul><li><p>Mint-005 is a 3 key joint custody vault that provides a way for a Principal to secure bitcoin with the help of an Agent.</p></li><li><p>It uses a negative control approach, where by default funds cannot be moved unless both the Principal and the Agent sign the transaction.</p></li><li><p>There are recovery mechanisms in place for situations where a party loses their keys or the agreement between the Principal and the Agent expires.</p></li></ul></li><li><p>00:47:28 Bitcoin Core <a href="https://github.com/bitcoin/bitcoin/blob/master/doc/release-notes/release-notes-28.1.md">v28.1</a></p><ul><li><p>This release includes new features, various bug fixes and performance improvements, as well as updated translations.</p></li><li><p>P2P</p><ul><li><p>When the <code>-port</code> configuration option is used, the default onion listening port will now be derived to be that port + 1 instead of being set to a fixed value (8334 on mainnet). This re-allows setups with multiple local nodes using different <code>-port</code> and not using <code>-bind</code>, which would lead to a startup failure in v28.0 due to a port collision.</p></li><li><p>#30568 addrman: change internal id counting to int64_t</p></li></ul></li><li><p>Key: #31166 key: clear out secret data in DecodeExtKey</p></li><li><p>Build:</p><ul><li><p>#31013 depends: For mingw cross compile use <code>-gcc-posix</code> to prevent library conflict</p></li><li><p>#31502 depends: Fix CXXFLAGS on NetBSD</p></li></ul></li><li><p>Test:</p><ul><li><p>#31016 test: add missing sync to feature_fee_estimation.py</p></li><li><p>#31448 fuzz: add cstdlib to FuzzedDataProvider</p></li><li><p>#31419 test: fix MIN macro redefinition</p></li><li><p>#31563 rpc: Extend scope of validation mutex in generateblock</p></li></ul></li><li><p>Doc: #31007 doc: add testnet4 section header for config file</p></li><li><p>CI: #30961 ci: add LLVM_SYMBOLIZER_PATH to Valgrind fuzz job</p></li><li><p>Misc:</p><ul><li><p>#31267 refactor: Drop deprecated space in <code>operator""_mst</code></p></li><li><p>#31431 util: use explicit cast in MultiIntBitSet::Fill()</p></li></ul></li></ul></li><li><p>00:48:10 Wasabi Wallet <a href="https://github.com/WalletWasabi/WalletWasabi/releases/tag/v2.4.0">v2.4.0</a></p><ul><li><p>Add support sending to Silent Payment addresses: receiving is a work in progress</p></li><li><p>Instead of TestNet 3, Wasabi now uses TestNet 4</p></li><li><p>Release Notes are now also available in the client</p></li><li><p>A donation button has been added on the main screen</p></li></ul></li><li><p>00:48:15 BDK <a href="https://github.com/bitcoindevkit/bdk/releases/tag/v0.30.1">v0.30.1</a> - DEPRECATED</p><ul><li><p>The <a href="https://crates.io/crates/bdk">bdk</a> library is now deprecated and replaced by <a href="https://crates.io/crates/bdk_wallet">bdk_wallet</a>. All projects should migrate to <a href="https://crates.io/crates/bdk_wallet/1.0.0">bdk_wallet 1.0.0</a> or newer as soon as possible.</p><ul><li><p>Update bdk 0.30.x README docs to deprecate the bdk library</p></li></ul></li></ul></li><li><p>00:48:27 Nunchuk Android <a href="https://github.com/nunchuk-io/nunchuk-android/releases/tag/android.1.9.59">v1.9.59</a></p><ul><li><p>Taproot multisig wallets</p></li><li><p>Revamp add key flow</p></li><li><p>Honey Badger Premier</p></li></ul></li><li><p>00:48:37 Specter Desktop <a href="https://github.com/cryptoadvance/specter-desktop/releases/tag/v2.1.1">v2.1.1</a></p><ul><li><p>Add wallet export to Jade via QR</p></li><li><p>Expose internal node to localhost only</p></li><li><p>HWI upgrade to 2.4.x</p></li><li><p>Make Specter work with Bitcoin Core 28.0</p></li><li><p>Remove BLE code for Jade</p></li></ul></li><li><p>00:49:02 Bitcoin Keeper</p><ul><li><p><a href="https://github.com/bithyve/bitcoin-keeper/releases/tag/v1.3.3">v1.3.3</a></p><ul><li><p>Redesign Electrum Server Management</p></li><li><p>Add Keystone remote signing support</p></li><li><p>PDF export for individual wallet configuration files</p></li></ul></li><li><p><a href="https://github.com/bithyve/bitcoin-keeper/releases/tag/v1.3.2">v1.3.2</a></p><ul><li><p>Concierge: Introducing new technical support</p></li><li><p>Simplify collaborative wallet setup</p></li><li><p>Support alphanumeric PIN for Portal</p></li></ul></li></ul></li><li><p>00:49:18 Blue Wallet <a href="https://github.com/BlueWallet/BlueWallet/releases/tag/v7.0.7">v7.0.7</a></p><ul><li><p>Import xpub as zpub/ypub if it was ever used</p></li><li><p>New wallet export screen</p></li><li><p>Display Lightning details in Invoice View</p></li><li><p>Add HKD fiat</p></li><li><p>Add loading indicator to Edit Vault row</p></li><li><p>Set preferred server from menu</p></li><li><p>Keyboard accessory on vault modal</p></li><li><p>Android menu icons</p></li><li><p>And many fixes</p></li></ul></li><li><p>00:50:32 BTC Pay Server <a href="https://github.com/btcpayserver/btcpayserver/releases/tag/v2.0.6">v2.0.6</a></p><ul><li><p>This release contains a security fix for merchants using refunds/pull payments On-Chain with automated payout processors</p></li><li><p>New features</p><ul><li><p>SEO: Add ability to customize HTML meta tags and HTML lang attribute for crowdfund and PoS</p></li><li><p>Add the ability for merchants to manually transition a payout from the <code>InProgress</code> state to <code>AwaitingPayment</code></p></li></ul></li></ul></li><li><p>00:55:39 Liana <a href="https://github.com/wizardsardine/liana/releases/tag/v9.0">v9.0</a> - It&#8217;s over 90.00k !</p><ul><li><p>Breaking changes</p><ul><li><p>Running Liana v9 on an existing installation will migrate its database. Once migrated the database won&#8217;t be compatible with previous versions of Liana.</p></li><li><p>The new Minimum Supported Rust Version of the GUI software is now 1.80</p></li></ul></li><li><p>Liana daemon / library</p><ul><li><p>The daemon feature was removed, we expect user to use their own process manager like systemd</p></li><li><p>Three new columns are added to the table transaction: the number of inputs, the number of outputs and if the transaction is a coinbase transaction</p></li><li><p>A new column is added to the coins table: <code>is_from_self</code> and a new <code>field is_from_self</code> is added to the coin entry of the <code>list_coins</code> command</p></li></ul></li><li><p>Liana GUI</p><ul><li><p>New button on the transactions panel allows user to do an export of their transactions to an external file using the CSV format</p></li><li><p>Bitcoind and electrum information in the settings panel can now be copied to clipboard</p></li><li><p>Coins that are change from transactions that user control are now part of the balance</p></li><li><p>Unconfirmed coins can now be selected by the automatic selection if the coins is from transaction which inputs are controlled by the wallet</p></li></ul></li></ul></li><li><p>00:55:58 Blockstream</p><ul><li><p>Green QT <a href="https://github.com/Blockstream/green_qt/releases/tag/release_2.0.17">v2.0.17</a></p><ul><li><p>Add graphical assets for Jade Plus</p></li><li><p>Support video promo on Linux</p></li><li><p>Show total spent amount in transaction details</p></li></ul></li></ul></li><li><p>00:57:58 BoltzExchange</p><ul><li><p>boltz-web-app <a href="https://github.com/BoltzExchange/boltz-web-app/releases/tag/v1.6.1">v1.6.1</a></p><ul><li><p>Safety check before calculating fees</p></li><li><p>Show when no lockup can be found for refund</p></li><li><p>Show routing fees</p></li><li><p>Pro build configuration</p></li></ul></li></ul></li><li><p>00:58:00 Live Wallet <a href="https://github.com/Jwyman328/LiveWallet/releases/tag/1.0.0">v1.0.0</a></p><ul><li><p>Transaction privacy analyzing</p></li><li><p>Transaction output labeling (KYC, do not spend)</p></li></ul></li><li><p>00:58:11 Kyoto</p><ul><li><p><a href="https://github.com/rustaceanrob/kyoto/releases/tag/v0.8.0">v0.8.0</a></p><ul><li><p>Request the broadcast minimum fee rate from connected peers</p></li></ul></li><li><p><a href="https://github.com/rustaceanrob/kyoto/releases/tag/v0.7.0">v0.7.0</a></p><ul><li><p>Request a block using the <code>Client</code></p></li><li><p>Add <code>broadcast_random</code> convenience method on <code>Client</code></p></li><li><p>Request a <code>Range</code> of block headers from <code>Client</code></p></li></ul></li></ul></li><li><p>00:58:19 ESP-Miner</p><ul><li><p><a href="https://github.com/skot/ESP-Miner/releases/tag/v2.5.0">v2.5.0</a></p><ul><li><p>Critical fix: CSRF vulnerability patch</p></li></ul></li><li><p><a href="https://github.com/skot/ESP-Miner/releases/tag/v2.4.5">v2.4.5</a></p><ul><li><p>Critical fix on devices without PSRAM module: Allow device to start without SPIRAM</p></li></ul></li><li><p><a href="https://github.com/skot/ESP-Miner/releases/tag/v2.4.3">v2.4.3</a></p><ul><li><p>Enable PSRAM</p></li><li><p>Configure GPIO in Kconfig</p></li></ul></li></ul></li><li><p>00:58:21 Bitcoin Safe <a href="https://github.com/andreasgriffin/bitcoin-safe/releases/tag/1.0.1">v1.0.1</a></p><ul><li><p>Add dark mode support</p></li><li><p>Add delete coin category (via right click context menu) additionally to the &#8220;drag to delete button&#8221; method</p></li><li><p>Fixes missing USB (HWI) support in Windows and Mac builds</p></li></ul></li><li><p>00:58:40 BTC Map</p><ul><li><p><a href="https://github.com/teambtcmap/btcmap-android/releases/tag/v0.9.1">v0.9.1</a></p><ul><li><p>Allow users to post merchant comments</p></li><li><p>Add special icon for debug builds</p></li></ul></li><li><p><a href="https://github.com/teambtcmap/btcmap-android/releases/tag/v0.9.0">v0.9.0</a></p><ul><li><p>Switch to vector maps</p></li></ul></li></ul></li></ul><h4><strong>Project spotlight</strong></h4><ul><li><p>00:58:44 Bitaxe Touch: A new touch screen single ASIC chip Bitcoin solo miner [<a href="https://www.solosatoshi.com/unveiling-the-bitaxe-touch-the-worlds-first-touchscreen-bitcoin-miner/">Announcement</a>]</p><ul><li><p>The Bitaxe Touch, developed by Open Source Miners United, is a touch screen Bitcoin miner featuring an 800&#215;480 pixel LCD that displays real-time Bitcoin price, Mempool data, power usage, hashrate, and temperature.</p></li><li><p>It is powered by the Bitaxe 601 Gamma, and utilizes the BM1370 ASIC chip from the Bitmain S21 Pro, with a hash rate of up to 1.6 TH/s.</p></li></ul></li><li><p>00:58:51 Coinswap: Functioning, minimal-viable binaries and libraries to perform a trustless, p2p Maxwell-Belcher Coinswap Protocol [<a href="https://github.com/citadel-tech/coinswap">Github</a>]</p><ul><li><p>The project offers a minimal viable implementation of a trustless, peer-to-peer Maxwell-Belcher Coinswap protocol using HTLCs on Bitcoin.</p></li><li><p>It includes automated integration testing on Bitcoin Regtest and operates over Tor by default. The system supports multiple users (makers, taker, and directory server).</p></li><li><p>Coinswap releases its [v0.1.0]<code>(https://github.com/citadel-tech/coinswap/releases/tag/v0.1.0</code>) - First Public Beta Release</p><ul><li><p>Complete Protocol Specification:</p><ul><li><p>The full Coinswap protocol has been formalized and documented in detail</p></li><li><p>Explore the Coinswap Protocol Specification to understand how it ensures decentralized, private, and censorship-resistant swaps</p></li></ul></li><li><p>Functional Test Coverage:</p><ul><li><p>A robust set of functional tests has been introduced to simulate swap scenarios and ensure protocol correctness</p></li><li><p>Dive into the tests and explore various swap situations: Functional Tests</p></li></ul></li><li><p>Modular Protocol Design: All protocol components have been modularized for flexibility, extensibility, and easier integration into other Bitcoin applications</p></li><li><p>Command-Line Applications: Coinswap introduces three key command-line apps:</p><ul><li><p><code>makerd</code>: Run as a swap service provider and earn fees</p></li><li><p><code>maker-cli</code>: Manage your maker server via a command-line interface</p></li><li><p><code>taker</code>: Act as a client and perform swaps with multiple makers</p></li></ul></li></ul></li></ul></li><li><p>00:59:20 <a href="https://paulmillr.com/noble/#scure">Scure</a>: Audited &amp; minimal library for creating, signing &amp; decoding Bitcoin transactions [<a href="https://github.com/paulmillr/scure-btc-signer">Github</a>]</p><ul><li><p>The library allows users to create, sign, and decode Bitcoin transactions, including support for classic and SegWit addresses.</p></li><li><p>Scure provides functionality for Schnorr &amp; Taproot BIP340/BIP341, and BIP174 PSBT, with minimal dependencies.</p></li></ul></li><li><p>00:59:28 <a href="https://bitcoinisdata.com/">Bitcoin Is Data</a>: A comprehensive Bitcoin metrics and visualizations platform launches two new sections related to UTXOs, Quantity of UTXOs and Balances of UTXOs, segmented by Bitcoin transaction types.</p></li><li><p>Bitcoin Fee Indicator: A system tray application that fetches and displays current Bitcoin transaction fee rates [<a href="https://github.com/frnandu/bitcoin-fee-indicator">Github</a>]</p><ul><li><p>It shows various fee rates, including fastest, half-hour, hourly, economy, and minimum, updating every 5 minutes.</p></li></ul></li><li><p>Kernel-Node: An experimental bitcoin node written in Rust using the libbitcoinkernel library [<a href="https://github.com/TheCharlatan/kernel-node">Github</a>]</p><ul><li><p>Its primary function is to validate blocks but not to serve them to the network. The implementation highlights the limited initial API of the kernel library.</p></li></ul></li><li><p>00:59:43 Qoinstr: A GUI tool for rust-joinstr [<a href="https://github.com/pythcoiner/qoinstr">Github</a>]</p><ul><li><p>Qoinstr is a work-in-progress graphical user interface designed to interact with the rust-joinstr library</p></li></ul></li><li><p><a href="https://fool.shinyapps.io/firstrshiny/">First Rshiny</a>: An interactive visualization tool used to explore Bitcoin&#8217;s dollar-cost averaging performance</p></li><li><p>00:59:53 <a href="https://opentollgate.github.io/tollgate/">TollGate</a>: A tool enabling WiFi routers to accept Bitcoin payments for internet access</p><ul><li><p>TollGate allows users with a router and internet connection to operate as internet service providers by accepting Bitcoin payments for access.</p></li></ul></li><li><p>Explore <a href="https://mempool.space/">Mempool.space</a> through two new lenses:</p><ul><li><p><a href="https://mempoo.space/">Mempoo.space</a>, a Bitcoin Poo Explorer showing ordinals as poo emojis</p></li><li><p><a href="https://memepool.space/">Memepool.space</a>, a Bitcoin Meme Explorer, showing memes in blocks</p></li></ul></li><li><p><a href="https://www.bitcoinfax.net/">BitcoinFax</a>: Send faxes worldwide with bitcoin payments over the Lightning Network</p></li></ul><h3><strong>Vulnerability Disclosures</strong></h3><ul><li><p>01:01:27 Unique 0-click deanonymization attack targeting Cloudflare-backed apps, Signal and Discord users vulnerable [<a href="https://gist.github.com/hackermondev/45a3cdfa52246f1d1201c1e8cdef6117">Disclosure</a>]</p><ul><li><p>A researcher discovers a 0-click attack leveraging Cloudflare caching to locate users within a 250-mile radius. This method uses the cf-ray HTTP header to identify the closest datacenter based on cached resource requests.</p></li><li><p>A tool called Cloudflare Teleport briefly exploited this before being patched</p></li></ul></li><li><p>01:02:00 UEFI secure boot vulnerability allows malicious bootkit deployment [<a href="https://thehackernews.com/2025/01/new-uefi-secure-boot-vulnerability.html">The Hacker News</a>]</p><ul><li><p>ESET researchers discover CVE-2024-7344, a vulnerability enabling attackers to bypass UEFI Secure Boot, leading to potential deployment of malicious bootkits.</p></li><li><p>The flaw exists in a UEFI application signed by Microsoft&#8217;s third-party UEFI certificate, affecting multiple real-time system recovery software suites.</p></li><li><p>Exploitation allows execution of untrusted code during system boot, granting persistent access even on systems with Secure Boot enabled.</p></li></ul></li><li><p>01:02:23 Google Ad directs users to malicious homebrew clone [<a href="https://bitcoin.review/podcast/episode-91/1880730173634699393">Twitter post</a>]</p><ul><li><p>A sponsored Google ad linked users to a fake Homebrew site with a cURL command distributing malware. The malicious site&#8217;s URL differed by just one letter from the official Homebrew site.</p></li></ul></li><li><p>01:03:01 Critical rsync vulnerability on Linux and Unix systems, affecting versions 3.2.7 to 3.4.0, necessitates urgent updates [<a href="https://www.cyberciti.biz/linux-news/cve-2024-12084-rsyn-security-urgent-update-needed-on-unix-bsd-systems/">Cyberciti</a>]</p><ul><li><p>A heap-based buffer overflow vulnerability, identified as CVE-2024-12084, is found in the rsync daemon due to improper handling of attacker-controlled checksum lengths. This flaw allows an attacker to write out of bounds in the sum2 buffer.</p></li></ul></li><li><p>01:03:31 January 2025 Patch Tuesday: 10 critical vulnerabilities and eight zero-days among 159 CVEs [<a href="https://www.crowdstrike.com/en-us/blog/patch-tuesday-analysis-january-2025/">Crowdstrike Blog post</a>]</p><ul><li><p>Three zero-day vulnerabilities in Windows Hyper-V NT Kernel Integration VSP are actively exploited, allowing attackers to gain SYSTEM privileges</p></li><li><p>Other zero-day vulnerabilities affect Microsoft Access, Windows App Package Installer, and Windows Themes, potentially leading to remote code execution or elevation of privileges.</p></li></ul></li><li><p>01:03:48 Unsecured tunneling protocols expose 4.2 million hosts, including VPNs and routers [<a href="https://thehackernews.com/2025/01/unsecured-tunneling-protocols-expose-42.html">The Hacker News</a>]</p><ul><li><p>Researchers identify security flaws in tunneling protocols, affecting 4.2 million hosts, including VPN servers and routers.</p></li><li><p>Affected protocols lack authentication and encryption, allowing attackers to inject malicious traffic and perform denial-of-service attacks.</p></li></ul></li><li><p>01:03:58 Apple&#8217;s CUPS printing system vulnerable to spoofing attacks [<a href="https://cyberinsider.com/apples-cups-printing-system-vulnerable-to-spoofing-attacks/">CyberInsider</a>]</p><ul><li><p>Security researcher Simone Margaritelli discloses a critical vulnerability in Apple&#8217;s Common UNIX Printing System (CUPS), highlighting its failure to verify TLS certificates. This flaw permits attackers on the same network to impersonate IPP-over-HTTPS (IPPS) printers, enabling them to intercept, modify, or redirect print jobs, potentially exposing sensitive data and compromising systems.</p></li><li><p>The vulnerability arises from CUPS&#8217;s integration with Apple&#8217;s Bonjour discovery service, which automatically trusts network printers without proper authentication.</p></li></ul></li><li><p>01:04:11 Security researcher Thomas Roth demonstrates code execution on Apple&#8217;s ACE3 USB-C controller, enabling firmware extraction [<a href="https://www.forbes.com/sites/daveywinder/2025/01/14/apple-iphone-usb-c-hacked-what-you-need-to-know/">Forbes</a>]</p><ul><li><p>Apple acknowledges the attack&#8217;s complexity and does not perceive it as an immediate threat, opting not to address it currently.</p></li></ul></li><li><p>01:05:32 Five dollars wrench attacks:</p><ul><li><p>A Canadian, volunteer moderator on a cryptocurrency forum, becomes the target of individuals who believe he possesses significant wealth in bitcoin [<a href="https://www.lapresse.ca/actualites/justice-et-faits-divers/2025-01-06/tentative-alleguee-d-enlevement/ils-avaient-de-l-equipement-pour-me-torturer.php">La Presse</a>]</p><ul><li><p>Suspects, including two minors, allegedly plan to kidnap and torture him to extract his passwords, assuming he holds millions in cryptocurrency</p></li></ul></li><li><p>A 56-year-old man found tied up in car trunk after kidnapping in eastern France [<a href="https://www.francebleu.fr/infos/faits-divers-justice/un-homme-retrouve-ligote-dans-le-coffre-d-une-voiture-interceptee-par-la-police-pres-du-mans-deux-hommes-en-fuite-7958611">France Bleu</a>]</p><ul><li><p>The victim, kidnapped on December 31, 2024, was found tied up in the trunk of a car intercepted by police, 600 kilometers from his home.</p></li><li><p>The kidnappers, armed and masked, reportedly demanded a ransom from the victim&#8217;s son, a cryptocurrency influencer based in Dubai, after holding the family hostage.</p></li></ul></li><li><p>Pakistani trader kidnapped, forced to transfer $340,000 in cryptocurrency, seven arrested [<a href="https://decrypt.co/299993/pakistani-trader-kidnapped-340000-crypto">Decrypt</a>]</p><ul><li><p>Seven individuals, including a Counter-Terrorism Department officer, were arrested for kidnapping crypto trader Mohammed Arsalan in December 2024. Arsalan was abducted and forced to transfer $340,000 from his Binance account. The criminals later released him after the ransom was paid.</p></li></ul></li><li><p>Turkish man tied up and robbed of nearly $300,000 in cryptocurrency by three individuals in Pattaya, Thailand [<a href="https://www.bangkokpost.com/thailand/general/2940227/police-hunt-suspects-in-b10m-pattaya-crypto-robbery">Bangkok Post</a>]</p><ul><li><p>The assailants binded Erkol&#8217;s hands and ankles, leaving him to seek help from a condominium security guard</p></li></ul></li><li><p>Korean bitcoin trader rescued after abduction in Batangas, Philippines [<a href="https://www.philstar.com/nation/2025/01/20/2415405/korean-bitcoin-trader-rescued-batangas">Philstar</a>]</p><ul><li><p>Taehwa Kim, a 40-year-old Korean bitcoin trader, is rescued in Batangas, after being kidnapped in Makati City.</p></li><li><p>Kim meets a prospective buyer for his car at his condominium. During a test drive, three men force him into another vehicle, blindfold and tie his hands, and detain him for three days.</p></li></ul></li><li><p>Feds arrest a gang of 4 men accused of plotting to kidnap Miami jeweler for cryptocurrency [<a href="https://www.local10.com/news/local/2025/01/15/feds-arrest-goons-they-say-plotted-to-kidnap-rob-miami-jeweler-one-good-bop-should-do-it/">Local10</a>]</p><ul><li><p>The group used a Telegram group chat to plan the kidnapping of a Miami jeweler and theft of $2 million in cryptocurrency. Unbeknownst to them, an informant in their group chat alerted the FBI, leading to their arrest.</p></li><li><p>The suspects, armed with firearms, allegedly planned to kidnap the jeweler using a wired SUV provided by an undercover agent. The group intended to exchange watches for cryptocurrency as a ruse, then hold the victim for ransom.</p></li></ul></li></ul></li></ul><h3><strong>Privacy &amp; Other Related Bitcoin Projects</strong></h3><h4><strong>Software Releases &amp; Project Updates</strong></h4><ul><li><p>01:07:17 Tails <a href="https://tails.net/news/version_6.11/index.en.html">v6.11</a></p><ul><li><p>Critical security fixes</p><ul><li><p>Prevent an attacker from installing malicious software permanently</p></li><li><p>Prevent an attacker from monitoring online activity</p></li><li><p>Prevent an attacker from changing the Persistent Storage settings</p></li></ul></li><li><p>New feature: Detection of partitioning errors</p><ul><li><p>Sometimes, the partitions on a Tails USB stick get corrupted. This creates errors with the Persistent Storage or during upgrades.</p></li><li><p>Tails now warns about such partitioning errors earlier.</p></li></ul></li><li><p>Changes and updates</p><ul><li><p>Remove support for hardware wallets in Electrum. Trezor wallets stopped working in Debian 12 (Bookworm), and so in Tails 6.0 or later.</p></li><li><p>Add a link to the Tor Connection assistant from the menu of the Tor status icon on the desktop.</p></li></ul></li></ul></li><li><p>01:09:52 <a href="https://m17project.org/">Module_17</a>, M17 modem board for 9600-baud capable radios [<a href="https://github.com/M17-Project/Module_17/">Github</a>]</p></li><li><p>Reticulum MeshChat <a href="https://github.com/liamcottle/reticulum-meshchat/releases/tag/v1.19.0">v1.19.0</a></p><ul><li><p>Add setting to enable and disable transport mode</p></li><li><p>Add ability to cancel sending messages</p></li><li><p>Add button to open an LXMF address when no conversations are open</p></li><li><p>Add button to open a nomadnet url without having to click a random node first</p></li><li><p>Telemetry requests from Sideband no longer show up as empty messages</p></li></ul></li><li><p>SideBand <a href="https://github.com/markqvist/Sideband/releases/tag/1.3.0">v1.3.0</a></p><ul><li><p>Increased performance by updating included RNS and LXMF to latest versions</p></li><li><p>Add ability to cancel outgoing messages</p></li><li><p>Add ability to render messages formatted with markdown</p></li><li><p>Add ability to compose messages with markdown</p></li><li><p>Add ability to query peer telemetry from the map by right-clicking on the peer</p></li><li><p>Add auto-switching of message mode on attachment</p></li><li><p>Add indication if receiver rejects message</p></li><li><p>Add support for SX1280 bandwidth options to RNode configuration</p></li><li><p>Add ability to launch RNode flasher directly from utilities</p></li></ul></li><li><p>NomadNet <a href="https://github.com/markqvist/NomadNet/releases/tag/0.5.7">v0.5.7</a></p><ul><li><p>Add sync transfer rate to PN list display</p></li><li><p>Update urwid API calls to handle deprecations</p></li></ul></li><li><p>Mullvad VPN <a href="https://mullvad.net/en/blog/split-tunneling-on-macos">v2024.4</a></p><ul><li><p>introduces split tunneling in version for macOS, allowing users to exclude specific apps from the VPN</p></li><li><p>Limitations include the inability to exclude Safari and other WebKit-based apps, performance overhead due to additional tunneling, and availability restricted to macOS 13 and above</p></li></ul></li></ul><h4><strong>Project spotlight</strong></h4><ul><li><p><a href="https://peergos.org/">Peergos</a>: A p2p, secure file storage, social network and application protocol [<a href="https://github.com/peergos/peergos">Github</a>]</p><ul><li><p>Peergos is an open-source platform that can be self-hosted and enables secure, peer-to-peer file storage and sharing without central nodes.</p></li></ul></li><li><p><a href="https://privacyspreadsheet.com/messaging-apps">PrivacySpreadsheet</a>: A privacy evaluation of messaging apps [<a href="https://github.com/du82/privacyspreadsheet.com">Github</a>]</p></li><li><p>cjdns: An encrypted IPv6 network using public-key cryptography for address allocation and a distributed hash table for routing [<a href="https://github.com/cjdelisle/cjdns">Github</a>]</p><ul><li><p>cjdns leverages a distributed hash table for routing, which enables scalable, near-zero-configuration networking.</p></li></ul></li><li><p><a href="https://botan.randombit.net/">Botan</a>: An open-source cryptography library for C++ with extensive features including TLS, X.509, modern and post-quantum cryptography, plus TPM and RNG support [<a href="https://github.com/randombit/botan">Github</a>]</p><ul><li><p>It provides APIs in C++, C, and Python, alongside other language bindings, and includes a command-line interface.</p></li></ul></li><li><p><a href="https://sticktock.com/">Sticktock</a>: Share TikToks Safely. No Ads, No Spyware, No Phone App. [<a href="https://github.com/PrivacySafe/sticktock">Github</a>]</p><ul><li><p>StickTock is an open-source tool allowing users to watch TikTok videos privately, without ads or tracking. [<a href="http://b7vypdv52igjfg7vwhlofny45koaa4ltletx67ranlwfotiiqwza2eyd.onion/">Onion</a>]</p></li></ul></li></ul><h3><strong>Lightning + L2+</strong></h3><h4><strong>Project spotlight</strong></h4><ul><li><p><a href="https://valet.finance/">Valet</a>: A Bitcoin + Lightning wallet for Android [<a href="https://github.com/standardsats/valet">Github</a>]</p><ul><li><p>Valet is a non-custodial Lightning wallet designed to offer stable purchasing power for users through hosted channels.</p></li><li><p>Developed as a fork of the <a href="https://github.com/Tactical-Advantage-Trading/wallet">Simple Bitcoin Wallet</a>, features include coin control, batching, and hardware wallet integration.</p></li></ul></li><li><p><a href="https://www.eggstr.com/">Eggstr</a>: A platform that enables users to deploy and manage Bitcoin and Lightning applications with their own domain</p><ul><li><p>It offers a variety of self-hosted apps, including LNBits, Alby Hub, Strfry (a Nostr relay), Nostr Address, and Blossom Server.</p></li></ul></li><li><p><a href="https://rizful.com/">Rizful</a>: A service offering instant disposable Lightning nodes</p><ul><li><p>Rizful offers cloud-hosted, disposable Lightning nodes designed for fast, high-uptime performance, with instant inbound capacity.</p></li></ul></li><li><p>Zeus2Koinly: A script to convert Zeus Wallet&#8217;s export format into Koinly&#8217;s import format [<a href="https://github.com/makeasnek/Zeus2Koinly/">Github</a>]</p></li><li><p>pWallet: A lightweight UI for Phoenix Server that can be set up and run entirely using Docker [<a href="https://github.com/hodladi/pwallet">Github</a>]</p></li><li><p><a href="https://lnbeats.com/">LNBeats</a>: A value-for-value music streaming app, using the Lightning Network</p></li></ul><h4><strong>Software Releases &amp; Project Updates</strong></h4><ul><li><p>Rust Lightning <a href="https://github.com/lightningdevkit/rust-lightning/releases/tag/v0.1">v0.1</a> - &#8220;Human Readable Version Numbers&#8221;</p><ul><li><p>API Updates</p><ul><li><p>The <code>lightning-liquidity</code> crate has been moved into the <code>rust-lightning</code> git tree, enabling support for both sides of the LSPS channel open negotiation protocols</p></li><li><p>This release includes support for BIP 353 Human Readable Names resolution</p></li><li><p>On-chain state resolution now more aggressively batches claims into single transactions, reducing on-chain fee costs when resolving multiple HTLCs for a single channel force-closure</p></li><li><p>And many more</p></li></ul></li><li><p>Performance Improvements</p><ul><li><p>LDK now verifies <code>channel_update</code> gossip messages without holding a lock, allowing additional parallelism during gossip sync</p></li><li><p>LDK now checks if it already has certain gossip messages before verifying the message signatures, reducing CPU usage during gossip sync after the first startup</p></li></ul></li><li><p>Node Compatibility: LDK now handles fields in the experimental range of BOLT 12 messages</p></li><li><p>Security: v0.1 fixes a funds-theft vulnerability when paying BOLT 12 offers as well as a funds-lockup denial-of-service issue for anchor channels.</p></li></ul></li><li><p>Alby</p><ul><li><p>Hub <a href="https://github.com/getAlby/hub/releases/tag/v1.13.0">v1.13.0</a> - Eva Galperin</p><ul><li><p>In this release we add some cool new apps to the app store, an auto-unlock feature for self-hosted hubs, extra information about pending closed channels, and some security improvements for isolated apps and budgeting.</p><ul><li><p>Auto unlock for self-hosted hubs</p></li><li><p>ZapPlanner custom app</p></li><li><p>Add simple boost widget app</p></li><li><p>Add Clams to Hub&#8217;s Store</p></li><li><p>Include funding transaction in pending closing channel message</p></li><li><p>Add balance details for pending channel closures</p></li></ul></li></ul></li><li><p>JS SDK <a href="https://github.com/getAlby/js-sdk/releases/tag/v3.9.0">v3.9.0</a></p><ul><li><p>Add nip 44 and versioning support</p></li></ul></li></ul></li><li><p>Mostro <a href="https://github.com/MostroP2P/mostro/releases/tag/v0.13.0">v0.13.0</a></p><ul><li><p>This version dramatically improves privacy for users with <a href="https://mostro.network/protocol/key_management.html">keys management</a> implementation: a way clients rotate keys for every trade adding another privacy layer to gift wrap previous implementation.</p></li></ul></li><li><p>BitBanana <a href="https://github.com/michaelWuensch/BitBanana/releases/tag/v0.8.9">v0.8.9</a></p><ul><li><p>Add Payment Path view (LND)</p></li><li><p>Implement &#8220;Enable Offer&#8221; command for Core Lightning &gt;=24.11</p></li><li><p>Allow offers without description (Core Lightning)</p></li><li><p>Add description and payer note for paid bolt12 offers in transaction history</p></li><li><p>Increase VPN start timeout to improve UX on slow internet connection</p></li></ul></li><li><p>Nutshell <a href="https://github.com/cashubtc/nutshell/releases/tag/0.16.4">v0.16.4</a></p><ul><li><p>This release brings two new protocol spec updates to nutshell, NUT-19 and NUT-20. It also includes a new HTTP compression middleware.</p><ul><li><p>Add MPP methods key to info endpoint</p></li><li><p>Add HTTP compression middleware</p></li><li><p>NUT-19: Cached Requests and Responses</p></li><li><p>NUT-20 (signatures on quotes) for mint and wallet side</p></li><li><p>Add period at the end of the phrase</p></li><li><p>Add NUT-19 example for caching responses</p></li></ul></li></ul></li></ul><h3><strong>Nostr</strong></h3><h4><strong>Project spotlight</strong></h4><ul><li><p><a href="https://start.njump.me/">Nstart</a>: A straight-forward nostr onboarding wizard [<a href="https://github.com/dtonon/nstart">Github</a>]</p><ul><li><p>Nstart is a user-friendly onboarding tool for Nostr, offering key features like local backups and customizable contact suggestions.</p></li><li><p>It incorporates a multi-signer bunker to protect Nsec keys, allowing for easy recovery and access even in case of failure or theft.</p></li></ul></li><li><p><a href="https://www.kanbanstr.com/">Kanbanstr</a>: A new nostr client for task management [<a href="https://github.com/vivganes/kanbanstr">Github</a>]</p><ul><li><p>Users can log in via nsec, npub, or NIP-07, create boards with customizable columns, and organize tasks using cards.</p></li><li><p>Current features include markdown support in cards, automatic mapping of cards to columns by status, and assigning tasks with &#8220;zap&#8221; tags to facilitate payment. Pending updates include programmatic functionalities and enabling direct zaps for task payments.</p></li></ul></li><li><p>Noshtastic: A geo-specific virtual Nostr relay for Meshtastic [<a href="https://github.com/ksedgwic/noshtastic">Github</a>]</p><ul><li><p>Noshtastic operates as a decentralized Nostr relay independent of the internet, using Meshtastic devices for communication.</p></li><li><p>It employs negentropy-based synchronization and region-specific geohash tagging to distribute messages locally without internet connectivity.</p></li></ul></li><li><p><a href="https://next-alexandria.gitcitadel.eu/">Alexandria</a>: A Nostr knowledge base and long-form article reader [<a href="https://github.com/ShadowySupercode/gc-alexandria">Github</a>]</p><ul><li><p>Alexandria is designed to display modular, long-form articles in a clean, distraction-free interface for focused reading.</p></li><li><p>It supports Nostr events, allowing users to interact with organized content in a structured format.</p></li></ul></li><li><p><a href="https://nosotros.app/">Nosotros</a>: A nostr web client optimized for both mobile and desktop usability [<a href="https://github.com/cesardeazevedo/nosotros">Github</a>]</p><ul><li><p>Built using TypeScript, it includes testing support and a progressive web app design for smooth functionality.</p></li></ul></li><li><p>Bostr: A nostr relay bouncer [<a href="https://codeberg.org/Yonle/bostr">Code repository</a>]</p><ul><li><p>Bostr is a minimalist HTTP server built with Go, designed to serve static files efficiently. It also acts as a nostr relay aggregator proxy, consolidating data from multiple relays.</p></li><li><p><a href="https://codeberg.org/Yonle/bostr2">Bostr2</a>, is a bostr next generation project</p></li></ul></li><li><p>Tides: A Nostr messenger browser extension for Chrome &amp; Brave [<a href="https://github.com/arbadacarbaYK/Tides">Github</a>]</p><ul><li><p>Tides is a browser extension that provides secure, private messaging using the Nostr protocol. It supports real-time encryption, contact management, and media sharing.</p></li><li><p>Users can log in via NIP-07 extension, Chrome storage, or manual key input</p></li></ul></li><li><p>CLN NWC: Nostr Wallet Connect plugin for CLN [<a href="https://github.com/gudnuf/cln_nwc">Github</a>]</p><ul><li><p>Users can configure or manually start the plugin, create connections with budgets, list active connections, and revoke them as needed.</p></li><li><p>Payment requests are routed via Nostr relays.</p></li></ul></li><li><p><a href="https://emojito.meme/">Emojito</a>: A platform based on the nostr application framework <a href="https://github.com/verbiricha/ngine">ngine</a> to create personalized emoji sets</p><ul><li><p>Nostr interactions: users can use personalized reactions, provided their client supports NIP-30</p></li></ul></li><li><p><a href="https://huggingface.co/some1nostr/Nostr-Llama-3.1-8B">Nostr Llama 3.1 8B</a>: A model built on Nostr notes from around 7,000 users</p><ul><li><p>Fine-tuned using multiple datasets, including Evol-Instruct-Code and CodeFeedback-Filtered-Instruction.</p></li><li><p>With 8.03B parameters, this model is based on Meta&#8217;s Llama 3.1</p></li></ul></li><li><p><a href="https://granary.io/">Granary</a>: A social web translator that fetches and converts data between platforms, formats, and protocols, including Nostr [<a href="https://github.com/snarfed/granary">Github</a>]</p><ul><li><p>It supports social networks, HTML, and JSON with microformats2, ActivityStreams 1 and 2 (including ActivityPub), Atom, RSS, and JSON Feed. It works as a Python library and REST API, supporting read and write operations for data interoperability.</p></li></ul></li></ul><h4><strong>Software Releases &amp; Project Updates</strong></h4><ul><li><p>Olas</p><ul><li><p><a href="https://github.com/pablof7z/olas/releases/tag/0.1.9">v0.1.9</a></p><ul><li><p>Web cleanup</p></li></ul></li><li><p><a href="https://njump.me/nevent1qvzqqqqqqypzp75cf0tahv5z7plpdeaws7ex52nmnwgtwfr2g3m37r844evqrr6jqyxhwumn8ghj7e3h0ghxjme0qyd8wumn8ghj7urewfsk66ty9enxjct5dfskvtnrdakj7qghwaehxw309aex2mrp0yh8qunfd4skctnwv46z7qpqxymquwrjnk0ekr9ztgpgk04cj9q3n5qy8pw3t5z3dhhe5r89kseqr83qjp">v0.1.8</a></p><ul><li><p>Reaction, comments, zaps, etc now showing up on the content view</p></li></ul></li><li><p><a href="https://github.com/pablof7z/olas/releases/tag/0.1.7">v0.1.7</a></p><ul><li><p>Add color style so text shows in dark mode</p></li></ul></li></ul></li><li><p>Notedeck <a href="https://njump.me/naddr1qvzqqqr4gupzq3qcntalp5jhzm0x4aunm3suzylv74skvjqezt8pfss99kmz7wtvqqpzutsp6rexg">Latest codebase changes</a></p><ul><li><p>Add <code>t</code> tags for hashtags</p></li><li><p>Use HashSet, lowercase, and add emoji tests</p></li><li><p>Add test and format</p></li><li><p>Adjust context menu/grip circle sizes</p></li><li><p>Extract timing from AppSizeHandler to TimedSerializer</p></li><li><p>Introduce ZoomHandler</p></li></ul></li><li><p>Amethyst</p><ul><li><p><a href="https://github.com/vitorpamplona/amethyst/releases/tag/v0.94.3">v0.94.3</a></p><ul><li><p>Add iMeta tags to GIF urls to optimize GIF previews</p></li><li><p>Maintain note reaction visibility when scrolling</p></li></ul></li><li><p><a href="https://github.com/vitorpamplona/amethyst/releases/tag/v0.94.1">v0.94.1</a> - GIFs and Custom Emoji inputs</p><ul><li><p>Add a <code>:</code> command to link custom emojis on new posts and chats. Similar to the @ for user search, just start typing to find your custom emojis.</p></li><li><p>Create your GIF and rection libraries on emojito.meme</p></li></ul></li><li><p><a href="https://github.com/vitorpamplona/amethyst/releases/tag/v0.94.0">v0.94.0</a> - Encrypted Media on DMs</p><ul><li><p>Adds support for encrypted media uploads on NIP-17 DMs</p></li><li><p>Integrates with Pokey&#8217;s Broadcast receiver</p></li><li><p>Shows NIP-22 replies in the replies tab of the user profile</p></li><li><p>New upload screen for chats</p></li><li><p>Add support for multiple media uploads at the same time.</p></li><li><p>Add support to display PictureEvents with multiple images at the same time</p></li><li><p>Add QR code private key export dialog</p></li><li><p>Add new picture and video events to the user profile gallery</p></li><li><p>Add basic support for RelationshipStatus to Quartz</p></li><li><p>And much more</p></li></ul></li></ul></li><li><p>YakiHonne</p><ul><li><p>Web - <a href="https://njump.me/nevent1qqsp0zn70fpfx8hjglr78nvau84jzn7yfgcqlwls33lpltpqvch6zeczyqsfsmac8em4m9k33r99e803pnndvylqadl9w69q7zcjkd7d4ssmxqcyqqqqqqgk6pw8g">v4.2.3</a> - Add support for uploading multiple images or videos in notes, comments, and messages - Refine the search mechanism for better accuracy and performance</p><ul><li><p><a href="https://njump.me/nevent1qgszpxr0hql8whvk6xyv5hya7yxwd4snur4hu4mg5rctz2ehekkzrvcqypdcwtq7kcvt9uguu4gztlnl4e67wkrrfkqe7dk7hxunnmlt5pqwwz4xk4j">v4.2.2</a></p><ul><li><p>Add language support for Spanish, Portuguese, Thai, Japanese, and Italian</p></li><li><p>Enable support for processing invoice payments in notes</p></li></ul></li></ul></li><li><p>Mobile <a href="https://njump.me/nevent1qgszpxr0hql8whvk6xyv5hya7yxwd4snur4hu4mg5rctz2ehekkzrvcqypdcwtq7kcvt9uguu4gztlnl4e67wkrrfkqe7dk7hxunnmlt5pqwwz4xk4j">v1.6.1</a></p><ul><li><p>Add language support for Spanish, Portuguese, Thai, Japanese, and Italian</p></li><li><p>Add ability to multi-select and upload media</p></li><li><p>Introduce enhanced video player</p></li><li><p>Add media through your camera into notes</p></li><li><p>Enable support for processing invoice payments in notes</p></li></ul></li></ul></li><li><p>Flotilla</p><ul><li><p><a href="https://github.com/coracle-social/flotilla/releases/tag/0.2.3">v0.2.3</a></p><ul><li><p>Add NIP 56 reports for messages and threads</p></li><li><p>Add ToS and privacy policy</p></li><li><p>Add avatar fallback icons</p></li><li><p>Add mark as read to chats</p></li><li><p>Add send button to chat compose</p></li><li><p>Accommodate onion URLs</p></li><li><p>Improve loading and notifications</p></li></ul></li><li><p><a href="https://github.com/coracle-social/flotilla/releases/tag/0.2.1">v0.2.1</a></p><ul><li><p>Improve performance, as well as scrolling and loading</p></li><li><p>Improve NIP 29 compatibility</p></li><li><p>Refine notifications</p></li><li><p>Add join space CTA</p></li></ul></li></ul></li><li><p>Njump.me <a href="https://njump.me/nevent1qvzqqqqqqypzqwlsccluhy6xxsr6l9a9uhhxf75g85g8a709tprjcn4e42h053vaqyd8wumn8ghj7urewfsk66ty9enxjct5dfskvtnrdakj7qgmwaehxw309aex2mrp0yh8wetnw3jhymnzw33jucm0d5hszymhwden5te0wahhgtn4w3ux7tn0dejj7qguwaehxw309a382cmtv46zucm0wfskxmr99eek7cmfv9kz7qguwaehxw309a3ksunfwd68q6tvdshxummnw3erztnrdakj7qpqqqqxj2qrjjhngnjz9zak9retcj755y8pylkl7ul868653zfqlveqteck93">Latest codebase changes</a></p><ul><li><p>Add support for kind:20 photos</p></li></ul></li><li><p>0xChat App</p><ul><li><p><a href="https://github.com/0xchat-app/0xchat-app-main/releases/tag/v1.4.6-release">v1.4.6</a></p><ul><li><p>Add reactions and mention notification button to chats</p></li><li><p>Long press the &#8220;Like&#8221; button on moments to select an emoji</p></li></ul></li><li><p><a href="https://github.com/0xchat-app/0xchat-app-main/releases/tag/v1.4.5-release">v1.4.5</a></p><ul><li><p>Add support for NIP46 login</p></li><li><p>Adapt UI for tablet devices</p></li><li><p>Introduce connection ping status</p></li><li><p>Implement search functionality for Moments</p></li><li><p>Set default relays for first login</p></li><li><p>Add default reaction emojis</p></li></ul></li></ul></li><li><p>Citrine <a href="https://github.com/greenart7c3/Citrine/releases/tag/v0.7.0">v0.7.0</a></p><ul><li><p>Update quartz dependency</p></li><li><p>Check if events are deleted</p></li><li><p>Recover service after crash</p></li><li><p>Add back button in the events screen</p></li></ul></li><li><p>nos.social <a href="https://github.com/planetary-social/nos/releases/tag/v1.1-296">v1.1</a></p><ul><li><p>Nos now publishes the hashtags it finds in your note when you post</p></li><li><p>Update the default relays that are added when you create an account</p></li><li><p>Add feed picker view (UI only)</p></li><li><p>Add feed source customizer drop-down view</p></li><li><p>Make feed source selector work</p></li><li><p>Add empty state for lists/relays drop-down</p></li><li><p>Add support for decrypting private tags in kind 30000 lists</p></li><li><p>Add pop-up tip for feed customization</p></li><li><p>Add remembering which feed source is selected</p></li></ul></li><li><p>Nostur <a href="https://github.com/nostur-com/nostur-ios-public/releases/tag/346">v1.17.0</a></p><ul><li><p>Sync already seen/read across multiple devices</p></li><li><p>New &#128514;-feed</p></li><li><p>Support new Olas/picture format (viewing)</p></li><li><p>Support Frost/multi-sig login</p></li><li><p>Support for .heic image format in posts</p></li><li><p>Show extra autopilot relays used on Post Preview (default off)</p></li><li><p>Login with nip05 (read-only)</p></li><li><p>Undelete button for deleted posts</p></li></ul></li><li><p>Nostrmo <a href="https://github.com/haorendashu/nostrmo/releases/tag/2.9.5">v2.9.5</a></p><ul><li><p>Add Pc tray support</p></li><li><p>Add Pc notice support</p></li><li><p>Add support for some linux packages</p></li><li><p>Relay dtail page can jump to jumble.social</p></li><li><p>User can config their Client tag</p></li><li><p>Add note tail support</p></li></ul></li><li><p>Nostrss <a href="https://github.com/Asone/nostrss/releases/tag/v1.1.0">v1.1.0</a></p><ul><li><p>Optional cache: A default size can still be set with env values, however if no env value is provided and no cache size is defined for a feed, no limit will be set.</p></li><li><p>Dependencies updates: Note that this new version uses a version on tokio-cron-scheduler which changes the scheduler pattern to be used.</p></li></ul></li><li><p>Zapstore</p><ul><li><p><a href="https://github.com/zapstore/zapstore/releases/tag/0.2.2">v0.2.2</a></p><ul><li><p>Replace buggy WoT API-based service with Vertex DVM-based service (alpha)</p></li></ul></li><li><p><a href="https://github.com/zapstore/zapstore/releases/tag/0.2.0">v0.2.0</a></p><ul><li><p>Sign in with NIP-55 (Amber)</p></li><li><p>Ability to zap via NWC and view zap receipts</p></li></ul></li></ul></li><li><p>Voyage <a href="https://github.com/dluvian/voyage/releases/tag/v0.17.2">v0.17.2</a></p><ul><li><p>Force nip22 usage when reply has 6 or less characters</p></li><li><p>Use v2 replies by default for new installs</p></li><li><p>Don&#8217;t set grandparent p-tags</p></li></ul></li><li><p>Strfry <a href="https://github.com/hoytech/strfry/releases/tag/1.0.4">v1.0.4</a></p><ul><li><p>New config: maxReqFilterSize. This allows REQs with many more filters</p></li><li><p>Default <code>maxReqFilterSize</code> was increased to 200</p></li><li><p>Reduce log spam by not dumping full invalid events</p></li><li><p>In sync and stream commands, provide the connected URL to write policy plugins</p></li></ul></li><li><p>Nostrss <a href="https://github.com/Asone/nostrss/releases/tag/v1.1.0">v1.1.0</a></p><ul><li><p>Dependencies updates: Note that this new version uses a version on tokio-cron-scheduler which changes the scheduler pattern to be used.</p></li><li><p>Optional cache: The feed cache is now optional. A default size can still be set with env values, however if no env value is provided and no cache size is defined for a feed, no limit will be set.</p></li></ul></li><li><p>Amber</p><ul><li><p><a href="https://github.com/greenart7c3/Amber/releases/tag/v3.1.8">v3.1.8</a></p><ul><li><p>Add button to clear cached data in settings</p></li><li><p>Fix multiple bunker requests not clearing when accepting or rejecting</p></li></ul></li><li><p><a href="https://github.com/greenart7c3/Amber/releases/tag/v3.1.0">v3.1.0</a></p><ul><li><p>Move bunker and nostrconnect to its own files</p></li><li><p>Show relays after the app is connected</p></li></ul></li></ul></li><li><p>Algo Relay <a href="https://github.com/bitvora/algo-relay/releases/tag/v0.1.3">v0.1.3</a></p><ul><li><p>Uselessly preallocate some slices</p></li><li><p>Dev refresh feeds</p></li><li><p>Saving the Social Graph</p></li><li><p>Purge Data Functionality</p></li></ul></li><li><p>Wot Relay <a href="https://github.com/bitvora/wot-relay/releases/tag/v0.1.16">v0.1.16</a></p><ul><li><p>Ignore follow list for people who follow spammers</p></li></ul></li><li><p>Feeder <a href="https://github.com/spacecowboy/Feeder/releases/tag/2.8.0">v2.8.0</a></p><ul><li><p>Add native Nostr NIP-23 feed support</p></li></ul></li></ul><h3><strong>Boosts</strong></h3><ul><li><p>01:12:29 Thanks to everyone who streamed sats, and shoutout to our top boosters:</p><ul><li><p>[&#127942; TOP BOOSTER] @Anonymous (3,333 sats) &#8220;I don&#8217;t know who this Rob guy is but congrats to him on the launch of his new fishing company!&#8221;</p></li><li><p>@manbyt (2,100 sats) &#8220;Itm!&#8221;</p></li><li><p>@agichoote (1,000 sats) &#8220;I see the new ep out and I don&#8217;t even need to see what else is out there&#8221;</p></li><li><p>@btconboard (300 sats) &#8220;The people using miniscript are people too despite their extra extra autism, NVK&#8221;</p></li></ul></li></ul><h3><strong>Tech Tip of the Day</strong></h3><ul><li><p><a href="https://itoa.hex.dance/">ITOA</a>: A web-based tool that converts images into ASCII art, with support for both monochrome and color output [<a href="https://github.com/solst-ice/itoa">Github</a>]</p></li></ul><h3><strong>Bitcoin Optech Newsletter</strong></h3><ul><li><p>Highlights from recent Bitcoin Optech Newsletters</p><ul><li><p><a href="https://bitcoinops.org/en/newsletters/2025/01/17/">337</a></p><ul><li><p>Continued <a href="https://delvingbitcoin.org/t/ecash-tides-using-cashu-and-stratum-v2/870">discussion</a> about rewarding pool miners with tradeable ecash shares</p></li><li><p>Offchain DLCs: developer conduition <a href="https://mailmanlists.org/pipermail/dlc-dev/2025-January/000186.html">posted</a> to the DLC-dev mailing list about a contract protocol that allows an offchain spend of the funding transaction signed by both parties to create multiple DLCs</p></li></ul></li><li><p><a href="https://bitcoinops.org/en/newsletters/2025/01/10/">336</a> - Investigating mining pool behavior before fixing a Bitcoin Core bug: Abubakar Sadiq Ismail <a href="https://delvingbitcoin.org/t/analyzing-mining-pool-behavior-to-address-bitcoin-cores-double-coinbase-reservation-issue/1351">posted</a> to Delving Bitcoin about a bug discovered in 2021 by Antoine Riard that results in nodes reserving 2,000 vbytes in block templates for coinbase transactions rather than the intended 1,000 vbytes</p><ul><li><p>Contract-level relative timelocks: Gregory Sanders <a href="https://delvingbitcoin.org/t/contract-level-relative-timelocks-or-lets-talk-about-ancestry-proofs-and-singletons/1353">posted</a> to Delving Bitcoin about finding a solution for a complication he discovered about a year ago (see Newsletter #284) when creating a proof-of-concept implementation of LN-Symmetry</p></li><li><p>Multiparty LN-Symmetry variant with penalties for limiting published updates: Daniel Roberts <a href="https://delvingbitcoin.org/t/broken-multi-party-eltoo-with-bounded-settlement/1364">posted</a> to Delving Bitcoin about preventing a malicious channel counterparty from being able to delay channel settlement by deliberately broadcasting old states at a higher feerate than an honest counterparty is paying for confirmation of the final state</p></li></ul></li><li><p><a href="https://bitcoinops.org/en/newsletters/2025/01/03/">335</a></p><ul><li><p>News:</p><ul><li><p>Deanonymization attacks against centralized coinjoin: Yuval Kogman <a href="https://groups.google.com/g/bitcoindev/c/CbfbEGozG7c/m/w2B-RRdUCQAJ">posted</a> to the Bitcoin-Dev mailing list details about several privacy-reducing vulnerabilities in the centralized coinjoin protocols used by current versions of the Wasabi and Ginger wallets, plus past versions of the Samourai, Sparrow, and Trezor Suite software wallets</p></li><li><p>Updated ChillDKG draft: Tim Ruffing and Jonas Nick <a href="https://groups.google.com/g/bitcoindev/c/HE3HSnGTpoQ/m/Y2VhaMCrCAAJ">posted</a> to the Bitcoin-Dev mailing list a link to the current draft BIP for ChillDKG, which describes a distributed key generation protocol compatible with FROST scriptless threshold signatures for Bitcoin</p></li></ul></li><li><p>Changing consensus:</p><ul><li><p>CTV enhancement opcodes</p></li><li><p>Adjusting difficulty beyond 256 bits</p></li><li><p>Transitory soft forks for cleanup soft forks</p></li><li><p>Quantum computer upgrade path</p></li><li><p>Consensus cleanup timewarp grace period</p></li></ul></li></ul></li></ul></li></ul><h3><strong>News &amp; Noteworthy</strong></h3><h4><strong>Bitcoin</strong></h4><ul><li><p><a href="https://www.xellox.io/clavis/">Clavis</a>: A new hardware wallet by <a href="https://x.com/xelloxwallet">Xellox Wallet</a></p><ul><li><p>Clavis is designed for online and offline bitcoin storage. It features a capacitive fingerprint sensor, passcode protection, and is IP68 rated.</p></li></ul></li><li><p>Judge dismisses man&#8217;s bid to recover 8,000 bitcoin from landfill [<a href="https://arstechnica.com/tech-policy/2025/01/judge-ends-mans-11-year-quest-to-dig-up-landfill-and-recover-765m-in-bitcoin/">Ars Technica</a>]</p><ul><li><p>James Howells&#8217; 11-year effort to retrieve a hard drive containing the private keys valued at approximately $765 million, ends as High Court Judge Keyser KC rules against him.</p></li><li><p>The judge cites environmental concerns and legal ownership, stating that excavating the landfill could release harmful substances.</p></li></ul></li></ul><h4><strong>Lightning</strong></h4><ul><li><p>Zeus increases its LSP maximum channel lease duration from 6 to 12 months [<a href="https://x.com/ZeusLN/status/1881197435172835699">Announcement</a>]</p></li></ul><h4><strong>Business &amp; Finance</strong></h4><ul><li><p>Block Inc fined $80 million for inadequate anti-money laundering controls in Cash App [<a href="https://www.reuters.com/technology/state-regulators-fine-block-inc-80-million-anti-money-laundering-violations-2025-01-15/">Reuters</a>]</p></li><li><p>BitMEX is fined an additional $100 million for Bank Secrecy Act violations between 2015 and 2020 [<a href="https://www.justice.gov/usao-sdny/pr/global-cryptocurrency-exchange-bitmex-fined-100-million-violating-bank-secrecy-act">DOJ Press release</a>]</p><ul><li><p>Prosecutors sought a $417 million fine, arguing BitMEX hadn&#8217;t fully accepted responsibility, noting the company earned approximately $1.3 billion while ignoring U.S. regulations over five years.</p></li></ul></li><li><p>Coinbase launches <a href="https://docs.cdp.coinbase.com/reputation/docs/welcome">Onchain Reputation API</a> and <a href="https://x.com/coinbase/status/1879902780564951530">Bitcoin-backed loans</a></p><ul><li><p>Coinbase introduces a public beta of the Onchain Reputation API, offering a reputation score for wallet addresses, ENS, and Basename IDs, ranging from -100 to +1000.</p></li><li><p>The company also announced Bitcoin-backed loans using its Base protocol, clarifying that the loans aren&#8217;t backed by Bitcoin nor based on its blockchain.</p></li></ul></li><li><p>Unchained now supports passkey support for enhanced account security [<a href="https://updates.unchained.com/en/add-passkeys-to-your-account-for-enhanced-security">Blog post</a>]</p></li><li><p>River introduces ForceField, an extra layer of protection to secure Bitcoin against theft and scams [<a href="https://blog.river.com/forcefield/">Announcement</a>]</p><ul><li><p>It features a 5-day delay on withdrawals, offering users time to respond to unauthorized access attempts.</p></li></ul></li><li><p>Tether has filed a lawsuit against Swan Bitcoin in the High Court of England and Wales, alleging major violations of their commercial agreements related to their 2022 Bitcoin mining joint venture, 2040 Energy [<a href="https://archive.ph/UtjUj">Blockspace</a>]</p><ul><li><p>In September 2024, Swan sued former employees, accusing them of stealing proprietary information to establish Proton Management, which now oversees Bitcoin mining assets with Tether.</p></li></ul></li><li><p>Bitcoin miner MARA deploys 16% of its BTC holdings (7,377 BTC, worth about $730 million) in short-term loans to third parties, aiming to generate a &#8220;modest single-digit yield&#8221; from these loans [<a href="https://theminermag.com/news/2025-01-05/mara-lend-bitcoin-btc/">The Miner Mag</a>]</p><ul><li><p>MARA surpassed its December hash rate target of 50 EH/s and increased its total BTC holdings to 44,893 BTC, including the loans.</p></li></ul></li><li><p>Canaan launches Avalon Mini 3 (37.5 TH/s) and Nano 3S (6 TH/s) Bitcoin miners, respectively $899 and $249 [<a href="https://www.canaan.io/news/canaan-introduces-revolutionary-bitcoin-mining-heaters-for-home-and-personal-use-in-ces-2025-1722">Blog post</a>]</p><ul><li><p>The Avalon Mini 3 doubles as a home heater, offering a sustainable, multi-purpose solution for home mining.</p></li></ul></li></ul><h4><strong>Tradfi</strong></h4><ul><li><p>BlackRock introduces the iShares Bitcoin ETF in Canada, trading under the ticker IBIT [<a href="https://www.businesswire.com/news/home/20250113540226/en/BlackRock-Launches-New-Bitcoin-ETF-on-Cboe-Canada">Business Wire</a>]</p></li></ul><h4><strong>Education</strong></h4><ul><li><p>Applications for the Sovereign Engineering Cohort 4 (SEC-04) are now open [<a href="https://sovereignengineering.io/madeira.html">Registration</a>]</p><ul><li><p>SEC-04, titled &#8216;Building it Right&#8217;, will take place from March 3 to April 11, 2025.</p></li></ul></li><li><p>The <a href="https://www.bitcoinstudentsnetwork.org/">Bitcoin Students Network</a> launches its Layer Zero program to empower students worldwide in building Bitcoin&#8217;s social layer and community [<a href="https://www.forbes.com/sites/digital-assets/2025/01/09/the-bitcoin-students-network-launch-layer-zero-to-empower-global-youth/">Forbes</a>]</p><ul><li><p>The program offers hands-on experience by connecting students with Bitcoin entrepreneurs.</p></li></ul></li></ul><h4><strong>Funding</strong></h4><ul><li><p>OpenSats <a href="https://opensats.org/blog/more-for-core">grants</a> additional funding to three dedicated Bitcoin Core contributors: <a href="https://github.com/l0rinc">@L0rinc</a>, <a href="https://github.com/kevkevinpal">@kevkevinpal</a>, and <a href="http://github.com/danielabrozzoni">@danielabrozzoni</a></p></li><li><p>BDK <a href="https://njump.me/nevent1qqsgd274h8c4gvygrvyyem367xl8t96uanczpxqkl5tn9stvnh84e5gpzdmhxue69uhhwmm59e6hg7r09ehkuef0qgsgkmgkmv63djkxmwvdlyaxx0xtsytvkyyg5fwzmp48pwd30f3jtxsrqsqqqqqpgc5t6m">announces</a> the pseudonymous John Galt as its newest grantee:</p><ul><li><p>John will lead the efforts in partnerships, membership program and onboarding new members.</p></li></ul></li><li><p>Vinteum <a href="https://medium.com/vinteum-org/announcing-our-fourth-grant-plebhash-and-stratum-v2-fec0abbb1840">awards</a> its fourth grant to plebhash for contributions to Stratum V2 and decentralized Bitcoin mining</p></li><li><p>Finney Freedom Prize honors (blocks 210,000-420,000) Bitcoin pioneers Pieter Wuille and Gregory Maxwell for their contributions to Bitcoin usability, scalability, and privacy. [<a href="https://hrf.org/program/financial-freedom/finney-prize/">Announcement</a>]</p></li><li><p>The BTC Pay Server Foundation receives a $25,000 grant in bitcoin from Unbank, a cash focused Bitcoin exchange [<a href="https://bitcoinmagazine.com/business/btcpay-server-foundation-receives-25000-grant-in-bitcoin-from-unbank">Bitcoin Magazine</a>]</p></li><li><p>Alpen Labs <a href="https://www.alpenlabs.io/blog/strategic-round">announces</a> raising $8.5M in a strategic round to support the development of Strata, a Bitcoin ZK rollup aimed at improving the Bitcoin ecosystem with self-custody, privacy, and interoperability.</p></li><li><p>Fold Inc. secures $30 million convertible note financing with ATW Partners backed by its bitcoin assets [<a href="https://ffnews.com/newsarticle/funding/fold-inc-announces-up-to-30-million-convertible-note-financing-backed-by-bitcoin/">FFNews</a>]</p></li><li><p>JAN3 raises $5 million in a seed funding round for AQUA Wallet development [<a href="https://jan3.com/blog/jan3-raises-5-million-seed-round/">Blog post</a>]</p></li></ul><h4><strong>Mining</strong></h4><ul><li><p>Fifteen transactions involving OFAC-sanctioned addresses were missing from blocks, prompting investigation into mining pool behavior [<a href="https://b10c.me/observations/13-missing-sanctioned-transactions-2024-12/">b10c Blog post</a>]</p><ul><li><p>F2Pool may be filtering sanctioned transactions, though other factors like transaction propagation or job publication may be responsible for some exclusions.</p></li></ul></li><li><p>Hashrate Index publishes a list ranking the top bitcoin mining countries of 2025 [<a href="https://hashrateindex.com/blog/top-10-bitcoin-mining-countries-of-2025/">Blog post</a>]</p></li></ul><h4><strong>Privacy</strong></h4><ul><li><p>Telegram provided U.S. authorities with data on 2,253 users in 2024, a significant increase in requests fulfilled [<a href="https://archive.ph/3vfuQ">404 Media</a>]</p><ul><li><p>Between January and September, Telegram fulfilled 14 requests involving 108 users; the number surged in the final quarter.</p></li><li><p>Following Telegram CEO Pavel Durov&#8217;s arrest, the company updated its privacy policy to share user data with law enforcement when legally required.</p></li></ul></li><li><p>GeoSpy, developed by Graylark Technologies, can pinpoint photo locations based on visual clues like soil, vegetation, and spatial relationships. [<a href="https://archive.ph/Z2t2y">404 Media</a>]</p><ul><li><p>Initially available to the public, GeoSpy has now restricted access, offering its tool to law enforcement and government agencies.</p></li><li><p>Experts warn that the widespread use of GeoSpy could pose privacy risks, as it enables mass geolocation without traditional metadata.</p></li></ul></li><li><p>The UN General Assembly adopts the United Nations Convention against Cybercrime, aimed at strengthening global cooperation to combat cybercrime and protect societies [<a href="https://news.un.org/en/story/2024/12/1158521">UN News</a>]</p><ul><li><p>Critics, including human rights activists and tech companies, raised concerns over potential misuse by authoritarian governments</p></li></ul></li><li><p>Apple agrees to a $95 million settlement following allegations that Siri recorded users without consent [<a href="https://cyberinsider.com/apple-to-pay-95-million-settlement-over-siri-privacy-breach/">CyberInsider</a>]</p><ul><li><p>Despite denying wrongdoing, Apple commits to deleting certain pre-October 2019 audio recordings and clarifying data collection practices</p></li></ul></li></ul><h4><strong>Cybercrime</strong></h4><ul><li><p>Gang exploited Bitcoin glitch for &#163;20m fraud, authorities recover full compensation [<a href="https://uk.news.yahoo.com/gang-handed-5-000-people-204629148.html">UK News</a>]</p><ul><li><p>An international crime gang exploited a flaw in an Australian cryptocurrency exchange in 2017, stealing over &#163;20m.</p></li><li><p>The victim was compensated in full due to the rise in Bitcoin&#8217;s value, with excess funds distributed to authorities.</p></li></ul></li></ul><h4><strong>Protocol</strong></h4><ul><li><p>Bitcoin Core #28121: Include verbose &#8220;reject-details&#8221; field in testmempoolaccept response [<a href="https://github.com/bitcoin/bitcoin/pull/28121">Merged</a>]</p></li><li><p>BDK #1592: Introduce Architectural Decision Records (ADRs) to document major changes by detailing the problem, decision drivers, considered alternatives, advantages and disadvantages, and the final decision. [<a href="https://github.com/bitcoindevkit/bdk/pull/1592">Merged</a>]</p></li><li><p>BDK #1670: Introduce O(n) canonicalization algorithm: This PR introduces an <code>O(n)</code> algorithm to determine the canonical set of transactions in <code>TxGraph</code> [<a href="https://github.com/bitcoindevkit/bdk/pull/1670">Merged</a>]</p></li><li><p>LDK #3435: Authenticate blinded payment paths: introduces an authentication field to the blinded path payment context message, allowing the payer to include a Hash-based Message Authentication Code (HMAC) and a nonce [<a href="https://github.com/lightningdevkit/rust-lightning/pull/3435">Merged</a>]</p></li><li><p>LDK #3340: Batch on-chain claims more aggressively per channel: introduces batching of on-chain claim transactions with pinnable outputs, reducing block space usage and fees in force-closure scenarios [<a href="https://github.com/lightningdevkit/rust-lightning/pull/3340">Merged</a>]</p></li><li><p>Eclair #2936: Delay considering a channel closed when seeing an on-chain spend: introduces a 12 block delay [<a href="https://github.com/ACINQ/eclair/pull/2936">Merged</a>]</p></li><li><p>Rust Bitcoin #3792: Add BIP324 V2 p2p network message support [<a href="https://github.com/rust-bitcoin/rust-bitcoin/pull/3792">Merged</a>]</p></li><li><p>NIP #1695: NIP-60: clarify privkey is optional [<a href="https://github.com/nostr-protocol/nips/pull/1695">Open</a>]</p></li><li><p>NIP #1706: Introduce support for signing and encryption/decryption on hardware based Nostr Signing Devices over BLE [<a href="https://github.com/nostr-protocol/nips/pull/1706">Open</a>]</p></li><li><p>NIP #1696: nostr over reticulum: allows nostr clients/relays to communicate over Reticulum networks [<a href="https://github.com/nostr-protocol/nips/pull/1696">Draft</a>]</p></li><li><p>NIP #1674: Adds Open Graph &#8220;iMeta&#8221; tags: for clients to preview URLs without having to ping them [<a href="https://github.com/nostr-protocol/nips/pull/1674">Open</a>]</p></li><li><p>NIP #1681: NIP-88: DLC oracle announcement/attestation event kinds [<a href="https://github.com/nostr-protocol/nips/pull/1681">Open</a>]</p></li></ul><h4><strong>Government &amp; Political</strong></h4><ul><li><p>At the World Economic Forum (WEF) Annual Meeting 2025, Spanish Prime Minister Pedro S&#225;nchez calls for &#8220;an end to anonymity on social media&#8221; and for forcing &#8220;all these platforms to link every user account to an European Digital Identity Wallet.&#8221; [<a href="https://x.com/ReclaimTheNetHQ/status/1882134824808538415">Reclaim The Net </a>]</p></li><li><p>U.S. court overturns sanctions on Tornado Cash mixer [<a href="https://www.theblock.co/post/336319/us-court-rules-against-tornado-cash-sanctions-torn-cryptocurrency-surges-140">The Block</a>]</p><ul><li><p>A U.S. District Court in the Western District of Texas orders the Office of Foreign Assets Control (OFAC) to remove Tornado Cash-related addresses from its Specially Designated Nationals and Blocked Persons (SDN) list.</p></li><li><p>The court <a href="https://storage.courtlistener.com/recap/gov.uscourts.txwd.1211705/gov.uscourts.txwd.1211705.99.0.pdf">rules</a> that Tornado Cash&#8217;s immutable smart contracts are not &#8220;property&#8221; under the International Emergency Economic Powers Act (IEEPA), as they cannot be owned or controlled.</p></li><li><p>Despite the sanctions reversal, the U.S. Department of Justice states that this decision does not affect ongoing criminal proceedings against Tornado Cash developers, including Roman Storm.</p></li></ul></li><li><p>Operators of Blender and Sinbad custodial bitcoin mixers arrested and charged with money laundering, facing over 25 years in prison if convicted [<a href="https://www.justice.gov/opa/pr/operators-cryptocurrency-mixers-charged-money-laundering">DOJ Press release</a>]</p><ul><li><p>The U.S. Department of Justice indicts three Russian nationals for operating unlicensed crypto mixers Blender.io and Sinbad.io</p></li><li><p>Blender.io operated from approximately 2018 to 2022, advertising a &#8220;No Logs Policy&#8221; and requiring no user registration.</p></li></ul></li><li><p>Donald and Melania Trump launch the $TRUMP and $MELANIA meme coins ahead of inauguration [<a href="https://cointelegraph.com/explained/what-is-trump-donald-trumps-billion-dollar-memecoin">Coin Telegraph</a>]</p><ul><li><p>Both tokens are built on the Solana blockchain. For $TRUMP coin, an initial supply of 200 million coins is set, with plans to expand to 1 billion over three years.</p></li><li><p>The token&#8217;s website states that $TRUMP is &#8220;not intended to be, or the subject of&#8221; an investment opportunity or any type of security, and is &#8220;not political and has nothing to do with&#8221; Trump&#8217;s campaign, office, or government agency.</p></li></ul></li><li><p>Trump-backed World Liberty Financial token extends sale [<a href="https://cointelegraph.com/news/trump-world-liberty-financial-token-sale-extended-sold-out-presale">Coin Telegraph</a>]</p><ul><li><p>World Liberty Financial extended its token sale after raising $300 million, selling 20% of 100 billion WLFI tokens at 1.5 cents each. The extension added 5 billion tokens at 5 cents, aimed at raising an additional $250 million.</p></li><li><p>A <a href="https://x.com/worldlibertyfi/status/1881457386671464804">tweet</a> from WLFI announced significant strategic purchases &#8220;to commemorate the inauguration of Donald J. Trump as the 47th President of the United States,&#8221; including $47 million in ETH and wBTC, alongside smaller investments in cryptocurrencies.</p></li></ul></li><li><p>The U.S. Department of Justice received court approval to liquidate 69,370 bitcoin following a four-year legal battle [<a href="https://decrypt.co/300133/us-court-greenlights-sale-of-6-5b-in-seized-silk-road-bitcoin">Decrypt</a>]</p></li><li><p>U.S. government recommends returning the 94,000 stolen bitcoin from 2016 Bitfinex hack to exchange as in-kind restitution [<a href="https://www.theblock.co/post/334791/us-government-says-stolen-bitcoin-from-2016-bitfinex-hack-should-be-returned-to-the-exchange-in-kind">The Block</a>]</p><ul><li><p>This recommendation aligns with prior court filings where both defendants and Bitfinex&#8217;s parent company, iFinex, acknowledged the exchange as the sole victim of the 2016 hack.</p></li></ul></li><li><p>U.S Internal Revenue Service (IRS) postpones bitcoin cost-basis reporting rules to 2026 [<a href="https://www.theblock.co/post/332781/irs-delays-implementing-crypto-cost-basis-reporting-rules">The Block</a>]</p><ul><li><p>The IRS delays new bitcoin tax reporting rules until January 1, 2026, granting brokers additional time to adapt to cost-basis regulations for centralized platforms.</p></li></ul></li><li><p>Coin Center Fellow Michael Lewellen is suing the DOJ for criminalizing the creation of non-custodial software, like his Pharos protocol [<a href="https://www.coincenter.org/coin-center-fellow-michael-lewellen-is-suing-the-doj-over-their-criminalization-of-software-development/">Coin Center Blog post</a>]</p><ul><li><p>The DOJ argues that developers who enable money movement, like those behind Tornado Cash, must register as money transmitters, a position Lewellen contests as unconstitutional and anti-innovation.</p></li></ul></li><li><p>Texas court <a href="https://www.courtlistener.com/docket/69425855/50/united-states-v-ahlgren/">orders</a> Coinbase user to surrender access to his $124 million bitcoin holdings [<a href="https://archive.ph/CX56g">Bloomberg</a>]</p><ul><li><p>Frank Ahlgren, was sentenced to two years for underreporting profits from $3.7 million in bitcoin sales.</p></li><li><p>Ahlgren must surrender access to his bitcoin holdings including private keys and passphrases, to settle a $1 million restitution, and disclose the location of 1,287 bitcoins moved via a mixing service in 2020.</p></li></ul></li><li><p>A U.S federal appeals court overturned the FCC&#8217;s net neutrality rules, limiting its authority to regulate wireless and broadband services, citing the Loper Bright case. [<a href="https://www.reuters.com/legal/us-appeals-court-blocks-biden-administration-net-neutrality-rules-2025-01-02/">Reuters</a>]</p><ul><li><p>The ruling prevents ISPs from throttling or blocking content, but allows state-level neutrality rules to remain in effect.</p></li></ul></li><li><p>Burma&#8217;s military junta is tightening control over online spaces through a new cybersecurity law targeting digital platform providers [<a href="https://apnews.com/article/internet-online-censorship-law-repression-8128ba7a2c02555217c6a64ab641eaf6">AP News</a>]</p><ul><li><p>The law mandates providers to store user data for three years and share it with the state on request, penalizing non-compliance.</p></li><li><p>VPN use is criminalized, with violators facing up to six months in prison and fines.</p></li></ul></li><li><p>Iran&#8217;s central bank abruptly blocks payment gateways to cryptocurrency exchanges amid currency crisis [<a href="https://x.com/sina_21st/status/1873097867625140230">Twitter post</a>]</p><ul><li><p>This action follows previous measures, including freezing bank accounts of cryptocurrency exchanges and suspending payment processing services in November, due to concerns over speculation in the Tether market and money laundering risks.</p></li></ul></li><li><p>Thai police seize 996 bitcoin mining devices [<a href="https://www.bangkokpost.com/thailand/general/2936275/996-bitcoin-mining-devices-seized-in-chon-buri">Bangkok Post</a>]</p><ul><li><p>Authorities raided JIT Co in Chon Buri, seizing 996 bitcoin miners, which were being run using modified power meters, stealing electricity.</p></li></ul></li><li><p>Kazakhstan shut down 36 unauthorized crypto exchanges in 2024, seizing assets worth $112 million [<a href="https://cointelegraph.com/news/kazakhstan-crypto-crackdown-2024">Coin Telegraph</a>]</p><ul><li><p>Authorities are working on a digital currency, the digital tenge, and are collaborating with Visa and Mastercard to integrate it into global payment systems.</p></li></ul></li></ul><h4><strong>Events</strong></h4><ul><li><p><a href="https://x.com/MyfirstBitcoin_/status/1876282680838349004">Bitcoin Educators Unconference</a>: Mi Primer Bitcoin fourth conference for educators, meetup organizers and community leaders</p><ul><li><p>April 10, 2025 in Nashville, U.S</p></li></ul></li><li><p><a href="https://bitcoinisforeveryone.com/">Bitcoin Is For Everyone</a>: An immersive full-day Bitcoin Experience in Portland, OR</p><ul><li><p>August 1st, 2025 in Portland, U.S</p></li></ul></li></ul><h3><strong>Reads</strong></h3><ul><li><p>Here&#8217;s a list of our top recently published reads:</p><ul><li><p>Privacy matters because it empowers us all, by Carissa V&#233;liz [<a href="https://aeon.co/essays/privacy-matters-because-it-empowers-us-all">Essay</a>]</p></li><li><p>A Spark of Defiance: A guide to Solo mining with a Bitaxe to a RasPi full node &amp; a self-hosted Public Pool stratum server, by econoalchemist [<a href="https://256foundation.org/newsletters/256Foundation-Newsletter-2501_v1.pdf">The 256 Foundation</a>]</p></li><li><p>How to run an economic node, by Scoresby [<a href="https://stacker.news/items/842044">Guide</a>]</p></li><li><p>Quantum Leap? Disentangling fact from fiction in bitcoin and quantum computing, by John [<a href="https://www.ten31timestamp.com/p/quantum-leap">Ten31 Blog post</a>]</p></li><li><p>Nostr is the world&#8217;s biggest bitcoin circular economy, by Frank Corva [<a href="https://bitcoinmagazine.com/takes/nostr-is-the-worlds-biggest-bitcoin-circular-economy-join-us">Bitcoin Magazine</a>]</p></li><li><p>A Day in the Life of a Prolific Voice Phishing Crew, by Krebs On Security [<a href="https://krebsonsecurity.com/2025/01/a-day-in-the-life-of-a-prolific-voice-phishing-crew/">Blog post</a>]</p></li><li><p>Buckets of blind signatures, by Cashu [<a href="https://blog.cashu.space/buckets-of-blind-signatures/">Blog post</a>]</p></li></ul></li></ul><h3><strong>Episode submission ideas</strong></h3><ul><li><p>We&#8217;re looking for ideas for interesting panel conversations. To send Bitcoin related questions, just go to <a href="https://bitcoin.review/">bitcoin.review</a> and follow the contact links at the bottom of the page.</p></li></ul><h3><strong>Get in touch with the pod</strong></h3><ul><li><p><a href="https://twitter.com/bitcoinreviewhq">Podcast Twitter</a></p></li><li><p><a href="https://twitter.com/nvk">NVK Twitter</a></p></li><li><p><a href="https://t.me/BitcoinReviewPod">Telegram</a></p></li><li><p><a href="mailto:producer@coinkite.com">Email</a></p></li><li><p>Nostr &amp; LN &#9889;nvk@nvk.org (not an email!)</p></li></ul>]]></content:encoded></item><item><title><![CDATA[BR090 - COLDCARD, BullBitcoin, Tangem & Proton Vulnerabilities, Signatures Explained + MORE ft. Rob]]></title><description><![CDATA[I&#8217;m joined by guest Rob Hamilton to go through the list.]]></description><link>https://substack.bitcoin.review/p/br090-coldcard-bullbitcoin-tangem</link><guid isPermaLink="false">https://substack.bitcoin.review/p/br090-coldcard-bullbitcoin-tangem</guid><dc:creator><![CDATA[STACK TO THE FUTURE]]></dc:creator><pubDate>Fri, 03 Jan 2025 23:01:37 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a95ac75-ac77-4167-9383-9930a48690bb_1080x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I&#8217;m joined by guest <a href="https://twitter.com/Rob1Ham">Rob Hamilton</a> to go through the list.</p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://bitcoin.review/podcast/episode-56/&quot;,&quot;text&quot;:&quot;Listen on your favorite podcast app&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://bitcoin.review/podcast/episode-56/"><span>Listen on your favorite podcast app</span></a></p><div><hr></div><h3><strong>Housekeeping</strong></h3><ul><li><p>00:01:37 Verify-address over NFC using a Coldcard Q and BDK iOS example wallet [<a href="https://njump.me/nevent1qqs8qjzkcdtzp93tkckekezeevvlnh6rjugc5a6wk4urdncn4080sjcpzemhxue69uhhyetvv9ujumn0wd68ytnzv9hxgq3qreezn2ctrrg736uqj7mva9lsuwv0kr5asj4vvkwxnrwlhvxf98tscetek9">Demo by Matthew Ramsden</a>]</p></li></ul><h3><strong>Urgent Vulnerability Disclosures</strong></h3><ul><li><p>00:18:57 New fake Ledger data breach emails try to steal crypto wallets [<a href="https://www.bleepingcomputer.com/news/security/new-fake-ledger-data-breach-emails-try-to-steal-crypto-wallets/">Bleeping Computer</a>]</p><ul><li><p>These emails falsely claim that a data breach has occurred, urging recipients to verify their recovery phrases through a provided link.</p></li></ul></li><li><p>00:20:51 Cryptocurrency hardware wallet Tangem &#8216;fixes&#8217; app bug that saved user seed phrases in application logs, exposing private keys during support interactions [<a href="https://cointelegraph.com/news/tangem-security-vulnerability-fixed-private-key-leak">Coin Telegraph</a>]</p><ul><li><p>&#8220;What was the issue? When creating a wallet with a seed phrase, the private key was mistakenly logged in the application&#8217;s logs. These logs could later be accessed during interactions with our support team.&#8221; [<a href="https://www.reddit.com/r/Tangem/comments/1hougo1/comment/m4jygh9/">Tangem&#8217;s Reddit comment</a>]</p></li><li><p>Redditor, u/areklanga points out in a <a href="https://www.reddit.com/r/Tangem/comments/1hougo1/comment/m4jygh9/?context=3">Reddit discussion</a> on Tangem&#8217;s operations &#8220;So, user private keys remain in both user email history, Tangem email history, and perhaps in some Tangem ticket tracking system and are available for Tangen employees. Which makes all Tangem users compromized.&#8221;</p></li></ul></li><li><p>00:26:03 Irrevocable fees&#8212;stealing from LN using revoked commitment transactions [<a href="https://delvingbitcoin.org/t/disclosure-irrevocable-fees-stealing-from-ln-using-revoked-commitment-transactions/1314">David Harding&#8217;s disclosure</a>]</p><ul><li><p>A critical vulnerability in all major Lightning Network implementations could allow miners to steal up to 98% of channel funds under certain conditions. Honest users performing normal operations also risk smaller fund losses due to similar flaws.</p></li><li><p>Eclair, LDK, and LND with default settings were vulnerable to an immediately exploitable version of the attack. Core Lightning users face risks with non-default configurations, especially when the <code>--ignore-fee-limits</code> setting is enabled.</p></li><li><p>Mitigations for the most critical flaws are implemented through updates: Eclair v0.10.0 (Feb 2024), LDK v0.0.123 (May 2024), and LND v0.18.3-beta (Sept 2024). Future protocol changes are required to eliminate all variations of the vulnerability.</p></li></ul></li><li><p>00:27:13 Security research company Zellic identified a <a href="https://www.zellic.io/blog/proton-dart-flutter-csprng-prng/#2--proton-wallet-encryption-vulnerability">vulnerability in Proton Wallet&#8217;s early preview version</a>, affecting wallet and backup mnemonic security.</p><ul><li><p>The issue stemmed from the use of Dart&#8217;s Random() class, which is not cryptographically secure. This weakness made it feasible for attackers to predict generated passwords, compromising user data.</p></li></ul></li></ul><h3><strong>Bitcoin</strong></h3><h4><strong>Software Releases &amp; Project Updates</strong></h4><ul><li><p>00:28:29 Coldcard Edge <a href="https://blog.coinkite.com/edge-634/">v6.3.4</a></p><ul><li><p>Shared Improvements - Both Mk4 and Q</p><ul><li><p>Enhancement: Hide Secure Notes &amp; Passwords in Deltamode. Wipe seed if notes menu accessed</p></li><li><p>Enhancement: Hide Seed Vault in Deltamode. Wipe seed if Seed Vault menu accessed</p></li><li><p>Bugfix: Do not allow to enable/disable Seed Vault feature when in temporary seed mode</p></li><li><p>Bugfix: Bless Firmware causes hanging progress bar</p></li><li><p>Bugfix: Prevent yikes in ownership search</p></li><li><p>Change: Do not allow to purge settings of current active tmp seed when deleting it from Seed Vault</p></li></ul></li><li><p>Mk4 Specific Changes</p><ul><li><p>All updates from 5.4.0</p></li><li><p>Enhancement: Export single sig descriptor with simple QR</p></li></ul></li><li><p>Q Specific Changes</p><ul><li><p>All updates from version 1.3.0Q</p></li><li><p>Bugfix: Properly re-draw status bar after Restore Master on COLDCARD without master seed</p></li></ul></li></ul></li><li><p>00:33:00 BLOCKCLOCK <a href="https://blockclockmini.com/firmware/ChangeLog.html">v1.2.3</a></p><ul><li><p>MINI only:</p><ul><li><p>Add some &#8220;mime fun&#8221; on display page. Mr. Yellow makes an appearance.</p></li><li><p>Press either of the two middle buttons (not top/bottom) and the next value in your list will be shown immediately. MICRO already had this feature with bottom right button.</p></li></ul></li><li><p>External IP address reported into the log file to aid network debug.</p></li><li><p>MAC address (wifi) is now shown on network page. Might be used for DHCP management on your LAN.</p></li><li><p>Carat symbol (^) added to the font.</p></li><li><p>Some values will be able to show OVER/UNDER without the bar between.</p></li><li><p>Improve local API display of numeric values, when using /api/show/number endpoint.</p></li></ul></li><li><p>00:33:36 BDK <a href="https://github.com/bitcoindevkit/bdk/releases/tag/wallet-1.0.0">v1.0.0</a></p><ul><li><p><code>Wallet::transactions</code> should only return relevant transactions</p></li><li><p>Minor updates to fix new rustc 1.83.0 clippy warnings</p></li></ul></li><li><p>00:33:50 Nunchuk</p><ul><li><p>Android</p><ul><li><p><a href="https://github.com/nunchuk-io/nunchuk-android/releases/tag/android.1.9.57">v1.9.57</a></p><ul><li><p>Taproot multisig wallets: Nunchuk introduces Taproot multisig, reducing transaction fees and simplifying complex scripts, improving user experience and network performance.</p></li></ul></li><li><p><a href="https://github.com/nunchuk-io/nunchuk-android/releases/tag/android.1.9.56">v1.9.56</a></p><ul><li><p>Add dark mode</p></li><li><p>Add biometric login support</p></li></ul></li></ul></li><li><p>Desktop <a href="https://github.com/nunchuk-io/nunchuk-desktop/releases/tag/1.9.42">v1.9.42</a></p><ul><li><p>Implement advanced coin control</p></li></ul></li></ul></li><li><p>00:34:19 BullBitcoin Mobile <a href="https://github.com/SatoshiPortal/bullbitcoin-mobile/releases/tag/v0.4.0">v0.4.0</a> - Payjo+n</p><ul><li><p>Basic Payjoin Implementation:</p><ul><li><p>Bull Bitcoin integrates Payjoin V2 into its mobile wallet, enabling serverless, asynchronous Bitcoin transactions. [<a href="https://www.bullbitcoin.com/blog/bull-bitcoin-wallet-payjoin">Announcement</a>]</p></li><li><p>Payjoin transactions no longer require constant internet connectivity or a full node. The receiver&#8217;s device can stay offline, resuming the session when reconnected.</p></li></ul></li></ul></li><li><p>00:36:59 Bitcoin Keeper</p><ul><li><p>Mobile <a href="https://github.com/bithyve/bitcoin-keeper/releases/tag/vv1.3.1">v1.3.1</a></p><ul><li><p>New Collaborative Wallet flow to make it easier to create a wallet with friends and family</p></li><li><p>Update the signing devices UI with a focus on easier collaboration and use</p></li></ul></li><li><p>How to set up Bitcoin Keeper wallet with Tapsigners to create a mobile inheritance plan [<a href="https://youtu.be/tCld_-n2d30">Tutorial by BTC Sessions</a>]</p></li></ul></li><li><p>00:37:21 Electrs <a href="https://github.com/romanz/electrs/blob/master/RELEASE-NOTES.md#0108-dec-30-2024">v0.10.8</a></p><ul><li><p>Separate blocks reading &amp; index writing into scoped threads</p></li><li><p>Set HTTP <code>Content-Type</code> header for Prometheus response</p></li><li><p>Use <code>ctrlc</code> in place of <code>signal-hook</code> on Windows</p></li><li><p>Don&#8217;t deserialize transactions if not needed</p></li><li><p>Run CI only on <code>master</code> branch and PRs</p></li><li><p>Update dependencies (<code>bitcoin</code>, <code>bitcoin_slices</code>, <code>crossbeam-channel</code>, <code>tempfile</code>)</p></li></ul></li><li><p>00:39:20 BTCPayServer <a href="https://github.com/btcpayserver/btcpayserver/releases/tag/v2.0.5">v2.0.5</a></p><ul><li><p>Checkout: Add support link to footer</p></li><li><p>Pull Payment: Add &#8220;Copy Link&#8221; button to the action column</p></li><li><p>Greenfield: Remove authorization requirement for PoS data</p></li><li><p>Greenfield: Resolve store user&#8217;s image URL</p></li></ul></li><li><p>00:39:36 rust-payjoin <a href="https://github.com/payjoin/rust-payjoin/releases/tag/payjoin-0.22.0">v0.22.0</a></p><ul><li><p>Payjoin V2 Sender now serializes reply_key so that it may resume after being persisted</p><ul><li><p>Propagate uri Fragment parameter errors to their caller</p></li><li><p>Have Sender persist reply key so resumption listens where a previous send session left off</p></li></ul></li></ul></li><li><p>00:39:45 Krux installer <a href="https://github.com/selfcustody/krux-installer/releases/tag/v0.0.20">v0.0.20</a></p><ul><li><p>First stable version of the entire code refactoring. Exisiting features:</p><ul><li><p>Automatic check of latest official firmware</p></li><li><p>Optional selection of older firmware versions</p></li><li><p>Supported devices: M5stickV, Sipeed Amigo, Sipeed Bit, Sipeed Dock, Sipeed Cube, Yahboom, WonderMV</p></li><li><p>Flash official firmware with automatic integrity/authenticity verification</p></li><li><p>Flash beta firmware devices</p></li><li><p>Air-gap update devices with SDcard</p></li><li><p>Wipe devices</p></li><li><p>Support for Windows, MacOS Arm, MacOS Intel, Debian-like OS and Fedora</p></li></ul></li></ul></li><li><p>00:39:55 Frostsnap <a href="https://github.com/frostsnap/frostsnap/releases/tag/v0.0.0-alpha.1">v0.0.0-alpha.1</a></p><ul><li><p>Basic wallet recovery:</p><ul><li><p>Allows you to delete keys from the key list</p></li><li><p>Allows you to recover them by plugging in devices</p></li></ul></li></ul></li><li><p>00:40:42 Bitcoin Safe <a href="https://github.com/andreasgriffin/bitcoin-safe/releases/tag/1.0.0rc1">1.0.0rc1</a></p><ul><li><p>New Features:</p><ul><li><p>Full support for all major hardware signers Coldcard, Q, Bitbox02, Blockstream Jade, Trezor, Foundation Passport, Keystone, Ledger, Specter DIY</p><ul><li><p>Full support for BBQr and UR</p></li></ul></li><li><p>Balance Statement PDF Export</p></li></ul></li><li><p>Improved Features:</p><ul><li><p>Sync &amp; Chat: Label Synchronization backup and Multi-party Multisig Collaboration can now be enabled in the last wallet setup wizard step</p></li><li><p>Transaction diagram navigation by clicking on inputs and outputs</p></li></ul></li></ul></li><li><p>00:42:03 Blockstream Satellite <a href="https://github.com/Blockstream/satellite/releases/tag/v2.5.0">v2.5.0</a></p><ul><li><p>Add graphical user interface (GUI) application (<code>blocksat-gui</code>)</p></li><li><p>Add option to disable Linux media build backport on TBS driver installation</p></li><li><p>Update Telstar 11N Africa and Europe downlink frequencies</p></li></ul></li><li><p>00:42:28 Raspiblitz <a href="https://github.com/raspiblitz/raspiblitz/releases/tag/v1.11.4">v1.11.4</a></p><ul><li><p>AlbyHub feature release</p></li><li><p>Add AlbyHub to RaspiBlitz SSH menus</p></li><li><p>Improve mempool install script</p></li></ul></li><li><p>00:42:39 Ashigaru <a href="http://ashicodepbnpvslzsl2bz7l2pwrjvajgumgac423pp3y2deprbnzz7id.onion/Ashigaru/Ashigaru-Mobile/releases/tag/v1.1.0">v1.1.0</a></p><ul><li><p>Overhaul of Settings menu user interface</p></li><li><p>Add wallet accounts recovery information</p></li><li><p>Ability to automatically update over Tor the app&#8217;s functionality URLs (with PGP verification) to ensure continuous PayNym directory and Soroban network availability.</p></li><li><p>Display Tor direct download .onion URLs. URLs automatically updated over Tor (with PGP verification).</p></li><li><p>Display Ashigaru Tor website URL. URL automatically updated over Tor (with PGP verification).</p></li><li><p>Ability to hide balance by tapping on available balance</p></li><li><p>Consolidation and Wallet Sweep transaction alerts</p></li></ul></li><li><p>00:45:02 BoltzExchange</p><ul><li><p>boltz-web-app <a href="https://github.com/BoltzExchange/boltz-web-app/releases/tag/v1.6.0">v1.6.0</a></p><ul><li><p>Add WalletConnect</p></li><li><p>Show error when QR scanning is not supported in browser</p></li><li><p>Help server claim Chain Swaps that receive on EVM</p></li></ul></li><li><p>boltz-backend <a href="https://github.com/BoltzExchange/boltz-backend/releases/tag/v3.9.0">v3.9.0</a> - Swarm of Swaps</p><ul><li><p>Add batch claim support for Chain Swaps</p></li><li><p>Add batch claiming on EVM based chains</p></li></ul></li><li><p>BoltzExchange launched <a href="https://pro.boltz.exchange/">Boltz Pro</a>, a non-custodial way to earn sats with swaps on Boltz [<a href="https://x.com/Boltzhq/status/1873778290210566233">Announcement</a>]</p><ul><li><p>Boltz Pro offers dynamic fees that let users earn sats for swapping funds in specific directions when wallet imbalances arise.</p></li></ul></li></ul></li><li><p>00:45:04 Mempal <a href="https://github.com/aeonBTC/Mempal/releases/tag/v1.4.0">v1.4.0</a></p><ul><li><p>New app icon</p></li><li><p>Tap to refresh any individual dashboard card</p></li><li><p>Save multiple custom mempool servers in settings</p></li><li><p>New settings option to change notification intervals from minutes to seconds</p></li><li><p>Fee distribution data will now fallback to mempool.space when using a custom mempool server</p></li><li><p>Widget data now defaults to mempool.space when using Tor</p></li></ul></li><li><p>00:45:11 Zaprite <a href="https://help.zaprite.com/en/articles/10315897-zaprite-release-notes-2024-12-23">v2024-12-23</a></p><ul><li><p>Orqestra: add new Orqestra.io integration to enable automated USD-to-BTC conversions</p></li><li><p>Merchant X: update Merchant X Checkouts to use an inline credit card form instead of a modal</p></li><li><p>Public API: update documentation to explain that Orders are not visible until paid</p></li><li><p>LNURL: enhance LNURL error reporting</p></li></ul></li><li><p>00:45:13 ESP-Miner <a href="https://github.com/skot/ESP-Miner/releases/tag/v2.4.2">v2.4.2</a></p><ul><li><p>Add uptime to home screen</p></li><li><p>Change naming of stratum url to host</p></li><li><p>Change Stratum Fallback URL as well</p></li><li><p>Adds solohash getQuickLink()</p></li><li><p>Change Mining URL to Stratum Host on screen</p></li></ul></li></ul><h4><strong>Project spotlight</strong></h4><ul><li><p>00:45:18 Satoshi: A new wallet for Bitcoin, Lightning, and Liquid payments, that can be both custodial or self custodial [<a href="https://x.com/satoshimoneybtc/status/1868721579305124231">Announcement</a>]</p><ul><li><p>Satoshi Version 1.0 is now live in the App Store in 40 countries. &#127881;</p></li></ul></li><li><p>00:45:28 Joinstr: An experimental rust implementation of <a href="https://joinstr.xyz/">joinstr</a> [<a href="https://github.com/pythcoiner/joinstr">Github</a>]</p><ul><li><p>A dedicated <a href="https://miningpool.observer/template-and-block/sanctioned-feed.xml">RSS feed</a> is available.</p></li></ul></li><li><p>00:45:33 <a href="https://miningpool.observer/">miningpool-observer</a>: The project compares block templates produced by a Bitcoin Core node to blocks produced by mining pools to provide insights [<a href="https://github.com/0xb10c/miningpool-observer">Github</a>]</p></li><li><p>00:46:51 <a href="https://dojobay.pw/">Dojo Bay</a>: A directory of available Dojo nodes, allowing users to select nodes based on reputation and location, both for Mainnet and Testnet.</p></li><li><p>00:46:56 Nightly Bitcoin Core Tests: A tool to test and review development versions of Bitcoin Core [<a href="https://github.com/hebasto/bitcoin-core-nightly">Github</a>]</p></li><li><p>00:47:04 <a href="https://nigiri.vulpem.com/">Nigiri</a>: A delicious docker box for special Bitcoin cookings [<a href="https://github.com/vulpemventures/nigiri">Github</a>]</p><ul><li><p>Nigiri offers a command-line interface that utilizes preconfigured Docker Compose setups to create a ready-to-use Bitcoin regtest environment.</p></li><li><p>The preconfigured package includes a Bitcoin Core node running in regtest mode, a backend and frontend explorer (Electrum) and Chopsticks a JSON HTTP proxy. You can extend the setup with: Ark, Elements/Liquid sidechain, and Lightning Network nodes.</p></li></ul></li><li><p>00:47:15 Run Litd: Notes and helper scripts for setting up and running a Litd node. [<a href="https://github.com/HannahMR/run-litd">Github</a>]</p></li><li><p>00:47:28 bllsh: A bullish shell for a bitcoin lisp language [<a href="https://github.com/ajtowns/bllsh">Github</a>]</p><ul><li><p>&#8220;Basic Bitcoin Lisp language (bll) is a proposed scripting language that could be added to Bitcoin in a soft fork. Formerly called BTC Lisp and conceptually based on Chia Lisp, it&#8217;s part of a set of tools that includes symbll (a miniscript-like compiler of higher-level Lisp to lower-level bll) and bllsh (a REPL for trying and debugging symbll and bll).&#8221; [<a href="https://bitcoinops.org/en/topics/basic-bitcoin-lisp-language/">Bitcoin Optech definition</a>]</p></li><li><p>AJ Towns recently presented his work on Basic Bitcoin Lisp Language to Brink engineers [<a href="https://brink.dev/blog/2024/12/19/eng-call-aj-towns-bll/">Presentation</a>]</p></li></ul></li><li><p>00:48:05 <a href="https://btceed.live/">Btceed</a>: Bird&#8217;s-eye view of your bitcoin HD wallet [<a href="https://github.com/pycanis/btceed">Github</a>]</p><ul><li><p>Btceed is a web application that provides a graphical overview of Bitcoin HD wallets using seed phrases.</p></li></ul></li><li><p>00:48:12 <a href="https://supertestnet.github.io/zero_fee_playground/">Zero Fee Playground</a>: A site for trying out zero fee bitcoin transactions</p><ul><li><p>The Zero Fee Playground provides a step-by-step demonstration for creating and testing paired transactions using Bitcoin version 28&#8217;s updated rules.</p></li></ul></li><li><p>00:49:17 <a href="https://supertestnet.github.io/p2pk_playground/">P2PK Playground</a>: A site for creating P2PK outputs in bitcoin i.e. paying someone&#8217;s raw public key</p><ul><li><p>The guide includes step-by-step instructions for creating and spending P2PK outputs, highlighting tools for broadcasting transactions</p></li></ul></li><li><p>00:50:51 <a href="https://testnet4.info/">Bitcoin Testnet4 Faucet</a>: A faucet for Bitcoin testnet4 coins, written in C# using ASP.Net Razor Pages and NBitcoin. [<a href="https://github.com/remcoros/bitcoin-testnet4-faucet">Github</a>]</p><ul><li><p>The faucet uses OAuth to authenticate users and does not store any personal information.</p></li></ul></li><li><p>00:50:58 <a href="https://hashteroids.btcdir.org/">Hashteroids</a>: browser-based game combining elements of the classic Asteroid arcade gameplay with Bitcoin mining concepts</p></li><li><p>00:51:07 My First Bitcoin launches <a href="https://network.myfirstbitcoin.io/">Community Hub</a> to support independent bitcoin educators with resources and tools [<a href="https://myfirstbitcoin.io/my-first-bitcoin-launches-community-hub-a-platform-for-independent-bitcoin-educators/">Announcement</a>]</p><ul><li><p>The platform features Wikis, forums, and a structured system for new educators, helping them connect and share resources globally.</p></li></ul></li></ul><h3><strong>Vulnerability Disclosures</strong></h3><ul><li><p>00:51:39 Oasis Security&#8217;s research team discovers a critical flaw in Microsoft&#8217;s Multi-Factor Authentication system, enabling attackers to bypass it and access user accounts, including Outlook, OneDrive, Teams, and Azure Cloud. [<a href="https://www.oasis.security/resources/blog/oasis-security-research-team-discovers-microsoft-azure-mfa-bypass">Public disclosure</a>]</p><ul><li><p>The vulnerability involves a lack of rate limiting for failed MFA attempts, permitting rapid session creation and code enumeration.</p></li><li><p>Attackers can exhaust all 1 million possible six-digit codes within approximately an hour, without user interaction or alerts.</p></li></ul></li><li><p>00:51:53 Five dollar wrench attacks: Fake uber driver steals over $223,000 in cryptocurrency from customers&#8217; centralized exchange accounts [<a href="https://www.fox10phoenix.com/news/fake-uber-driver-allegedly-stole-thousands-crypto-from-customers">Fox10</a>]</p><ul><li><p>The driver allegedly deceived victims into handing over their phones by claiming his own device was malfunctioning or offering to assist with the Uber app.</p></li><li><p>Once in possession of the phones, he reportedly transferred funds from their Coinbase accounts.</p></li></ul></li><li><p>00:52:40 Two men fall victim to phishing scams, in May 2024, involving fraudulent Google security prompts [<a href="https://krebsonsecurity.com/2024/12/how-to-lose-a-fortune-with-just-one-bad-click/">Krebs On Security</a>]</p><ul><li><p>An individual fell victim to a phishing scam, losing nearly $500,000 in cryptocurrency. Scammers tricked him into clicking a fraudulent Google account recovery prompt, providing them access to his Google account. They then retrieved his secret seed phrase stored in Google Photos.</p></li><li><p>Another individual lost 45 bitcoin after receiving a fake Google security alert and a call from someone claiming his account was compromised. The victim clicked &#8220;yes&#8221; on the fraudulent prompt and later provided his seed phrase on a phishing site, leading to the instant drainage of his wallet.</p></li></ul></li><li><p>00:55:28 Apache MINA&#8217;s CVE-2024-52046 flaw, rated CVSS 10.0, enables remote code execution through unsafe Java deserialization. [<a href="https://thehackernews.com/2024/12/apache-mina-cve-2024-52046-cvss-100.html">The Hacker News</a>]</p><ul><li><p>The vulnerability affects versions 2.0.X, 2.1.X, and 2.2.X, triggered by specific classes and unsafe data processing.</p></li></ul></li><li><p>00:55:37 WPA3 vulnerability: risks of downgrade attacks and social engineering [<a href="https://cybernews.com/security/wifi-hackers-can-bypass-wpa3-security/">CyberNews</a>]</p><ul><li><p>Researchers reveal WPA3 vulnerabilities through a rogue access point and a downgrade attack to WPA2. This allows hackers to capture partial handshake data and potentially recover WiFi passwords.</p></li></ul></li><li><p>00:56:07 Hackers compromise 16 Chrome extensions, affecting over 600,000 users, by injecting malicious code to steal cookies and access tokens. [<a href="https://thehackernews.com/2024/12/16-chrome-extensions-hacked-exposing.html">The Hacker News</a>]</p><ul><li><p>The attack begins with a breach of Cyberhaven&#8217;s extension on December 24, 2024, through a web-browser-based supply chain attack, exploiting an employee&#8217;s credentials to publish a malicious update. [<a href="https://www.cyberhaven.com/blog/cyberhavens-chrome-extension-security-incident-and-what-were-doing-about-it">Press release</a>]</p></li></ul></li><li><p>00:56:54 Symlink exploit: A vulnerability in Apple&#8217;s FileProvider component, identified as CVE-2024-44131, allows unauthorized access to sensitive data by bypassing the Transparency, Consent, and Control (TCC) framework. [<a href="https://thehackernews.com/2024/12/researchers-uncover-symlink-exploit.html">The Hacker News</a>]</p><ul><li><p>Exploiting this flaw, a malicious app can intercept user file operations in the Files app, redirecting them to attacker-controlled locations without user awareness.</p></li></ul></li></ul><h3><strong>Audience Questions</strong></h3><ul><li><p>00:57:22 Thanks to everyone who sent in questions. Remember to send yours to questions@bitcoin.review.</p><ul><li><p>00:57:32 Can you explain (like I own ETH), how signatures work for spending Bitcoin? Perhaps you can give a useful analogy for how signing can be done offline using your private key, but which doesn&#8217;t releal your private key to the network. In other words how do you PROVE to the network you can legitmately spend that bitcoin without revealing your private key? - anonymous</p></li><li><p>01:01:04 When people say &#8220;there&#8217;s not enough UTXOs for everyone to have one&#8221;. How do you quantify that? What&#8217;s the number of UTXOs and what factors affect that number? (Such as blocksize?) - anon</p></li><li><p>01:06:20 &#8220;I have a legacy address that starts with 1 wirh some BTC Should I be worried about CC?&#8221; -@Johnylabb</p></li><li><p>01:07:16 &#8220;Don&#8217;t get it&#8230;.why should anyone, except maybe millionaires, self custody? Even if u have a lot of BTC, if it&#8217;s from many small utxo then it&#8217;s worthless&#8221; -@Richard-ki4nkgm</p></li><li><p>01:10:20 &#8220;If BTC must be essentially be held in custody, then why use BTC over gold? Distrust among large banks might encourage BTC over gold?&#8221; -@Richard-ki4nkgm</p></li></ul></li></ul><h3><strong>Privacy &amp; Other Related Bitcoin Projects</strong></h3><h4><strong>Software Releases &amp; Project Updates</strong></h4><ul><li><p>Reticulum MeshChat</p><ul><li><p><a href="https://github.com/liamcottle/reticulum-meshchat/releases/tag/v1.18.0">v1.18.0</a></p><ul><li><p>Add interface importing and exporting</p></li><li><p>Add dropdown menu on interfaces</p></li><li><p>Add button to export a single interface</p></li></ul></li><li><p><a href="https://github.com/liamcottle/reticulum-meshchat/releases/tag/v1.17.0">v1.17.0</a></p><ul><li><p>Add docker image</p></li><li><p>Add the ability to select a custom profile icon similar to Sideband&#8217;s Icon Appearance</p></li><li><p>Add the ability to select different levels of image compression when adding an image to a message</p></li></ul></li><li><p><a href="https://github.com/liamcottle/reticulum-meshchat/releases/tag/v1.16.0">v1.16.0</a></p><ul><li><p>Add new Ping tool under <code>Tools</code> -&gt; <code>Ping</code></p></li></ul></li><li><p><a href="https://github.com/liamcottle/reticulum-meshchat/releases/tag/v1.15.0">v1.15.0</a></p><ul><li><p>Add RNode web flasher to new tools section</p></li><li><p>Add SNR and hops away to LXMF announces list</p></li><li><p>Add new drop down menu to conversation viewer</p></li><li><p>Add the ability to ping destination from conversation viewer dropdown</p></li><li><p>Add LXMF user icons to the announce list and conversation viewer</p></li><li><p>Add signal metrics to conversation viewer</p></li></ul></li><li><p><a href="https://github.com/liamcottle/reticulum-meshchat/releases/tag/v1.14.0">v1.14.0</a></p><ul><li><p>Add dark mode</p></li><li><p>Add full micron format and field support thanks</p></li><li><p>Add setting to select Light Theme or Dark Theme</p></li><li><p>Add support for showing Sideband/LXMF user appearance icons in conversations list</p></li></ul></li></ul></li><li><p>SimpleX</p><ul><li><p><a href="https://github.com/simplex-chat/simplex-chat/releases/tag/v6.3.0-beta.0">v6.3.0-beta.0</a></p><ul><li><p>Chat lists: organize and filter your chats</p></li></ul></li><li><p><a href="https://github.com/simplex-chat/simplex-chat/releases/tag/v6.2.2">v6.2.2</a></p><ul><li><p>Open files in default app (Android)</p></li></ul></li></ul></li></ul><h4><strong>Project spotlight</strong></h4><ul><li><p><a href="https://superbacked.com/">Superbacked</a>: A secret management platform used to back up and pass on sensitive data from one generation to the next, is now free and source-available [<a href="https://superbacked.com/faq/you-are-not-the-product">Announcement</a>]</p><ul><li><p>&#8220;Superbacked distributed backups are encrypted using Shamir Secret Sharing &#8230; before being encrypted (again) using Blockcrypt.&#8221; [<a href="https://github.com/superbacked/superbacked">Github</a>]</p></li></ul></li><li><p><a href="https://www.ludlowinstitute.org/">The Ludlow Institute</a>: an independent research and media organization dedicated to defending privacy, freedom, and individual autonomy in the digital age. [<a href="https://www.ludlowinstitute.org/articles/introducing-the-ludlow-institute">Announcement</a>]</p><ul><li><p>The institute aims to advance privacy and surveillance research, support privacy tools through advocacy and grants, and provide educational resources such as workshops and meetups.</p></li></ul></li></ul><h3><strong>Lightning + L2+</strong></h3><h4><strong>Project spotlight</strong></h4><ul><li><p>Self-custodial wallet <a href="https://klever.io/">Klever Wallet</a> integrates the Lightning Network using the Breez SDK. [<a href="https://klever.io/blog/klever-wallet-and-breeze-lightning/">Blog post</a>]</p><ul><li><p>Klever targets underserved areas like Nigeria, Brazil, India, and the Philippines with this integration.</p></li></ul></li><li><p>Doppler: A tool for building out and managing bitcoind/lightning clusters for regtest or signet environments [<a href="https://github.com/tee8z/doppler">Github</a>]</p></li><li><p>LN OPR: A fast, scalable protocol for resolving Lightning payments [<a href="https://github.com/JohnLaw2/ln-opr">Github</a>]</p><ul><li><p>The Off-chain Payment Resolution (OPR) protocol enables Lightning payments to be resolved off-chain, even in worst-case situations.</p></li><li><p>It ensures faster resolution, typically within seconds, and improves scalability by avoiding additional blockchain data. [<a href="https://github.com/JohnLaw2/ln-opr/blob/main/opr_v1.1.pdf">Research paper</a>]</p></li></ul></li><li><p>Magma AI: Intelligent channel management for Lightning Network [<a href="https://amboss.tech/blog/magma-ai">Announcement</a>]</p><ul><li><p>&#8220;By analyzing network data to recommend optimal channel configurations, Magma AI helps node operators improve routing performance and manage liquidity more efficiently.&#8221;</p></li></ul></li><li><p>Lightstack (Full Phoenixd Stack): Automagic selfcustodial cloud Lightning stack [<a href="https://github.com/massmux/lightstack">Github</a>]</p><ul><li><p>A self-custodial Lightning node that can be run on a VPS using this stack, accessed via your domain name. It includes an LNBits instance on your node and a phoenixd endpoint secured with SSL.</p></li><li><p>A multistack feature now allows multiple stacks to operate on the same VPS, served concurrently.</p></li></ul></li><li><p><a href="https://zapplanner.albylabs.com/">ZapPlanner</a>: Schedule automatic recurring lightning payments</p><ul><li><p>ZapPlanner is a tool enabling automated transfers within customizable intervals, using Nostr Wallet Connect.</p></li></ul></li><li><p>CLN Backup: A CLN plugin that uploads the latest SCB to remote locations. [<a href="https://github.com/BoltzExchange/cln-backup">Github</a>]</p></li><li><p>Hashpool: An accountless mining pool that represents mining shares as ecash tokens [<a href="https://github.com/vnprc/hashpool">Github</a>]</p><ul><li><p>&#8220;This project is a fork of the Stratum V2 Reference Implementation (SRI) that replaces traditional share accounting with an ecash mint.&#8221;</p></li></ul></li><li><p>nutjar-ui: A project that helps integrate Lightning tips on websites using nostr and Cashu [<a href="https://github.com/Egge21M/nutjar-ui">Github</a>]</p><ul><li><p>It provides a web component that simplifies the process of adding donation functionality, allowing users to configure attributes like donation receiver details and minting options.</p></li></ul></li></ul><h4><strong>Software Releases &amp; Project Updates</strong></h4><ul><li><p>Core Lightning <a href="https://github.com/ElementsProject/lightning/releases/tag/v24.11.1">v24.11.1</a> - The lightning-dev Mailing List II</p><ul><li><p><code>xpay</code> compatibility improved significantly for <code>xpay-handle-pay:</code> the JSON return should be identical, and it handles maxfeepercent and exemptfee parameters.</p></li><li><p><code>xpay</code> results in <code>listpays</code> will include <code>destination</code> and <code>amount_msat</code> fields.</p></li><li><p><code>xpay</code> doesn&#8217;t spam the logs at INFO level any more</p></li><li><p><code>xpay</code> now works through unannounced channels</p></li></ul></li><li><p>Zeus <a href="https://github.com/ZeusLN/zeus/releases/tag/v0.9.4-rc1">v0.9.4-rc1</a></p><ul><li><p>Embedded Node: LND v0.18.4-beta</p></li><li><p>Speed up transaction UX improvements</p></li><li><p>CLNRest: fix display of destination addresses on TXs</p></li><li><p>Display keysend messages in Activity and Payment views</p></li><li><p>Open Channel view: UI tabs for Connect Peer</p></li><li><p>LND: optimize payment path calls after payments</p></li><li><p>CLNRest: add ability to paste connection strings</p></li><li><p>Channels: restore sort by Close Height</p></li><li><p>Networking improvements</p></li></ul></li><li><p>Ark <a href="https://github.com/ark-network/ark/releases/tag/v0.4.1">v0.4.1</a> - Support absolute locktime (CLTV)</p><ul><li><p>Patch release that adds supports for absolute locktimes encoded in the VTXO script with CLTV</p></li></ul></li><li><p>Fedimint <a href="https://github.com/fedimint/fedimint/releases/tag/v0.5.0">v0.5.0</a> - Christmas Edition</p><ul><li><p>Highlights:</p><ul><li><p>Add Tor support for client-federation connections</p></li><li><p>Stabilize v2 lightning module</p></li><li><p>Upgrade rust-bitcoin (and related ecosystem-crates) from 0.30 to 0.32</p></li><li><p>Improve CI to increase our agility while maintaining compatibility guarantees</p></li></ul></li></ul></li><li><p>Fedi App <a href="https://x.com/fedibtc/status/1867689651743731719">Update</a></p><ul><li><p>Cashu Melting: Spend eCash between CashuBTC and Fedimint</p></li><li><p>Portable Nostr Keys: Fedi generates an nPub for you and you can take this nPub with you</p></li></ul></li><li><p>Alby</p><ul><li><p>Alby-go <a href="https://github.com/getAlby/go/releases/tag/v1.8.1">v1.8.1</a></p><ul><li><p>Enhanced UI with popicons and new transaction icons</p></li><li><p>Verified ownership of Lightning addresses to avoid confusion</p></li><li><p>Support for nostr+walletconnect:// connection URLs</p></li><li><p>Show wallet name in payment confirmations and home screen</p></li><li><p>Simplified wallet renaming process</p></li></ul></li><li><p>Alby-hub</p><ul><li><p><a href="https://github.com/getAlby/hub/releases/tag/v1.12.0">v1.12.0</a> - Michael Froomkin</p><ul><li><p>Pay 0-amount invoices</p></li><li><p>Migrate to VSS</p></li><li><p>Fire channel open and closure events in lnd</p></li><li><p>Improve Alby Account connection card</p></li><li><p>Add environment variable to customize LDK listening addresses</p></li></ul></li><li><p><a href="https://github.com/getAlby/hub/releases/tag/v1.11.2">v1.11.2</a> - Suelette Dreyfus</p><ul><li><p>Implement a large number of improvements to the privacy of app connections:</p><ul><li><p>Relay connectivity</p></li><li><p>Backups</p></li><li><p>Open channel flows</p></li><li><p>Receive page</p></li><li><p>Isolated app connections</p></li><li><p>Transaction lists</p></li></ul></li></ul></li></ul></li></ul></li><li><p>BitBanana <a href="https://github.com/michaelWuensch/BitBanana/releases/tag/v0.8.8">v0.8.8</a></p><ul><li><p>Proper Android 14 support</p></li><li><p>Add Auto-Lock Timeout setting</p></li><li><p>Increase disconnect timeout after app moved to background to 5 min</p></li><li><p>Unlocking the app does no longer restart the connection</p></li><li><p>Migration Backup now includes app settings</p></li><li><p>Increase displayed lightning fee precision</p></li><li><p>Add explanation popup when enabling stealth mode</p></li><li><p>Add Tamil language</p></li></ul></li><li><p>Loop <a href="https://github.com/lightninglabs/loop/releases/tag/v0.29.0-beta">v0.29.0-beta</a></p><ul><li><p>Add support for persisting address loop in mode</p></li></ul></li></ul><h3><strong>Nostr</strong></h3><h4><strong>Project spotlight</strong></h4><ul><li><p><a href="https://pzp.wiki/">PZP</a>, a peer-to-peer protocol focused on enabling decentralized app development with lightweight storage requirements [<a href="https://codeberg.org/pzp">Code repository</a>]</p><ul><li><p>Key features include public-key addressing, content deletion, multi-device identity support, and easy CRDT data structures like sets and dicts.</p></li><li><p>PZP differs from Nostr by using device-specific keys, sig-chains to track missing content, and being invite-only.</p></li></ul></li><li><p>Narr: A self-hosted Nostr and RSS reader [<a href="https://github.com/fiatjaf/narr">Github</a>]</p><ul><li><p>&#8220;narr (not another rss reader) is a web-based RSS and Nostr long-form feed aggregator which can be used both as a desktop application and a personal self-hosted server.&#8221;</p></li></ul></li><li><p><a href="https://noflux.nostr.technology/">Noflux</a>: A minimalist and opinionated feed reader based on Miniflux. [<a href="https://github.com/fiatjaf/noflux">Github</a>]</p><ul><li><p>Noflux is a free and open-source Nostr and RSS feed reader optimized for readability, featuring fast navigation, no advertising or user tracking, and simple installation, while supporting Nostr NIP-23 feeds.</p></li></ul></li><li><p>Keycast: Secure remote signing and permissions for teams using Nostr. [<a href="https://github.com/erskingardner/keycast">Github</a>]</p><ul><li><p>Keycast is an open-source platform designed for secure remote signing and key management for teams using Nostr. It enables collaborative management of keys, setting policies, and managing permissions.</p></li></ul></li><li><p>Aegis Relay: A premium relay and blossom service that allows relay operators to earn income by providing relay services to the network. [<a href="https://github.com/bitvora/aegis">Github</a>]</p></li><li><p>Nostr Safebox: Your own private portable safebox on nostr [<a href="https://github.com/trbouma/safebox">Github</a>]</p><ul><li><p>Nostr Safebox acts as a personal, portable safebox for securely storing private information like wallets and records while using the Nostr network.</p></li><li><p>It uses NIP-44 encrypted events to store its index and contents securely. Access is granted via a unique nsec key, which can be user-generated or provided by a custodial service.</p></li></ul></li><li><p>nostr-nsec-seedphrase: A focused TypeScript library for Nostr key management and seedphrase functionality, with seamless integration with nostr-crypto-utils [<a href="https://github.com/HumanjavaEnterprises/nostr-nsec-seedphrase">Github</a>]</p><ul><li><p>This package is designed to convert between nsec keys and seed phrases, manage delegations, and support multiple key formats.</p></li></ul></li><li><p>Noscrypt: A nostr specific cryptography library written in C [<a href="https://github.com/VnUgE/noscrypt">Github</a>]</p><ul><li><p>&#8220;A high-level C utility library built specifically for nostr cryptography operations such as those defined in NIP-01 and the new NIP-44 (NIP-04 coming soon).</p></li><li><p>Noscrypt simplifies key generation, note signing &amp; verification, NIP-44 data encryption, NIP-44 private message encryption, and much more.&#8221;</p></li></ul></li><li><p><a href="https://immortal.dezh.tech/">Immortal</a>: A nostr relay designed for scale [<a href="https://github.com/dezh-tech/immortal">Github</a>]</p><ul><li><p>Immortal is a Nostr relay implementation written in Go, and designed for scalability and high performance. It is particularly suitable for large community or paid relays, rather than personal use.</p></li></ul></li><li><p><a href="https://lumilumi.app/">LumiLumi</a>: A lightweight web client for Nostr [<a href="https://github.com/TsukemonoGit/lumilumi">Github</a>]</p><ul><li><p>LumiLumi is a web-based client for the Nostr protocol. It supports image and URL sharing, custom emojis, and various muting features.</p></li><li><p>To accommodate users with limited data, LumiLumi offers settings to disable images, icons, and Open Graph Protocol (OGP) data, reducing communication costs. It also includes features like NIP-05 verification, relay configuration, and reaction settings.</p></li></ul></li><li><p><a href="https://lokuyow.github.io/nostr-zap-view/">nostr-zap-view</a>: View any nostr zaps from anywhere, supporting npub, nprofile, note, and nevent identifiers. [<a href="https://github.com/Lokuyow/nostr-zap-view">Github</a>]</p></li><li><p>Spring boot starter: Write Nostr applications with the Spring boot kit [<a href="https://github.com/theborakompanioni/nostr-spring-boot-starter">Github</a>]</p><ul><li><p>The project helps developers build Nostr applications, supports both custom relay software and client creation, and integrates with nostr-proto for core Nostr concepts.</p></li></ul></li><li><p><a href="https://bouquet.slidestr.net/">Bouquet</a>: A web tool to sync blobs between blossom servers. [<a href="https://git.v0l.io/florian/bouquet">Code repository</a>]</p></li><li><p><a href="https://csv-importer.coracle.social/">CVS Importer</a>: A Nostr Uploader. Publish events in bulk via CSV</p></li><li><p>Servus: A minimalist social media server [<a href="https://github.com/servus-social/servus">Github</a>]</p><ul><li><p>Servus is fully self-contained within one executable file: CMS, Personal Nostr relay, and Personal file server (Blossom &amp; NIP-96).</p></li></ul></li><li><p>Mostr: An immutable nested collaborative task manager, powered by nostr [<a href="https://github.com/xeruf/mostr">Github</a>]</p></li><li><p><a href="https://novia-web.vercel.app/">Novia</a> (NOstr VIdeo Archive): Manage video downloads on NOSTR [<a href="https://github.com/teamnovia/novia">Github</a>]</p><ul><li><p>A service that connects video archive tools to NOSTR. It supports video downloading, metadata management, and publishing video events on NOSTR relays while enabling decentralized video management and sharing.</p></li></ul></li><li><p><a href="https://memeamigo.lol/">Meme Amigo</a>: A companion app for <a href="https://gifbuddy.lol/">Gifbuddy.lol</a>, designed as a PWA for creating memes on the go. It allows users to easily add memes to notes on Nostr.</p><ul><li><p>Meme templates stored on relays under NIP94, generate @nostr.build URLs for easy sharing, add emojis, paste images, and meme GIFs on the same page.</p></li></ul></li><li><p>Awesome Nostr Bots: List of collected Bots on nostr [<a href="https://github.com/besoeasy/awesome-nostr-bots">Github</a>]</p><ul><li><p>A curated list of bots on Nostr with their descriptions and functionalities. These bots bring automation, insights, and updates to the Nostr network.</p></li></ul></li><li><p><a href="https://kehiy.github.io/persian-nostr-book/">Persian Nostr Book</a>: A nostr book written in Persian [<a href="https://github.com/kehiy/persian-nostr-book">Github</a>]</p></li></ul><h4><strong>Software Releases &amp; Project Updates</strong></h4><ul><li><p>Rust Nostr <a href="https://github.com/rust-nostr/nostr/blob/master/CHANGELOG.md#v0380---20241231">v0.38.0</a></p><ul><li><p>Add full NIP42 support for SDK and relay builder</p></li><li><p>Add negentropy support</p></li><li><p>Add read/write policy plugins for relay builder</p></li><li><p>Add NIP35 support</p></li><li><p>Improve logs, docs, and performance</p></li></ul></li><li><p>Primal Android</p><ul><li><p><a href="https://github.com/PrimalHQ/primal-android-app/releases/tag/2.0.34">v2.0.34</a></p><ul><li><p>Highlights in Reads</p></li><li><p>USD currency support in Wallet</p></li><li><p>Biometric prompt when accessing private key</p></li><li><p>Blossom support when rendering images in feeds</p></li><li><p>Rendering quoted articles, highlights and notes in note editor</p></li></ul></li><li><p><a href="https://github.com/PrimalHQ/primal-android-app/releases/tag/2.0.28">v2.0.28</a></p><ul><li><p>Implemented:</p><ul><li><p>Profile avatar and cover image viewer in profile details screen</p></li><li><p>Rendering highlights and generic events in feeds</p></li><li><p>Tap QR code to copy addresses on profile QR code viewer</p></li><li><p>Follow/unfollow approvals if contact list is not found</p></li><li><p>Onboarding follows customisation and zaps introductions</p></li><li><p>Premium badge on profile details screen</p></li><li><p>Support for primal legend avatars across the app</p></li><li><p>Primal premium check into profile editor</p></li></ul></li></ul></li></ul></li><li><p>Damus Testflight <a href="https://njump.me/nevent1qqspztcwj2g7agygr964ey8s8x2fu2r6udtsh2cp3rphr44upz7zsdspp4mhxue69uhkummn9ekx7mqzyql0mt4mrkyj867enj084n3mgx22k3239c4708qm045djfp7p5ngzc2pscz">v1.12</a></p><ul><li><p>Render Gif and video files while composing posts</p></li><li><p>Add profile info text in stretchable banner with follow button</p></li><li><p>Paste Gif image similar to jpeg and png files</p></li><li><p>Improve UX around the label for searching words</p></li><li><p>Improve accessibility support on some elements</p></li></ul></li><li><p>YakiHonne web <a href="https://njump.me/nevent1qqsptst7se8wn9cv9vv7a7syqswxdjyaarhlls4hgyztgf2d4my2qsqpp4mhxue69uhkummn9ekx7mqpzemhxue69uhhyetvv9ujumn0wd68ytnzv9hxgqg5waehxw309aex2mrp0yhxgctdw4eju6t0qgszpxr0hql8whvk6xyv5hya7yxwd4snur4hu4mg5rctz2ehekkzrvcdxl2ty">Update</a></p><ul><li><p>Resolve issues causing the article editor to appear malformed</p></li><li><p>Add support for both LTR and RTL languages in the article editor</p></li><li><p>Enhance the messaging box to support long text writing</p></li><li><p>Secure DMs (Nip44) can now be enabled globally via the messages and settings pages</p></li></ul></li><li><p>Flotilla <a href="https://github.com/coracle-social/flotilla/releases/tag/0.2.0">v0.2.0</a></p><ul><li><p>Add NIP 29 compatibility</p></li></ul></li><li><p>CDK <a href="https://github.com/cashubtc/cdk/releases/tag/v0.6.0">v0.6.0</a></p><ul><li><p>Changed:</p><ul><li><p>cdk: Enforce quote_id to uuid type in mint</p></li><li><p>cdk: Refactor wallet mint connector</p></li></ul></li><li><p>Added:</p><ul><li><p>cdk: NUT19 Settings in NUT06 info</p></li><li><p>cdk: NUT17 Websocket support for wallet</p></li><li><p>cdk-axum: Redis cache backend</p></li><li><p>cdk-mints: Get mint settings from env vars</p></li><li><p>cdk-axum: HTTP compression support</p></li></ul></li></ul></li><li><p>Knox <a href="https://gitlab.com/soapbox-pub/knox/-/commit/dbdffb32fe8a9555b80f16ca9bbf4f15813a9c65">Update</a></p><ul><li><p>Switch to NIP-44 encryption</p></li></ul></li><li><p>Gossip <a href="https://github.com/mikedilger/gossip/releases/tag/v0.13.0">v0.13.0</a></p><ul><li><p>File Metadata support (NIP-92 / NIP-94)</p></li><li><p>Blossom support (BUD-01, BUD-02)</p></li><li><p>NIP-89 Support - Recommended Application Handlers</p></li><li><p>Search on relays (NIP-50): choose your search relays first</p></li><li><p>Followers and Followed: see who someone follows, and who follows them</p></li><li><p>Undo Send - for 10 seconds (or whatever you configure) you can undo sending</p></li><li><p>Thread replies now sorted by date, except author replies come first</p></li><li><p>Feeds no longer inject new events and scroll while you are trying to read.</p></li><li><p>Relays can now be tested to see whether they are fit for purpose</p></li><li><p>NIP-46 replies with NIP-44 encryption if the client used it</p></li><li><p>NIP-44 encryption now used for private contacts and private lists</p></li></ul></li><li><p>Nostrudel <a href="https://github.com/hzrd149/nostrudel/releases/tag/v0.42.0">v0.42.0</a></p><ul><li><p>Add support for olas media posts and NIP-22 comments</p></li><li><p>Add tools menu under thread post</p></li><li><p>Add favorite DVM feeds</p></li><li><p>Add templates to event publisher</p></li><li><p>Update timelines to use applesauce</p></li><li><p>Add open and share button to stream view</p></li><li><p>Add &#8220;Proactively authenticate to relays&#8221; option to privacy settings, defaults to off</p></li><li><p>Support searching local relay</p></li><li><p>Add support for cashu v4 tokens</p></li></ul></li><li><p>0xChat App Desktop <a href="https://github.com/0xchat-app/0xchat-app-main/releases/tag/v1.0.0-desktop-beta">v1.0.0</a></p><ul><li><p>The first desktop beta version supports macOS, Linux, and Windows</p></li><li><p>Future plans:</p><ul><li><p>Support NIP-46 login</p></li><li><p>Optimize the UI &amp; UX for the desktop version</p></li><li><p>Improve the performance of the desktop version</p></li></ul></li></ul></li><li><p>nos.social <a href="https://github.com/planetary-social/nos/releases/tag/vstaging-1.0.4-564">v1.0.4</a></p><ul><li><p>Add feed picker view (UI only)</p></li><li><p>Add feed source customizer drop-down view</p></li><li><p>Add empty state for lists/relays drop-down</p></li><li><p>Add support for decrypting private tags in kind 30000 lists</p></li><li><p>Add remembering which feed source is selected</p></li></ul></li><li><p>Citrine <a href="https://github.com/greenart7c3/Citrine/releases/tag/v0.6.0">v0.6.0</a></p><ul><li><p>Show notifications when importing, exporting, downloading events</p></li><li><p>Change database functions to be suspending functions</p></li><li><p>Update dependencies</p></li></ul></li><li><p>Honeypot <a href="https://github.com/pablof7z/nutsack/releases/tag/0.1.0">v0.1.0</a></p><ul><li><p>Improve onboarding flow</p></li></ul></li><li><p>Nowser <a href="https://github.com/haorendashu/nowser/releases/tag/0.0.3">v0.0.3</a></p><ul><li><p>Add build-in relay for remote signer</p></li><li><p>Bookmarks support add to app index</p></li><li><p>Bookmarks support quick action for mobile</p></li><li><p>Bookmarks support add to desktop for android</p></li><li><p>Reject private zap decrypt request from amethyst</p></li></ul></li><li><p>Haven <a href="https://github.com/bitvora/haven/releases/tag/v1.0.3">v1.0.3</a></p><ul><li><p>Add support for count events</p></li><li><p>Remove dynamic relay handler</p></li><li><p>Feature/blossom http range requests</p></li></ul></li><li><p>Pokey <a href="https://github.com/KoalaSat/pokey/releases/tag/v0.1.3-alpha">v0.1.3</a></p><ul><li><p>Add notifications center</p></li><li><p>Views rearrangement</p></li></ul></li><li><p>Amber <a href="https://github.com/greenart7c3/Amber/releases/tag/v3.0.3">v3.0.3</a></p><ul><li><p>Better pin entry screen</p></li><li><p>Add a close application config in the ui</p></li><li><p>Separate the service notification in a group</p></li><li><p>Always return a hex key for the get_public_key method</p></li></ul></li><li><p>Openvibe <a href="https://njump.me/nevent1qqsvxx27vff8xxqkurlter7wjest3ydw3tvdzlc5gvauulfp3selp2sppamhxue69uhkummnw3ezumt0d5pzqrlqkx95m0cwp2jqln28yzdj5jdngv0ug5a5vrhu73w2p0gkh44vheqdf2">v1.5.0</a></p><ul><li><p>Multiple profiles: add multiple accounts from the same network (e.g., Mastodon or Bluesky) and organize them into sets like personal or work.</p></li></ul></li></ul><h3><strong>Boosts</strong></h3><ul><li><p>01:13:47 Thanks to everyone who streamed sats, and shoutout to our top boosters:</p></li><li><p>[&#127942; TOP BOOSTER] @Ape Mithrandir (17,777 sats) &#8220;(Craig Raw)&#8217;s feature request for Broadcast Pool is much needed and we should get more eyes on it. [<a href="https://github.com/bitcoin/bitcoin/issues/30471">Feature request</a>]&#8221;</p></li><li><p>@Ape Mithrandir (7,777 sats) &#8220;Epic rant at the end. Craig Raw always worth listening to.&#8221;</p></li><li><p>@shadowysuperbadger (1,000 sats) &#8220;Cool episode. Thanks for putting it together.&#8221;</p><ul><li><p>@user40113771 (1,000 sats) &#8220;&#128591;&#8221;</p></li><li><p>@user40113771 (500 sats) &#8220;&#128293;&#128293;&#128591;&#128293;&#128293;&#8221;</p></li><li><p>@btconboard (300 sats) &#8220;SO MUCH WINNING &#129761;&#129761;&#8221;</p></li><li><p>@Leurico8 (100 sats) &#8220;Fucking epic episode&#8221;</p></li><li><p>@Juan &#8220;May need to find a new sleep therapy solution as I made it thru this whole episode, on a night-flight. great rip guys, learned a lot. happy thanksgiving ;)&#8221;</p></li></ul></li></ul><h3><strong>Bitcoin Optech Newsletter</strong></h3><ul><li><p>Highlights from recent Bitcoin Optech Newsletters</p><ul><li><p><a href="https://bitcoinops.org/en/newsletters/2024/12/20/">334</a></p><ul><li><p>2024 Year-in-Review Special: The seventh annual Bitcoin Optech Year-in-Review special summarizes notable developments in Bitcoin during all of 2024</p></li></ul></li><li><p><a href="https://bitcoinops.org/en/newsletters/2024/12/13/">333</a></p><ul><li><p>Vulnerability allowing theft from LN channels with miner assistance: David Harding <a href="https://delvingbitcoin.org/t/disclosure-irrevocable-fees-stealing-from-ln-using-revoked-commitment-transactions/1314">announced</a> to Delving Bitcoin a vulnerability he had responsibly disclosed earlier in the year.</p></li><li><p>Deanonymization vulnerability affecting Wasabi and related software: a developer of GingerWallet <a href="https://github.com/GingerPrivacy/GingerWallet/discussions/116">disclosed</a> a method a coinjoin coordinator could use to prevent users from gaining any privacy during a coinjoin.</p></li><li><p>Insights into channel depletion: Ren&#233; Pickhardt <a href="https://delvingbitcoin.org/t/channel-depletion-ln-topology-cycles-and-rational-behavior-of-nodes/1259/6">posted</a> to Delving Bitcoin and participated, along with Christian Decker, in an Optech Deep Dive about his research into the mathematical foundations of payment channel networks (namely LN).</p></li><li><p>Poll of opinions about covenant proposals: /dev/fd0 <a href="https://gnusha.org/pi/bitcoindev/028c0197-5c45-4929-83a9-cfe7c87d17f4n@googlegroups.com/">posted</a> to the Bitcoin-Dev mailing list a link to a public poll of developer opinions about selected covenant proposals.</p></li><li><p>Incentive-based pseudo-covenants: Jeremy Rubin <a href="https://gnusha.org/pi/bitcoindev/30440182-3d70-48c5-a01d-fad3c1e8048en@googlegroups.com/">posted</a> to the Bitcoin-Dev mailing list a link to a <a href="https://rubin.io/public/pdfs/unfedcovenants.pdf">paper</a> he authored about oracle-assisted covenants.</p></li><li><p>Bitcoin Core developer meeting summaries: many Bitcoin Core developers met in person in October, and several notes from the meeting have now been <a href="https://btctranscripts.com/bitcoin-core-dev-tech/2024-10">published</a>.</p></li></ul></li></ul></li></ul><h3><strong>News &amp; Noteworthy</strong></h3><h4><strong>Bitcoin</strong></h4><ul><li><p>pqcBitcoin: A Post-Quantum Cryptography (PQC)-enhanced fork of Bitcoin [<a href="https://github.com/QBlockQ/pqc-bitcoin">Github</a>]</p><ul><li><p>pqcBitcoin is a fork of Bitcoin Core that integrates post-quantum cryptography (PQC) algorithms, such as Kyber, FrodoKEM, and NTRU, to address potential future threats from quantum computing. The developers have proposed this feature to the Bitcoin community for review and consensus.</p></li></ul></li><li><p><a href="https://timechainindex.com/">Timechainindex</a> is shutting down on January 10, 2025 after one year of operation. [<a href="https://x.com/SaniExp/status/1871935742194147418">Announcement</a>]</p><ul><li><p>Timechainindex is a platform that tracks Bitcoin holdings across exchanges, funds, ETFs, and companies, offering real-time data and insights into Bitcoin&#8217;s market distribution.</p></li></ul></li></ul><h4><strong>Lightning + L2+</strong></h4><ul><li><p><a href="https://diamondhands.technology/">Diamond Hands</a>, Japan-based Bitcoin community and organization, announces the closure of the DH Node, a Lightning node which has been operational since June 2021, citing challenges in maintaining large-scale routing operations [<a href="https://diamondhandsen.substack.com/p/closure-of-the-dh-node-routing-node">Announcement</a>]</p></li></ul><h4><strong>Nostr</strong></h4><ul><li><p>Orange Pill App integrates nostr login [<a href="https://x.com/orangepillapp/status/1870235577557127614">Announcement</a>]</p></li></ul><h4><strong>Business &amp; Finance</strong></h4><ul><li><p><a href="https://seedhammer.com/">SeedHammer</a> announces SeedHammer II: A smaller, lighter and more secure machine than the original off-the-shelf product, with an integrated controller. [<a href="https://njump.me/nevent1qqsq5dlje82pascfefn7gmrfntk75c3htzrs6meeh69g9553qm337lqpzemhxue69uhhyetvv9ujumn0wd68ytnzv9hxgqgdwaehxw309ahx7uewd3hkcq3qz072s0nvldeva7a6qek3kj358f0h5gm640kkllkk52h0qrjtnw8q6nflx2">Announcement</a>]</p></li><li><p>Canadian broker Bull Bitcoin officially launches in Europe with a brand-new platform [<a href="https://www.bullbitcoin.com/blog/the-bull-returns-to-europe">Announcement</a>]</p></li><li><p>Casa implements deepfake-resistant verification codes to enhance security for Premium, Enterprise, and Private clients [<a href="https://blog.casa.io/deepfake-resistant-verification-codes/">Blog post</a>]</p><ul><li><p>The system uses shared cryptographic keys to generate matching codes, protecting against impersonation during live support interactions.</p></li></ul></li><li><p>Unchained improves its Connections feature, allowing collaborate on key security without revealing vault details, maintaining control over shared information. [<a href="https://updates.unchained.com/en/unchained-connections-is-now-more-flexible-and-private-p1GwKupF">Announcement</a>]</p></li><li><p>Strike now enables USDT deposits and withdrawals for customers in 17+ countries. [<a href="https://x.com/Strike/status/1869453111095660812">Announcement</a>]</p></li><li><p>Strike adopts Travel Rule regulation [<a href="https://strike.me/faq/what-is-the-travel-rule-regulation/">Explainer</a>]</p><ul><li><p>The Travel Rule, established by the Financial Action Task Force (FATF), requires financial institutions to collect and share information about the originators and beneficiaries of financial transfers. In the EU, this is implemented through the Transfer of Funds Regulation (TFR).</p></li><li><p>For users in the EU or UK, sending or receiving Bitcoin via crypto-asset service providers will require sharing personal information such as name, address, and identification details.</p></li></ul></li><li><p>Digital Currency Group divides Foundry&#8217;s mining business into two separate entities. Fortitude Mining will oversee Foundry&#8217;s former self-mining operations and physical infrastructure, while Foundry will retain its pool operations and other Bitcoin mining services [<a href="https://blockspace.media/insight/dcg-creates-new-company-fortitude-from-foundrys-self-mining-business/">Blockspace</a>]</p></li></ul><h4><strong>Encryption</strong></h4><ul><li><p>01:16:45 NIST proposes to standardize wider variant of AES [<a href="https://csrc.nist.gov/News/2024/nist-proposes-to-standardize-wider-variant-of-aes">Proposal</a>]</p><ul><li><p>NIST is considering a new version of Rijndael with 256-bit blocks, driven by the need for larger block sizes due to increased data processing demands.</p></li></ul></li></ul><h4><strong>Funding</strong></h4><ul><li><p>01:17:40 OpenSats <a href="https://opensats.org/blog/9th-wave-of-nostr-grants">announces</a> its Ninth Wave of Nostr Grants, supporting five innovative projects that advance and strengthen the nostr ecosystem:</p><ul><li><p>AlgoRelay</p></li><li><p>Pokey</p></li><li><p>Nostr Safebox</p></li><li><p>Persian NIPs</p></li><li><p>LumiLumi</p></li></ul></li><li><p>01:17:47 Spiral renews its grant to BTCPayServer [<a href="https://x.com/spiralbtc/status/1869816695273205844">Announcement</a>]</p></li><li><p>01:17:49 The Human Rights Foundation donates 7 bitcoin to fund Bitcoin development and projects: [<a href="https://bitcoinmagazine.com/business/human-rights-foundation-donates-700000000-satoshis-to-fund-bitcoin-development-and-projects">Bitcoin Magazine</a>]</p><ul><li><p>Stratum V2 Reference Implementation (SRI), Public Pool, Naiyoma, Daniela Brozzoni, Michael Haase, No Bullshit Bitcoin, Tando, YakiHonne, SeedSigner Multi-language Support, Vexl, Tomatech, Krux, Iris, African UX Bitcoin Bootcamp, Bitcoin History, Cashu-ts, Unify, The Financial Freedom Policy Coalition, Jon Atack and Brink.</p></li></ul></li><li><p>01:17:53 Btrust <a href="https://blog.btrust.tech/announcing-the-q4-2024-btrust-grant-recipients/">announces</a> its Q4 2024 Btrust grant recipients: Abdullahi Yunus Ahmed, Enigbe Ochekliye, and Tobechi Chukwuleta</p></li><li><p>Chaincode Labs awards its inaugural Bitcoin Scholarship to 17-year-old Ishaana Misra, the youngest Bitcoin Core contributor. The scholarship covers one year of academic expenses and is renewable for her undergraduate education. [<a href="https://bitcoinmagazine.com/press-releases/youngest-ever-bitcoin-core-contributor-gets-bitcoin-scholarship">Bitcoin Magazine</a>]</p></li><li><p>Relai secures $12 million in a Series A funding round led by Ego Death Capital, bringing its valuation to $72 million. [<a href="https://www.theblock.co/post/330146/bitcoin-investment-app-relai-funding-valuation">The Block</a>]</p></li><li><p>Lava raises $10 million in a Series A funding round led by Khosla Ventures and Founders Fund. The Bitcoin lending platform plans to expand its offerings, including Bitcoin purchasing and payment services. [<a href="https://fortune.com/2024/12/09/bitcoin-lending-lava-khosla-keith-rabois-founders-fund-venture/">Forbes</a>]</p></li></ul><h4><strong>Mining</strong></h4><ul><li><p>01:18:12 GreenpeaceUSA&#8217;s &#8216;Change the Code&#8217; campaign, aiming to modify Bitcoin&#8217;s energy-intensive proof-of-work system, likely shut down [<a href="https://www.batcoinz.com/p/anti-bitcoinchange-the-code-campaign">Batcoinz&#8217; blog post</a>]</p><ul><li><p>The campaign has been inactive since January 2024 and its former campaign director has since departed GreenpeaceUSA to join another organization.</p></li></ul></li><li><p>Cango Inc., a Chinese automotive services firm listed on the NYSE, purchases 32 EH/s of Antminer ASICs from Bitmain for $256 million, securing approximately 4% of Bitcoin&#8217;s network hashrate. [<a href="https://blockspace.media/insight/chinese-car-company-cango-emerges-as-third-largest-public-miner/">Blockspace</a>]</p><ul><li><p>An additional 18 EH/s acquisition is under contract with Golden TechGen Limited, owned by former Bitmain CFO Max Hua, elevating Cango&#8217;s total hashrate to 50 EH/s, comparable to leading miners like Marathon Digital Holdings.</p></li></ul></li><li><p>Foundry USA refunds overpaid Bitcoin transaction fee [<a href="https://x.com/FoundryServices/status/1872629580487426221">Twitter post</a>]</p><ul><li><p>Foundry USA Pool mined block 875475 on December 19, which included a transaction with an 8.18 BTC overpaid fee, which was 91,127 times higher than necessary.</p></li></ul></li><li><p>MicroBT introduces WhatsMiner M6XS++ series with a hashrate of 218 TH/s and 15.5 J/TH efficiency, including air-cooled, hydro-cooled, and immersion-cooled models [<a href="https://theminermag.com/news/2024-12-09/bitcoin-whatsminer-15-efficiency/">The Miner Mag</a>]</p></li><li><p>Russia enacts six-year bitcoin mining ban to both individual and pool mining activities, across multiple regions [<a href="https://www.coindesk.com/policy/2024/12/24/russia-imposes-6-year-ban-on-crypto-mining-in-10-regions-citing-energy-use-tass">CoinDesk</a>]</p><ul><li><p>Partial restrictions will also affect three Siberian regions from November to March each year, aligning with high energy demands.</p></li></ul></li><li><p><a href="https://e4pool.com/">e4pool</a>, an open source mining pool, is closing due to new mining regulations in Russia. [<a href="https://x.com/e4pool_com/status/1868264596743827827">Announcement</a>]</p><ul><li><p>Reasons cited are that mining pools now must register in a special list of mining operators, and provide user data to the tax office.</p></li></ul></li></ul><h4><strong>Privacy</strong></h4><ul><li><p>Byte Federal, a U.S.-based Bitcoin ATM operator, reports a data breach compromising personal information of approximately 58,000 customers [<a href="https://techcrunch.com/2024/12/12/bitcoin-atm-giant-byte-federal-says-58000-users-personal-data-compromised-in-breach/">TechCrunch</a>]</p><ul><li><p>The breach, discovered on November 18, resulted from a vulnerability in third-party software, specifically a bug in the GitLab developer platform.</p></li><li><p>Exposed data includes names, birthdates, addresses, phone numbers, email addresses, government-issued IDs, social security numbers, transaction activity, and user photographs. [<a href="https://www.bytefederal.com/files/Consumer%20Breach%20Notification%20Letter.pdf">Notice of data breach</a>]</p></li></ul></li><li><p>Privacy and security focused open-source mobile operating system, DivestOS, announces the end of its mobile updates in December after 10 years. [<a href="https://divestos.org/pages/news#end">Announcement</a>]</p></li><li><p>NSO Group found liable for spyware attacks on WhatsApp users [<a href="https://www.infosecurity-magazine.com/news/spyware-maker-nso-group-whatsapp/">Infosecurity Magazine</a>]</p><ul><li><p>A U.S. court ruled NSO Group liable for using zero-day exploits to deploy its Pegasus spyware on at least 1400 WhatsApp devices. The attack targeted journalists, activists, and government officials, violating both state and federal laws.</p></li></ul></li><li><p>NoviSpy: Serbian authorities deploy NoviSpy spyware and Cellebrite forensic tools to surveil journalists and activists [<a href="https://securitylab.amnesty.org/latest/2024/12/serbia-a-digital-prison-spyware-and-cellebrite-used-on-journalists-and-activists/">Security Lab&#8217;s report</a>]</p><ul><li><p>NoviSpy captures personal data and can remotely activate microphones or cameras on targeted devices</p></li><li><p>Cellebrite is used to unlock phones, facilitating the installation of NoviSpy during police interviews</p></li></ul></li><li><p>01:18:29 Samourai Wallet pretrial hearing postponed to March 12, 2025, due to additional discovery batches, with the trial now set for November 3, 2025. [<a href="https://www.therage.co/samourai-wallet-trial-set-for-november-3-2025/">The Rage</a>]</p><ul><li><p>The U.S. government is reviewing data from 45 devices seized from developers, with over half of the total 17 TB of data already shared.</p></li></ul></li><li><p>01:19:59 Russian government directs ISPs to identify users accessing blocked content via VPNs [<a href="https://cyberinsider.com/russian-government-orders-isps-to-hand-over-names-of-vpn-users/">CyberInsider</a>]</p><ul><li><p>ISPs must implement Technical Means of Countering Threats (TSPU) to monitor user traffic and report in real-time.</p></li></ul></li></ul><h4><strong>Security</strong></h4><ul><li><p>Cryptocurrency thefts rise in 2024, according to a <a href="https://www.chainalysis.com/blog/crypto-hacking-stolen-funds-2025/">Chainalysis&#8217; report</a></p><ul><li><p>In 2024, digital currency platform theft reached $2.2 billion, a ~21% increase from 2023. These attacks increased in both frequency and size, signaling a growing threat.</p></li><li><p>A shift in targets was observed in 2024, with centralized services becoming more vulnerable, particularly to private key exploits.</p></li></ul></li><li><p>FBI, DC3, and Japan&#8217;s NPA alert the public to TraderTraitor, a North Korean cyber group responsible for a $308M cryptocurrency theft in May 2024. The group targeted Japan-based Bitcoin.DMM.com using sophisticated social engineering tactics. [<a href="https://www.fbi.gov/news/press-releases/fbi-dc3-and-npa-identification-of-north-korean-cyber-actors-tracked-as-tradertraitor-responsible-for-theft-of-308-million-from-bitcoindmmcom">FBI&#8217;s Press release</a>]</p></li></ul><h4><strong>Protocol</strong></h4><ul><li><p>Bitcoin Core #31096: Package validation: accept packages of size 1. This change relaxes the RPC checks as enables the AcceptPackage flow to accept packages of a single transaction. [<a href="https://github.com/bitcoin/bitcoin/pull/31096">Merged</a>]</p></li><li><p>Bitcoin Core #31112: Improve parallel script validation error debug logging [<a href="https://github.com/bitcoin/bitcoin/pull/31112">Merged</a>]</p></li><li><p>Bitcoin Core #31175: rpc: Remove submitblock pre-checks [<a href="https://github.com/bitcoin/bitcoin/pull/31175">Merged</a>]</p></li><li><p>BIPS #1535: BIP&#8239;348: OP_CHECKSIGFROMSTACK [<a href="https://github.com/bitcoin/bips/pull/1535">Merged</a>]</p></li><li><p>BTCPayServer #5743: Multisig/watchonly wallet transaction creation flow proof of concept [<a href="https://github.com/btcpayserver/btcpayserver/pull/5743">Merged</a>]</p></li><li><p>LDK #3446: Support Trampoline flag in BOLT12 invoices [<a href="https://github.com/lightningdevkit/rust-lightning/pull/3446">Merged</a>]</p></li><li><p>BOLTs #1180: Include BIP 353 name info in <code>invoice_requests</code>. Update BOLT12 to allow optional inclusion of BIP353 human-readable Bitcoin payment instructions in invoice requests. [<a href="https://github.com/lightning/bolts/pull/1180">Merged</a>]</p></li><li><p>NUT-20 &#8211; Signature on Mint Quote: an optional specification that locks a mint quote to a user-defined public key and requires a valid signature for minting. [<a href="https://x.com/CashuBTC/status/1872019631646601300">Merged</a>]</p></li></ul><h4><strong>Government &amp; Political</strong></h4><ul><li><p>01:20:14 Craig Wright is handed a one-year suspended sentence in the UK for contempt of court after violating an earlier ruling. The judge confirmed Wright continued his legal action against Bitcoin developers, despite a ban on such claims. [<a href="https://www.reuters.com/markets/currencies/self-proclaimed-bitcoin-inventor-contempt-court-over-12-trillion-uk-lawsuit-2024-12-19/">Reuters</a>]</p><ul><li><p>The court also ordered Wright to drop his $1.15 trillion lawsuit against Square and Bitcoin developers.</p></li></ul></li><li><p>El Salvador agrees to scale back Bitcoin policies to secure $1.4 billion IMF loan [<a href="https://www.bloomberg.com/news/articles/2024-12-18/imf-reaches-agreement-with-el-salvador-for-1-4-billion-loan">Bloomberg</a>] [<a href="https://www.imf.org/en/News/Articles/2024/12/18/pr-24485-el-salvador-imf-reaches-staff-level-agreement-on-an-eff-arrangement">IMF Press release</a>]</p><ul><li><p>The government will make Bitcoin acceptance voluntary for the private sector and limit public sector involvement in Bitcoin-related activities.</p></li><li><p>The Chivo wallet will be gradually phased out, and taxes will be payable exclusively in U.S. dollars.</p></li></ul></li><li><p>Russian companies embrace bitcoin in international payments to bypass sanctions, following legislative changes aimed at countering Western sanctions. [<a href="https://www.reuters.com/markets/currencies/russia-is-using-bitcoin-foreign-trade-finance-minister-says-2024-12-25/">Reuters</a>]</p><ul><li><p>Finance Minister Anton Siluanov confirmed that cryptocurrencies, including bitcoin, are being used in foreign trade and are expected to expand in 2025.</p></li></ul></li><li><p>EU-regulated exchange updates on digital currencies deposits and withdrawals exceeding &#8364;1,000 in value. [<a href="https://stacker.news/items/827547">Stacker News post</a>]</p><ul><li><p>Starting December 30, 2024, deposits and withdrawals in select European countries will require additional verification, users must now verify their private wallets.</p></li></ul></li><li><p>The European Securities and Markets Authority (ESMA) releases the final set of regulatory technical standards and guidelines, facilitating the full implementation of the Markets in Crypto Assets Regulation (MiCA). [<a href="https://www.esma.europa.eu/press-news/esma-news/esma-releases-last-policy-documents-get-ready-mica">Press release</a>]</p><ul><li><p>The regulation requires crypto service providers to obtain licenses, adhere to organizational standards, and implement robust governance measures to ensure consumer protection and market integrity.</p></li></ul></li><li><p>Financial Accounting Standards Board (FASB) approves new standard requiring Bitcoin to be valued at fair value for fiscal years starting after December 15, 2024. [<a href="https://archive.ph/0q2VG">FASB Media Advisory</a>]</p><ul><li><p>This change aims to simplify accounting processes, reduce complexity, and provide more relevant information to investors about digital asset holdings, including Bitcoin. It mandates disclosures about significant holdings and changes during reporting periods.</p></li></ul></li><li><p>The IRS finalizes two regulations affecting digital asset users and developers: a KYC dealer-broker rule for DeFi front-ends and IRS Safe Harbor Transitional Relief. [<a href="https://www.therage.co/the-biden-irss-two-pronged-2/">The Rage</a>]</p><ul><li><p>The KYC dealer-broker rule, effective by 2027, may require noncustodial services to implement KYC/AML measures.</p></li><li><p><a href="https://theblockchainassociation.org/industry-groups-sue-over-finalized-irs-broker-rulemaking/">Update</a>: Industry groups, including the Blockchain Association and DeFi Education Fund, are suing the IRS over new KYC requirements for &#8220;DeFi front-end services&#8221;.</p></li></ul></li><li><p>Early bitcoin investor receives a two-year prison sentence for underreporting capital gains on $3.7 million in bitcoin sales [<a href="https://bitcoinmagazine.com/legal/early-bitcoin-investor-sentenced-to-prison-for-tax-evasion-on-3-7-million-btc-sale">Bitcoin Magazine</a>]</p><ul><li><p>He reportedly misled his accountant about purchase prices and concealed additional profits using mixers and cash exchanges. This case is noted as the first criminal tax evasion prosecution centered exclusively on cryptocurrency.</p></li></ul></li><li><p>The Bank of Italy identifies platforms facilitating Bitcoin transactions without user identification as &#8220;crime-as-a-service,&#8221; citing the website kycnot.me, which lists P2P platforms operating without KYC checks. [<a href="https://atlas21.com/bank-of-italy-p2p-services-are-criminal/">Atlas21</a>]</p><ul><li><p>The institution highlights that money launderers exploit pseudonymity in cryptocurrency transactions to conceal illicit funds, using methods like mixers, tumblers, chain-hopping, and anonymous wallets to evade detection.</p></li></ul></li></ul><h4><strong>Events</strong></h4><ul><li><p><a href="https://denver.space/heatpunk_summit">Undermine Heatpunk Summit</a>: The first Bitcoin Heat Reuse conference</p><ul><li><p>February 21-22, 2025 in Denver, United States</p></li></ul></li><li><p><a href="https://btcpp.dev/conf/floripa">bitcoin++ Florianopolis</a>: bitcoin++ is hacking at the beach</p><ul><li><p>February 19-22, 2025 in Florianopolis, Brasil</p></li></ul></li></ul><h3><strong>Reads</strong></h3><ul><li><p>Here&#8217;s a list of our top recently published reads:</p><ul><li><p>Choosing a hash function for 2030 and beyond: SHA2 vs SHA3 vs BLAKE3, by Sylvain Kerkour [<a href="https://kerkour.com/fast-secure-hash-function-sha256-sha512-sha3-blake3">Blog post</a>]</p></li><li><p>OpenSats&#8217; 2024 Year in Review [<a href="https://opensats.org/blog/2024-year-in-review">Blog post</a>]</p></li><li><p>Stone Ridge 2024 Investor Letter, by Ross Stevens [<a href="https://www.nydig.com/research/stone-ridge-2024-investor-letter">NYDIG</a>]</p></li><li><p>The DOJ&#8217;s Dangerous New Legal Theory: Implications for Samourai Wallet and Bitcoin Self-Custody, by Bitcoin Policy Institute [<a href="https://www.btcpolicy.org/articles/the-dojs-dangerous-new-legal-theory-implications-for-samourai-wallet-and-bitcoin-self-custody">Policy brief</a>]</p></li><li><p>Can Nostr fix app distribution? by @franzap [<a href="https://zapstore.dev/blog/nostr-app-distribution/">Blog post</a>]</p></li><li><p>P2QRH/QuBit chain growth rate calculations: An evaluation of the number of P2QRH transactions that can fit in a block under various attestation discount scenarios. [<a href="https://x.com/cryptoquick/status/1866986505434264047">Analysis</a>]</p></li></ul></li></ul><h3><strong>Episode submission ideas</strong></h3><ul><li><p>We&#8217;re looking for ideas for interesting panel conversations. To send Bitcoin related questions, just go to <a href="https://bitcoin.review/">bitcoin.review</a> and follow the contact links at the bottom of the page.</p></li></ul><h3><strong>Get in touch with the pod</strong></h3><ul><li><p><a href="https://twitter.com/bitcoinreviewhq">Podcast Twitter</a></p></li><li><p><a href="https://twitter.com/nvk">NVK Twitter</a></p></li><li><p><a href="https://t.me/BitcoinReviewPod">Telegram</a></p></li><li><p><a href="mailto:producer@coinkite.com">Email</a></p></li><li><p>Nostr &amp; LN &#9889;nvk@nvk.org (not an email!)</p></li></ul>]]></content:encoded></item><item><title><![CDATA[BR089 - Lark, Security Tradeoffs Masterclass, Bitcoin Quantum Risks, WabiSabi Deanonymization, Core Txn Broadcast, Better Wallet Migration, Scaling Bitcoin, Bullish Sentiments + MORE ft. Craig & Rob]]></title><description><![CDATA[I&#8217;m joined by guests Craig Raw and Rob Hamilton to go through the list.]]></description><link>https://substack.bitcoin.review/p/br089-lark-security-tradeoffs-masterclass</link><guid isPermaLink="false">https://substack.bitcoin.review/p/br089-lark-security-tradeoffs-masterclass</guid><dc:creator><![CDATA[STACK TO THE FUTURE]]></dc:creator><pubDate>Fri, 13 Dec 2024 22:04:09 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a95ac75-ac77-4167-9383-9930a48690bb_1080x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I&#8217;m joined by guests <a href="https://twitter.com/craigraw">Craig Raw</a> and <a href="https://twitter.com/Rob1Ham">Rob Hamilton</a> to go through the list.</p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://bitcoin.review/podcast/episode-56/&quot;,&quot;text&quot;:&quot;Listen on your favorite podcast app&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://bitcoin.review/podcast/episode-56/"><span>Listen on your favorite podcast app</span></a></p><div><hr></div><h3><strong>Urgent Vulnerability Disclosures</strong></h3><ul><li><p>00:01:18 Full Disclosure: Transaction-Relay Throughput Overflow Attacks against Off-Chain Protocols [<a href="https://groups.google.com/g/bitcoindev/c/GuS36ldye7s/m/4zHfQGj9AQAJ">Antoine Riard&#8217;s post</a>]</p><ul><li><p>A new transaction-relay jamming attack targets off-chain protocols, exploiting throughput limits in full-node algorithms.</p></li><li><p>The &#8220;high-overflow&#8221; variant exploits the sender-side fee-rate sorting algorithm. The &#8220;low-overflow&#8221; variant targets receiver-side processing limits but remains untested.</p></li></ul></li><li><p>00:01:53 Vulnerability in WabiSabi coinjoin protocol exposes users to deanonymization risks [<a href="https://www.therage.co/vulnerability-wabisabi-coinjoin/">The Rage</a>]</p><ul><li><p>A flaw in the WabiSabi coinjoin protocol allows malicious coordinators to deanonymize users by correlating inputs and outputs.</p></li><li><p>The issue stems from malicious coordinators assigning unique maximum amount parameters, enabling tagging attacks to cluster wallets.</p></li><li><p>The vulnerability impacts Wasabi Wallet 2.2.1.0 and below, Ginger Wallet 2.0.13 and below, and BTCPay Server coinjoin plugin 1.0.101.0 and below. [<a href="https://github.com/GingerPrivacy/GingerWallet/discussions/116">GingerWallet&#8217;s Vulnerability Report</a>]</p></li></ul></li></ul><h3><strong>Bitcoin</strong></h3><h4><strong>Software Releases &amp; Project Updates</strong></h4><ul><li><p>00:19:59 Rust Payjoin <a href="https://github.com/payjoin/rust-payjoin/releases/tag/payjoin-0.21.0">v0.21.0</a></p><ul><li><p>This release enables transaction cut-through by allowing the receiver to add an arbitrary number of inputs and outputs, and allowing mixed input script types in Payjoin V2.</p></li><li><p>Allow receiver to contribute multiple inputs and outputs</p></li><li><p>Make <code>InputPair</code> public to facilitate working with inputs in coin selection and input contributions</p></li><li><p>Enable receiver fee contributions in <code>apply_fee</code>, which now requires a max_feerate parameter</p></li><li><p>Allow mixed input scripts in Payjoin V2</p></li><li><p>Implement client end-to-end encryption using HPKE using bitcoin-hpke</p></li></ul></li><li><p>00:32:48 Lark: Command line application for the Lark USB Hardware Wallet library [<a href="https://github.com/sparrowwallet/larkapp">Github</a>]</p><ul><li><p>&#8220;The Lark application is a command line app for interacting with USB hardware wallets in Bitcoin related functions. It uses the <a href="https://github.com/sparrowwallet/lark">Lark Java library</a>, which in turn is a port of the Python library <a href="https://github.com/bitcoin-core/HWI">HWI</a>.&#8221;</p></li><li><p>&#8220;The Lark command line application is designed to be a drop-in replacement for HWI, with a subset of commands implemented.&#8221;</p></li><li><p>Lark initial release <a href="https://github.com/sparrowwallet/larkapp/releases/tag/1.0.0">v1.0.0</a></p><ul><li><p>The following hardware wallets (for all models) are supported: Coldcard, Trezor, Ledger (current and legacy Bitcoin apps), BitBox02, Jade, and Keepkey.</p></li><li><p>Across the following platforms: Linux x86_64 and aarch64, macOS x86_64 and aarch64, and Windows x86_64.</p></li></ul></li></ul></li><li><p>01:12:40 Bitcoin Keeper</p><ul><li><p>Mobile <a href="https://github.com/bithyve/bitcoin-keeper/releases/tag/v1.3.0">v1.3.0</a></p><ul><li><p>Subscriptions: More features, reduced prices for all tiers.</p></li><li><p>Inheritance Planning: Inheritance Key now secured on the Bitcoin network using Miniscript. Convert any key into an Inheritance Key.</p></li><li><p>Attorney letters now include the Recovery Key and all added</p></li><li><p>Key Sharing: Share and sign keys remotely with any</p></li><li><p>Transactions: New history screen and support for sending unconfirmed</p></li></ul></li><li><p>Desktop <a href="https://github.com/bithyve/keeper-desktop/releases/tag/keeper-desktop-v0.1.4">v0.1.4</a></p><ul><li><p>Allow getting specific BIP44 accounts from a device</p></li><li><p>Add Taproot Key when getting device xPubs</p></li></ul></li></ul></li><li><p>01:13:23 Blue Wallet <a href="https://github.com/BlueWallet/BlueWallet/releases/tag/v7.0.5">v7.0.5</a></p><ul><li><p>Add Offline import</p></li><li><p>Add CoinControl sorting</p></li><li><p>Add AMD Fiat</p></li><li><p>Add RSD Fiat</p></li><li><p>Add Market Price intent</p></li><li><p>Add Reset currency alert</p></li><li><p>Add Notification shortcuts</p></li><li><p>Add Remove all recipients</p></li><li><p>Add Clear clipboard on import</p></li><li><p>Add Dark/Tinted iOS icons</p></li></ul></li><li><p>01:13:33 Floresta <a href="https://github.com/vinteumorg/Floresta/releases/tag/0.7.0">v0.7.0</a></p><ul><li><p>Async-std To Tokio: ends a major milestone of replacing <code>async-std</code> with <code>tokio</code> as the async runtime</p></li><li><p>florestad: expose assumeutreexo in lib mode</p></li><li><p>Feature: daemonize: On NIX environments, run <code>florestad</code> in the background as a daemon</p></li><li><p>Wire: handle block filters out-of-order</p></li><li><p>ssl init: Adds support for SSL to our Electrum Server</p></li><li><p>Adds fuzz to <code>floresta</code> using <code>cargo fuzz</code> with a few targets</p></li><li><p>Improve connection</p></li><li><p>Update getutxo: Now the <code>gettxout</code> rpc only returns UTXOS that are cached by the wallet</p></li><li><p>Improve CI caching</p></li><li><p>Add criterion benches and restructure testdata</p></li><li><p>Add test-features recipe to justfile</p></li><li><p>Add floresta-cli to Docker image</p></li></ul></li><li><p>01:13:44 Labelbase <a href="https://github.com/Labelbase/Labelbase/releases/tag/2.2.3">v2.2.3</a></p><ul><li><p>UI: New, card based, label list view for small screens (mobile devices)</p></li><li><p>UI/UX: New, improved status and error messages</p></li><li><p>Rework Electrum background operations (UTXO lookup)</p></li><li><p>Add &#8220;Address Derivation&#8221; support for Testnet (tpub, upub, vpub)</p></li><li><p>Add Samourai Backup Import, allows you to import your samourai.txt</p></li><li><p>Add Donation page</p></li></ul></li><li><p>01:14:17 BDK <a href="https://github.com/bitcoindevkit/bdk/releases/tag/v1.0.0-beta.6">v1.0.0-beta.6</a></p><ul><li><p>Final &#8220;beta&#8221; test release before a final bdk_wallet 1.0.0 version.</p></li><li><p>Changes include small bug fixes and API improvements plus an improved algorithm for determining which transactions are in the current best &#8220;canonical&#8221; block chain.</p></li><li><p>The new canonicalization algorithm processes the transaction graph in linear time versus the prior quadratic time algorithm.</p></li></ul></li><li><p>01:14:26 FullyNoded <a href="https://github.com/Fonta1n3/FullyNoded-Server/releases/tag/0.0.0.6-alpha">v0.0.0.6</a></p><ul><li><p>Quick Connect QR code url&#8217;s no longer contain real RPC credentials</p></li><li><p>Tweaks to JM config default fee settings to help increase chance of successful coinjoins (users can always add their own)</p></li><li><p>Obwatcher button added to Join Market so users can easily launch the order book to help trouble shoot failed coinjoins</p></li><li><p>Add auto refresh to Core Lightning</p></li></ul></li><li><p>01:14:43 BTCPay Server <a href="https://github.com/btcpayserver/btcpayserver/releases/tag/v2.0.4">v2.0.4</a></p><ul><li><p>Add QR Code with link to invitation email</p></li><li><p>Add rate providers for Norwegian exchanges</p></li><li><p>Greenfield: Improve store users API</p></li></ul></li><li><p>01:14:52 Zaprite</p><ul><li><p><a href="https://help.zaprite.com/en/articles/10258495-zaprite-release-notes-2024-12-09">v2024.12.09</a></p><ul><li><p>Add new View Contact page that displays Contact information and recent Invoices and Transactions</p></li><li><p>Add new View Recurring Invoice page that displays the Recurring Invoice Schedule summary and a list of Recent Invoices</p></li><li><p>Add new User Account Profile page, enabling Users to add avatars and display names</p></li><li><p>Add Coinos LNURL integration</p></li><li><p>Add LifPay LNURL integration</p></li></ul></li><li><p><a href="https://help.zaprite.com/en/articles/10200019-zaprite-release-notes-2024-11-25">v2024.11.25</a></p><ul><li><p>Add new View Invoice page which shows recent transactions and activity history</p></li><li><p>Add a &#8216;Discover&#8217; carousel to the Home dashboard</p></li></ul></li></ul></li><li><p>01:14:54 Peach <a href="https://github.com/Peach2Peach/peach-app/releases/tag/v0.5.2">v0.5.2</a></p><ul><li><p>Dark Mode Build</p></li><li><p>Match paymentdata fix</p></li><li><p>Always share device id hash when using contact form</p></li></ul></li><li><p>01:14:55 Boltz boltz-web-app</p><ul><li><p><a href="https://github.com/BoltzExchange/boltz-web-app/releases/tag/v1.5.4">v1.5.4</a></p><ul><li><p>Switch to Blockstream Liquid explorer</p></li></ul></li><li><p><a href="https://github.com/BoltzExchange/boltz-web-app/releases/tag/v1.5.3">v1.5.3</a></p><ul><li><p>Improve HWW derivation path selection</p></li></ul></li><li><p><a href="https://github.com/BoltzExchange/boltz-web-app/releases/tag/v1.5.2">v1.5.2</a></p><ul><li><p>Submarine Swap preimage copy button</p></li><li><p>Add Chatwoot</p></li><li><p>Show when no browser wallet found</p></li><li><p>0-amount chain swaps</p></li></ul></li></ul></li><li><p>01:14:56 ESP-Miner <a href="https://github.com/skot/ESP-Miner/releases/tag/v2.4.1">v2.4.1</a></p><ul><li><p>Add support for eusolo stats for ckpool</p></li><li><p>Add Noderunners pool to quick links</p></li><li><p>Add 205 config and remove self test flag</p></li><li><p>api: add stratum difficulty</p></li><li><p>Don&#8217;t abandon the first mining.notify</p></li><li><p>Swarm styles, refresh on load, more combined stats, more info in table</p></li></ul></li><li><p>01:14:58 Clams remote <a href="https://x.com/clamstech/status/1857695270793793973">Update</a></p><ul><li><p>Add support for BIP-353 usernames</p></li></ul></li><li><p>01:14:59 Mempal <a href="https://github.com/aeonBTC/Mempal/releases/tag/v1.3.0">v1.3.0</a></p><ul><li><p>Elapsed time since latest block displayed on dashboard and widgets</p></li><li><p>Number of blocks to clear mempool displayed on dashboard and widgets</p></li><li><p>Tor connection indicator now displays on dashboard when connected over Tor</p></li><li><p>Set specific block height alerts for notifications</p></li><li><p>Widget update frequency option in settings</p></li><li><p>Add tap to refresh widget feature and double tap to open Mempal app</p></li></ul></li><li><p>01:15:07 Kyoto <a href="https://github.com/rustaceanrob/kyoto/releases/tag/v0.6.0">v0.6.0</a></p><ul><li><p>Pass FeeFilter to client</p></li><li><p>Add Signet and Bitcoin checkpoints</p></li></ul></li><li><p>01:15:20 LifPay</p><ul><li><p>Introduces Reusable Payment QR Codes with fixed amounts, allowing users to create a QR code with a fixed amount that can be scanned and reused multiple times. [<a href="https://stacker.news/items/783298">Stacker News</a>]</p></li></ul></li></ul><h4><strong>Project spotlight</strong></h4><ul><li><p>01:16:09 Specter Shield Lite: Low Cost Secure Element Backed Security for DIY Bitcoin Hardware Wallet [<a href="https://x.com/YTCryptoGuide/status/1862139967792660560">Announcement</a>] [<a href="https://github.com/3rdIteration/specter-diy/">Github fork</a>]</p></li><li><p>01:16:17 <a href="https://en.bitcoin.it/wiki/Covenants_support">Covenants support</a>: A dedicated covenants support page on the Bitcoin Wiki, listing developers&#8217; current support positions.</p></li><li><p>01:18:08 <a href="https://kibo.money/">Kibo</a>: An open source Bitcoin Core data extractor and visualizer [<a href="https://github.com/kibo-money/kibo">Github</a>]</p></li><li><p>01:18:20 <a href="https://savingsatoshi.com/">Saving Satoshi</a>: The world&#8217;s first interactive, practice-focused game to teach you bitcoin development.</p><ul><li><p>&#8220;Saving Satoshi is a light-hearted, first point of contact for developers of all ages that want to learn how bitcoin works.&#8221; [<a href="https://github.com/saving-satoshi/saving-satoshi">Github</a>]</p></li></ul></li><li><p>01:18:28 Fully Noded Server: A one click Bitcoin Core, Core Lightning and Join Market server to connect to Fully Noded apps. [<a href="https://github.com/Fonta1n3/FullyNoded-Server">Github</a>]</p></li><li><p>01:18:30 <a href="https://www.timestampfinancial.com/">Timestamp</a>: A platform that enables both accredited and non-accredited investors to invest in Bitcoin and open-source companies with low minimum investments.</p></li><li><p>01:18:49 <a href="https://satosh.ee/">Satoshee</a>: Winners&#8217; club. Carefully curated gift cards, discounts, loyalty program.</p><ul><li><p>Satoshee is platform offering gift cards, exclusive discounts, and Loyalty Programs, which support the creation and distribution of open-source media.</p></li></ul></li><li><p>01:19:06 <a href="https://github.com/Schnitzel/hass-miner">hass-miner</a>: Control and monitor your Bitcoin Miners from Home Assistant.</p><ul><li><p>Great for Heat Reusage, Solar Mining or any usecase where you don&#8217;t need your miners running 24/7 or with a specific wattage.</p></li><li><p>Works great in coordination with ESPHome for Sensors (like temperature) and Grafana for Dashboards.</p></li><li><p>Support for: Antminers, Whatsminers, Avalonminers, Innosilicons, Goldshells, Auradine, BitAxe, IceRiver, Hammer, Braiins Firmware, Vnish Firmware, ePIC Firmware, HiveOS Firmware, LuxOS Firmware, Mara Firmware</p></li></ul></li><li><p>01:19:12 <a href="https://entropy.page/pow.html">Entropy</a>: A collection of open-source bitcoin workshops, projects, hackathons, and software, by D++.</p></li><li><p>01:19:20 PlebDevs launches [<a href="https://plebdevs.com/course/naddr1qvzqqqr4xspzpueu32tp0jc47uzlcuxdgcw06m40ytu7ynpna2adnqty3e0vda6pqy88wumn8ghj7mn0wvhxcmmv9uq32amnwvaz7tmjv4kxz7fwv3sk6atn9e5k7tcpr9mhxue69uhhyetvv9ujuumwdae8gtnnda3kjctv9uq3wamnwvaz7tmjv4kxz7fwdehhxarj9e3xzmny9uq36amnwvaz7tmjv4kxz7fwd46hg6tw09mkzmrvv46zucm0d5hsz9mhwden5te0wfjkccte9ec8y6tdv9kzumn9wshszynhwden5te0dehhxarjxgcjucm0d5hszynhwden5te0dehhxarjw4jjucm0d5hsz9nhwden5te0wp6hyurvv4ex2mrp0yhxxmmd9uq3wamnwvaz7tmjv4kxz7fwv3jhvueww3hk7mrn9uqzge34xvuxvdtrx5knzcfhxgkngwpsxsknsetzxyknxe3sx43k2cfkxsurwdq68epwa">PlebDev Starter Course</a>], a free starter course aimed at complete beginners to learn basic coding or webdev skills, covering code editors, Git/Github, HTML, CSS, and JavaScript.</p></li></ul><h3><strong>Vulnerability Disclosures</strong></h3><ul><li><p>01:19:29 Droidbot targets banking and crypto apps across Europe [<a href="https://www.cleafy.com/cleafy-labs/droidbot-insights-from-a-new-turkish-maas-fraud-operation">Cleafy&#8217;s disclosure</a>]</p><ul><li><p>The malware impersonates apps like Google Chrome to steal credentials for 77 banking and cryptocurrency platforms across Europe, and uses Accessibility Services to log keystrokes, overlay fake login pages, and intercept SMS OTPs.</p></li><li><p>DroidBot employs MQTT, typically used in IoT, for stealthy data exfiltration. It encrypts and compresses data before transmission, complicating detection.</p></li></ul></li><li><p>01:19:36 DaMAgeCard: SD Express Card vulnerability exposes memory access risks in laptops and consoles [<a href="https://cyberinsider.com/sd-express-card-flaw-exposes-laptops-and-consoles-to-memory-attacks/">CyberInsider</a>]</p><ul><li><p>Positive Technologies researchers identified a vulnerability in SD Express cards, leveraging the Direct Memory Access (DMA) feature to bypass system protections. Modified cards can exploit gaps in securing the transition between SDIO and PCIe modes.</p></li></ul></li><li><p>01:19:47 Web3: Malicious versions of Solana&#8217;s web3.js npm library expose private keys [<a href="https://thehackernews.com/2024/12/researchers-uncover-backdoor-in-solanas.html?m=1">The Hacker News</a>]</p><ul><li><p>Researchers uncovered two malicious versions (1.95.6 and 1.95.7) of the popular @solana/web3.js npm library, which harvested private keys to drain crypto wallets.</p></li><li><p>The attack is believed to have stemmed from a phishing incident targeting the npm package maintainer, allowing the hacker to publish compromised versions.</p></li></ul></li><li><p>Encrypted communications service &#8216;Matrix&#8217;, dismantled by international police operation [<a href="https://www.europol.europa.eu/media-press/newsroom/news/international-operation-takes-down-another-encrypted-messaging-service-used-criminals">Europol</a>]</p><ul><li><p>A large-scale investigation, lead by French and Dutch authorities involved in a joint investigation, lead to the interception of 2.3 million messages in 33 languages over a monitoring period of three months, dismantling more than 40 servers.</p></li></ul></li><li><p>Uganda confirms central bank hack, downplays extent of the loss of 62 billion shillings ($16.8 million) [<a href="https://www.reuters.com/world/africa/hackers-steal-17-mln-uganda-central-bank-state-paper-2024-11-28/">Reuters</a>]</p><ul><li><p>The hacking group, &#8216;Waste&#8217;, based in Southeast Asia, transferred funds abroad, including to Japan. The central bank has recovered over half of the stolen amount.</p></li></ul></li></ul><h3><strong>Audience Questions</strong></h3><ul><li><p>01:24:05 How do NVK and the guests feel about <a href="https://x.com/intengineering/status/1866491976134099210">Google&#8217;s Willow quantum chip</a>? Is Bitcoin at risk?</p></li><li><p>01:30:01 Can NVK and the guests comment on <a href="https://x.com/jamesob/status/1866625791829709020">James OB&#8217;s recent Tweet</a>? &#8220;Very simple scenario for you: Tomorrow gov announces that by EOW, all exchanges must move held bitcoins over to a one-way hardfork that adds &#8220;monetary policy tools&#8221; and OFAC compliance Can bitcoin support an exit for everyone who wants out? This is why scaling matters.&#8221; What are your general thoughts, and also how would a &#8220;one-way hardfork&#8221; work?</p></li></ul><h3><strong>Privacy &amp; Other Related Bitcoin Projects</strong></h3><h4><strong>Software Releases &amp; Project Updates</strong></h4><ul><li><p>The Tor Project replaces its legacy BridgeDB system with Rdsys, a modular and adaptable bridge distribution system. [<a href="https://blog.torproject.org/making-connections-from-bridgedb-to-rdsys/">Blog post</a>]</p><ul><li><p>Rdsys supports flexible distribution channels, such as Telegram, enhancing user accessibility and bypassing restrictions without relying on outdated captchas.</p></li><li><p>Tor Browser <a href="https://blog.torproject.org/new-release-tor-browser-1403/">v14.03</a></p><ul><li><p>This version includes important <a href="https://www.mozilla.org/en-US/security/advisories/">security updates</a> to Firefox.</p></li></ul></li></ul></li><li><p>NomadNet <a href="https://github.com/markqvist/NomadNet/releases/tag/0.5.5">v0.5.5</a></p><ul><li><p>Add Checkbox and Radio Group fields to Micron</p></li><li><p>Fix invalid LXMF link handling in browser</p></li></ul></li><li><p>Sideband</p><ul><li><p><a href="https://github.com/markqvist/Sideband/releases/tag/1.2.0">v1.2.0</a></p><ul><li><p>Sideband now includes Liam Cottle&#8217;s RNode flasher in the internal repository</p></li><li><p>Updated message color scheme for better readability and theme consistency</p></li><li><p>Updated theme and user interface defaults for new installations</p></li><li><p>Added signal stats to the announce stream (if available from interface)</p></li><li><p>Added ability to render rich markup in messages</p></li><li><p>Added per-object live-tracking mode for telemetry-enabled peers</p></li><li><p>Added ability to add any number of interfaces via the Advanced RNS Configuration option</p></li><li><p>Added Utilities section</p></li><li><p>Added support for the repository server on desktop operating systems</p></li></ul></li><li><p><a href="https://github.com/markqvist/Sideband/releases/tag/1.1.4">v1.1.4</a></p><ul><li><p>Add ability to add message attachments from sharing intent on Android</p></li><li><p>Add ability to add message attachments with drag-and-drop on desktop</p></li><li><p>Add user interface scaling option</p></li><li><p>Update RNS and LXMF to latest versions</p></li></ul></li></ul></li><li><p>Tails <a href="https://tails.net/news/version_6.10/">v6.10</a></p><ul><li><p>Fix support for Trezor hardware wallets in Electrum</p></li><li><p>Disable saving telemetry data in Thunderbird</p></li><li><p>Update Tor Browser to 14.0.3. and Thunderbird from 115.16.0 to 128.4.3</p></li></ul></li></ul><h3><strong>Lightning + L2+</strong></h3><h4><strong>Project spotlight</strong></h4><ul><li><p>PeerSwap: enables Lightning Network nodes to balance their channels by facilitating atomic swaps with direct peers [<a href="https://github.com/ElementsProject/peerswap">Github</a>]</p><ul><li><p>PeerSwap enhances decentralization of the Lightning Network by enabling all nodes to be their own swap provider. No centralized coordinator, no 3rd party rent collector, and lowest cost channel balancing means small nodes can better compete with large nodes.</p></li></ul></li><li><p><a href="https://t.me/voltztip_bot">Voltz Tip Bot</a>: An easy-to-use Lightning Network Telegram Bot designed to facilitate tipping sats right within your Telegram groups [<a href="https://stacker.news/items/800859">Announcement</a>]</p></li><li><p><a href="https://liquid.horse/">Liquid Horse</a>: Liquid Sidechain Statistics. Provides statistics and analytics for the Liquid Network.</p><ul><li><p>It tracks data such as block production, sidechain transactions, functionary uptime, and federation wallet balances. It also highlights the operational status of block signers and other technical metrics related to network performance</p></li></ul></li><li><p><a href="https://liquidnetwork.wiki/">awesome-liquid-network</a>: A curated list of Liquid Network resources, libraries, tools and applications</p></li><li><p><a href="https://macadamia.cash/">Macadamia</a>: A native iOS client for cashu [<a href="https://github.com/zeugmaster/macadamia">Github</a>]</p><ul><li><p>Macadamia supports standard Cashu operations such as: Minting of tokens, sending and receiving, melting tokens, restoring your wallet balance using a 12 word mnemonic seed phrase backup.</p><ul><li><p><a href="https://github.com/zeugmaster/macadamia/releases/tag/v0.2.0">v0.2.0</a>: This version is a complete rewrite, segregating cashu logic to its own library and implementing a database model in SwiftData.</p></li></ul></li></ul></li><li><p>Strata Bridge: Alpen Labs is developing a bitcoin bridge to its Strata platform, enabling 1 BTC on Strata to match 1 BTC on bitcoin with minimal trust assumptions. [<a href="https://www.alpenlabs.io/blog/introducing-the-strata-bridge">Announcement</a>]</p><ul><li><p>The Strata bridge is based on the BitVM2 paper by Robin Linus, incorporating optimizations and advanced research to improve efficiency and robustness.</p></li></ul></li></ul><h4><strong>Software Releases &amp; Project Updates</strong></h4><ul><li><p>Core Lightning <a href="https://github.com/ElementsProject/lightning/releases/tag/v24.11">v24.11</a> - The lightning-dev Mailing List</p><ul><li><p>Highlights for Users:</p><ul><li><p><code>xpay</code> is a new, experimental plugin for payments. It&#8217;s rewritten from the ground up, on top of another plugin called <code>askrene</code>, which provides advanced routing advice for payments</p></li><li><p>Paying and receiving offers (bolt12 send and receive) are enabled by default</p></li><li><p><code>hsmtool</code> <code>generatehsm</code> can now accept all the parameters on the command line</p></li></ul></li><li><p>Highlights for Developers:</p><ul><li><p><code>cln-grpc</code> (our rust plugin to provide a GRPC interface) is enabled by default</p></li><li><p>There&#8217;s a new dev-splice command which lets you provide a splice script for describing complex moves</p></li><li><p>Improve tracing infrastructure</p></li></ul></li><li><p>Highlights for the Network:</p><ul><li><p>We gossip harder: we try to stay connected to 10 nodes</p></li><li><p>Connectd will connect faster on startup, maintaining up to 10 outgoing connection attempts in parallel</p></li></ul></li></ul></li><li><p>LND <a href="https://github.com/lightningnetwork/lnd/releases/tag/v0.18.4-beta.rc1">v0.18.4-beta.rc1</a></p><ul><li><p>Minor release which ships the features required for building custom channels, alongside the usual bug fixes and stability improvements.</p></li><li><p>Features: The main channel state machine and database now allow for processing and storing custom Taproot script leaves, allowing the implementation of custom channel types in a series of changes.</p></li><li><p>Functional Enhancements:</p><ul><li><p>A new <code>protocol.simple-taproot-overlay-chans</code> configuration item/CLI flag was added to turn on custom channel functionality.</p></li><li><p>Compatibility with bitcoind v28.0 was ensured by updating the version the CI pipeline is running against.</p></li></ul></li></ul></li><li><p>Eclair <a href="https://github.com/ACINQ/eclair/releases/tag/v0.11.0">v0.11.0</a></p><ul><li><p>This release adds official support for Bolt 12 offers and makes progress on liquidity management features (splicing, liquidity ads, on-the-fly funding). We also stop accepting channels that don&#8217;t support anchor outputs and update our dependency on Bitcoin Core.</p></li><li><p>Implement full support for Bolt 12 payments</p></li><li><p>Improve implementation of splicing, by relying on the now official quiescence feature and adding RBF support</p></li><li><p>Include an early prototype for liquidity ads</p></li><li><p>Update minimal version of Bitcoin Core (v27.2)</p></li><li><p>Incoming obsolete channels will be rejected</p></li><li><p>HTLC endorsement for channel jamming</p></li><li><p>On-the-fly funding: introduces implementation of proposed protocol to negotiate an on-the-fly liquidity purchase</p></li></ul></li><li><p>Zeus <a href="https://github.com/ZeusLN/zeus/releases/tag/v0.9.3">v0.9.3</a></p><ul><li><p>Improved channels UI: including reserves</p></li><li><p>Invoice Settings: Display requested amount on invoice</p></li><li><p>Embedded LND: Troubleshooting menu</p></li><li><p>Bitcoin denominated amounts: display with spaces</p></li><li><p>ZEUS Pay: UX improvements</p></li></ul></li><li><p>Ark <a href="https://github.com/ark-network/ark/releases/tag/v0.4.0">v0.4.0</a> - New address encoding, Notes and Market Hours</p><ul><li><p>New Address Encoding: Instead of encoding user and server public keys, we now encode the VTXO output script (Taproot key) and server public key</p></li><li><p>Ark Notes: a feature designed for users who may not be online frequently</p><ul><li><p>Clients can share a Nostr public key (profile) for each of their VTXOs</p></li><li><p>When users go offline, the Server will print notes worth their unspent swept VTXOs</p></li><li><p>Users can restore their off-chain balances when they come back online in the future</p></li></ul></li><li><p>Market Hours:</p><ul><li><p>Introduce specific periods during which the server will offer lower service fees for users joining rounds</p></li><li><p>Allow users to schedule their settlements at predetermined times in the future, potentially saving on fees</p></li></ul></li><li><p>Server Improvements:</p><ul><li><p>Connection of the internal Bitcoin wallet to bitcoind with ZMQ</p></li><li><p>Support for restoration of the internal Bitcoin wallet</p></li><li><p>Auto-unlock feature for the internal wallet</p></li><li><p>Increase testing surface for improved reliability</p></li><li><p>Consolidation of APIs</p></li></ul></li></ul></li><li><p>Alby</p><ul><li><p>lightning-browser-extension <a href="https://github.com/getAlby/lightning-browser-extension/releases/tag/v3.10.0">v3.10.0</a> - Ice Clouds over a Red Planet</p><ul><li><p>Version v3.10.0 introduces the Alby Hub Connector and a notification banner for upgrading shared wallets to Alby Hub. It also replaces &#8220;Citadel&#8221; with &#8220;Nirvati&#8221; and includes multiple translation updates.</p></li></ul></li><li><p>Alby-go <a href="https://github.com/getAlby/go/releases/tag/v1.7.2">v1.7.2</a></p><ul><li><p>LNURL-withdraw support</p></li><li><p>Improve currency selection</p></li><li><p>Boostagram info in transaction details</p></li><li><p>Delete contacts in address book</p></li><li><p>Enhance QR code readability</p></li></ul></li><li><p>bitcoin-connect <a href="https://github.com/getAlby/bitcoin-connect/releases/tag/v3.6.3">v3.6.3</a></p><ul><li><p>Add currency selector UI</p></li></ul></li></ul></li><li><p>Breez SDK <a href="https://github.com/breez/breez-sdk-greenlight/releases/tag/0.6.5">v0.6.5</a></p><ul><li><p>Increase reliability for trampoline payments</p></li></ul></li><li><p>Lightning Terminal <a href="https://github.com/lightninglabs/lightning-terminal/releases/tag/v0.14.0-alpha.rc1">v0.14.0-alpha.rc1</a></p><ul><li><p>This first Release Candidate of Lightning Terminal (LiT) ships the first non-experimental version of Taproot Asset Channels</p></li></ul></li><li><p>Taproot-assets <a href="https://github.com/lightninglabs/taproot-assets/releases/tag/v0.5.0-rc1">v0.5.0-rc1</a></p><ul><li><p>Database Migrations: <code>tapd</code> v0.5.0 contains non-revertible database migrations. After running <code>tapd</code> v0.5.0, these database migrations prevent downgrading <code>tapd</code> to a previous release. Create backups of <code>tapd</code> database state, before upgrading to <code>tapd</code> v0.5.0.</p></li><li><p>Breaking changes:</p><ul><li><p>Downstream Projects - <code>litd</code>: <code>litd</code> v0.14.0-alpha enhancements require both channel peers to upgrade to a <code>litd</code> version &gt;= v0.14.0-alpha to continue Lightning Channel functionality.</p></li></ul></li><li><p><code>tapd</code> v0.5.0 changes:</p><ul><li><p>Oracle RPC: The RPC protobuf definitions for the Price Oracle have changed. Asset exchange rates are now expressed as <code>FixedPoint</code> to achieve better precision.</p></li><li><p>Configuration changes: The configuration value (<code>universe.public-access</code>) and command line flag (<code>--universe.public-access</code>) now needs a value and is no longer a boolean</p></li></ul></li></ul></li><li><p>Torq <a href="https://github.com/lncapital/torq/releases/tag/v2.1.0">v2.1.0</a></p><ul><li><p>Bitcoind wallet as a node type (Torq now has on-chain wallet support for CLN, LND and bitcoind)</p></li><li><p>Bitcoind existing on-chain address listing</p></li><li><p>Management of UTXO locking</p></li><li><p>Improve transaction output visualizations (and backend)</p></li><li><p>Improve transaction output linking to channels (funding/closing transactions)</p></li><li><p>LND: sweep transaction output linking to channels -Torq gRPC (BETA feature):</p><ul><li><p>New call SubscribeBlockHeight</p></li><li><p>New call PayOnChain</p></li><li><p>New call DecodeInvoice</p></li><li><p>New call GetInvoiceStatus</p></li></ul></li></ul></li><li><p>Polar <a href="https://github.com/jamaljsr/polar/releases/tag/v3.1.0">v3.1.0</a></p><ul><li><p>This minor release is needed to support the latest released versions of litd v0.14.0-alpha.rc1 and tapd v0.5.0-alpha.rc1.</p></li><li><p>Features:</p><ul><li><p>Add Description field when creating a new network</p></li><li><p>Add full support for decimal display for TAP assets</p></li></ul></li></ul></li><li><p>CLBOSS <a href="https://github.com/ZmnSCPxj/clboss/releases/tag/v0.14.1">v0.14.1</a> - Hand at the Grindstone</p><ul><li><p>Contrib Script Enhancements:</p><ul><li><p>Add <code>--lightning-dir</code> option to the contrib scripts</p></li><li><p>Add Nix Support</p></li></ul></li><li><p>Stack Unwinding Support:</p><ul><li><p>Implement <code>libunwind</code> for stack unwinding</p></li><li><p>Replace the use of <code>program_invocation_name</code> with a custom global variable to store the program name, improving portability to systems like FreeBSD and other Unix-like systems.</p></li></ul></li><li><p>Configurable Exception Backtrace Support:</p><ul><li><p>Add the <code>--disable-exception-backtrace</code> option to <code>configure</code></p></li><li><p>The <code>Util::BacktraceException</code> class now provides a no-op wrapper when exception backtraces are disabled via <code>--disable-exception-backtrace</code></p></li></ul></li></ul></li><li><p>Minibits Wallet <a href="https://github.com/minibits-cash/minibits_wallet/releases/tag/v0.1.10-beta.2">v0.1.10</a></p><ul><li><p>This native update brings sole but important architectural change: all Nostr wallet (NWC) commands are now processed using Android&#8217;s foreground service.</p></li></ul></li><li><p>Cashu-ts <a href="https://github.com/cashubtc/cashu-ts/releases/tag/v2.0.0">v2.0.0</a></p><ul><li><p>NUT-05: description for invoice, integration test without bolt11 decode</p></li><li><p>DX: Enforce explicit type annotations on function parameters</p></li><li><p>NUT-18: Payment requests</p></li><li><p>Add pipeline to build RC from staging branch</p></li><li><p>Add fees and coin selection</p></li><li><p>Streamline blinding</p></li><li><p>Wallet: Remove bip39 dependency</p></li><li><p>Support for NUT-12</p></li></ul></li></ul><h3><strong>Nostr</strong></h3><h4><strong>Project spotlight</strong></h4><ul><li><p>Myriad: A simple personal <a href="https://github.com/hzrd149/blossom">blossom</a> server for your own files [<a href="https://git.fiatjaf.com/myriad">Code repository</a>]</p></li><li><p><a href="https://npub19sstws4x9t7nua2sh6cxkeez25y6lvvnq6fqpmyzwnthsjap5tqqkdsghg.nsite.lol/">Cherry Tree</a>: Chunked files stored on blossom servers [<a href="https://github.com/hzrd149/cherry-tree">Github</a>]</p><ul><li><p>&#8220;An experiment to see if its possible to re-create torrents on top of blossom servers and nostr&#8221; [<a href="https://github.com/hzrd149/blossom/pull/51">Explanation</a>]</p></li></ul></li><li><p>Condenser: A nostr bot built using the mistral api which summarizes all notes from the news.utxo.one relay [<a href="https://github.com/coracle-social/condenser">Github</a>]</p><ul><li><p>&#8220;A script that fetches the last 6 hours of events from news.utxo.one and summarizes them using the Mistral API.&#8221;</p></li></ul></li><li><p>Mostr: An immutable nested collaborative task manager, powered by nostr [<a href="https://github.com/xeruf/mostr">Github</a>]</p></li><li><p>Robosats Nostr Sync: Scrappers to publish to nostr orders from other platforms [<a href="https://github.com/RoboSats/robosats-nostr-sync">Github</a>]</p><ul><li><p>The tool can display non-kyc exchange HodlHodl offers on Robosats&#8217; client [<a href="https://njump.me/nevent1qqszpnezp7v8njlsad2sm5t30sjduzhkld8u02mh0m8qz6mptzk7mmqpp4mhxue69uhkummn9ekx7mqzypj9dqde6pnmrgmzcjlw3h0lnp7jgek5nyzuym9clmz7d7mn4awgghkwnfm">Note</a>]</p></li></ul></li><li><p><a href="https://nokakoi.com/">nokakoi</a>: Grid style live nostr client for Windows. [<a href="https://github.com/betonetojp/kakoi">Github</a>]</p></li><li><p><a href="https://bullishbulletin.vercel.app/">The Bullish Bulletin</a>: An app powered by Nostr Wallet Connect to post all sorts of messages like job ads or announcements</p><ul><li><p>Users can choose a note type, enter their message and pay via Bitcoin Connect to publish their post.</p></li></ul></li><li><p><a href="https://vpnstr.com/">Vpnstr</a>: A new VPN service with 53 locations and unlimited bandwidth, can be paid with Bitcoin on the Lightning Network</p></li></ul><h4><strong>Software Releases &amp; Project Updates</strong></h4><ul><li><p>Rust Nostr <a href="https://github.com/rust-nostr/nostr/releases/tag/v0.37.0">v0.37.0</a></p><ul><li><p>Add support to NIP17 relay list in SDK (when <code>gossip</code> option is enabled)</p></li><li><p>Add NIP22 and NIP73 support</p></li><li><p>Fix Swift Package</p></li><li><p>From this release all the rust features are be disabled by default (except <code>std</code> feature in <code>nostr</code> crate).</p></li></ul></li><li><p>Primal</p><ul><li><p>iOS <a href="https://njump.me/nevent1qqsxqyn2ym3rplv9ykaj49rqf9a0aqly38rn4nzqc5ekvl49gy5gllqpzemhxue69uhhyetvv9ujumn0wd68ytnzv9hxgq3qzga04e73s7ard4kaektaha9vckdwll3y8auztyhl3uj764ua7vrq6utlw4">v2.0.134</a></p><ul><li><p>Improve onboarding</p></li><li><p>Profile screen improvements</p></li><li><p>Feed rendering improvements</p></li><li><p>App shell cosmetic improvements</p></li></ul></li><li><p>Android <a href="https://github.com/PrimalHQ/primal-android-app/releases/tag/2.0.28">v2.0.28</a></p><ul><li><p>Implement:</p><ul><li><p>Profile avatar and cover image viewer in profile details screen</p></li><li><p>Rendering highlights and generic events in feeds</p></li><li><p>Tap QR code to copy addresses on profile QR code viewer</p></li><li><p>Follow/unfollow approvals if contact list is not found</p></li><li><p>Onboarding follows customisation and zaps introductions</p></li><li><p>Premium badge on profile details screen</p></li><li><p>New avatars designs</p></li><li><p>Support for primal legend avatars across the app</p></li><li><p>Primal premium check into profile editor</p></li></ul></li></ul></li><li><p>Web <a href="https://njump.me/nevent1qqsxqyn2ym3rplv9ykaj49rqf9a0aqly38rn4nzqc5ekvl49gy5gllqpzemhxue69uhhyetvv9ujumn0wd68ytnzv9hxgq3qzga04e73s7ard4kaektaha9vckdwll3y8auztyhl3uj764ua7vrq6utlw4">v2.0.11</a></p><ul><li><p>Profile screen improvements</p></li><li><p>Feed rendering improvements</p></li></ul></li></ul></li><li><p>Damus Notedeck Alpha is now available for Purple subscribers [<a href="https://njump.me/nevent1qqsrlz8fh77slt8puzc7s32auc0n87l2zcwnwt5wuu5cxxzsc4epj2cpzemhxue69uhhyetvv9ujumn0wd68ytnzv9hxgq3q8m76awca3y37hkvuneavuw6pjj4525fw90necxmadrvjg0sdy6qsvuxexh">Announcement</a>]</p><ul><li><p>Lightning fast: Built from the ground up with an ultra-fast database made exclusively for nostr, leveraging several state-of-the-art performance techniques not available on web clients</p></li><li><p>Custom feeds: Add timeline, hashtag, and notification columns of any nostr public key. Which means you can see the nostr landscape through other peoples&#8217; eyes</p></li><li><p>Add account switching</p></li></ul></li><li><p>Notedeck <a href="https://njump.me/naddr1qvzqqqr4gupzqnyk6a37ktlqryg00eezpd78and7rfcq2le5fw0hns527zqv8m3sqy88wumn8ghj7mn0wvhxcmmv9uqqyt3wauhhvk">Update</a></p><ul><li><p>Update user relay-list via polling</p></li><li><p>Add user mute list sync via polling</p></li><li><p>Skip muted content</p></li><li><p>debug: add crate features which enable egui DebugOptions</p></li></ul></li><li><p>Amethyst</p><ul><li><p><a href="https://github.com/vitorpamplona/amethyst/releases/tag/v0.93.1">v0.93.1</a></p><ul><li><p>Move to NIP-22 to reply to Interactive Stories</p></li><li><p>Add amount and personalization labels to the DVM feed</p></li><li><p>Improve performance of the Hex encoder</p></li><li><p>Improve the layout of the discovery feed items</p></li><li><p>Update Jackson, secp256k1, and AGP</p></li></ul></li><li><p><a href="https://github.com/vitorpamplona/amethyst/releases/tag/v0.93.0">v0.93.0</a> - Blossom, Olas, Around Me feeds and Interactive Stories</p><ul><li><p>Add support for displaying NIP-63 Interactive Stories</p></li><li><p>Add support for Blossom media servers</p></li><li><p>Add support for Olas&#8217; Image feeds</p></li><li><p>Add support for Around Me feed with posts that only show up in that location</p></li><li><p>And many more new features</p></li></ul></li></ul></li><li><p>Chronicle <a href="https://github.com/dtonon/chronicle/releases/tag/v0.3">v0.3</a></p><ul><li><p>Add workaround to stop saving duplicate events</p></li></ul></li><li><p>Olas</p><ul><li><p>iOS <a href="https://njump.me/nevent1qqsg0fff9kv69g3l6fv36xlalsj69mhzgwn8xvxmmc573p4zaw653hqppamhxue69uhkummnw3ezumt0d5pzp75cf0tahv5z7plpdeaws7ex52nmnwgtwfr2g3m37r844evqrr6jgc279e">v0.1.5</a></p><ul><li><p>Reposts</p></li><li><p>Zaps (via Nostr Wallet Connect for now)</p></li><li><p>Swipe-to-zap</p></li><li><p>Performance improvements</p></li></ul></li><li><p>Android <a href="https://njump.me/nevent1qqsrcqjseghrvfpcsfc87a59dvffnmeagshmxazu4aruwtjrduwc66gpp4mhxue69uhkummn9ekx7mqzyrafsj7hmweg9ur7zmn6apajdg48hxuskujx53rhrux0ttjcqx84ykzjpej">v0.1.5</a></p><ul><li><p>NWC zaps</p></li><li><p>LN and Nutzaps via swipe-to-zap</p></li><li><p>Reposts</p></li><li><p>Performance optimizations</p></li></ul></li><li><p><a href="https://github.com/pablof7z/olas/releases/tag/0.1.4-1">v0.1.4-1</a></p><ul><li><p>Add reposts</p></li><li><p>Performance improvements</p></li></ul></li><li><p><a href="https://github.com/pablof7z/olas/releases/tag/0.1.4">v0.1.4</a></p><ul><li><p>Add bookmarks</p></li></ul></li></ul></li><li><p>Snort <a href="https://git.v0l.io/Kieran/snort/releases/tag/v0.3.0">v0.3.0</a></p><ul><li><p>Drop NIP-04 support for DM&#8217;s</p></li><li><p>Profile link QR selector (npub/nprofile)</p></li><li><p>Relay up time reporting (via nostr.watch NIP)</p></li><li><p>New note designer media attachment UI</p></li><li><p>Media browser via NIP-96 server list</p></li><li><p>NIP-89 support (App handlers for unknown events)</p></li><li><p>WoT filter for replies</p></li><li><p>Drop NIP-04 support for NIP-46 bunkers (NIP-44 only)</p></li><li><p>NIP-55 Amber signer support</p></li></ul></li><li><p>YakiHonne <a href="https://njump.me/nevent1qqsyrn277057f7p9mfhrcrkgkfnn09tzpmr2ksg5r24jwg7tmdplmdgppamhxue69uhkummnw3ezumt0d5pzqgycd7urua6ajmgc3jjunhcseekkz0swkljhdzs0pvftxlx6cgdnh4wuq7">Update</a></p><ul><li><p>Mobile:</p><ul><li><p>All-in-One Content Hub: Create notes, articles, videos, curations, and smart widgets all in one place</p></li><li><p>New Media Servers: Added support for NostrMedia.com (npub18jn&#8230;59kc), Nostr check, and more</p></li><li><p>Thread Timeline Enhancements: Smoother and clearer thread viewing</p></li><li><p>Nip 44 Gift Messages: Now enabled by default</p></li><li><p>App-Wide Improvements: Faster, smoother, better</p></li></ul></li><li><p>Web:</p><ul><li><p>Upgraded Note Editor: GIFs, emojis, and real-time previews to enhance your creativity</p></li><li><p>Enhanced Long-Form Content: A fresh design to make writing a joy</p></li><li><p>Custom Media Uploaders: Support for more media options and servers</p></li><li><p>Expanded Search: Find more notes, media, and users with ease</p></li><li><p>Browsing Suggestions: Discover new notes, media, users, and more</p></li></ul></li></ul></li><li><p>Nostrmo <a href="https://github.com/haorendashu/nostrmo/releases/tag/2.9.4">v2.9.4</a></p><ul><li><p>Remove metadata cache when start and change wot reload method</p></li><li><p>Add support to sync user&#8217;s local events to relays</p></li><li><p>Add support to send long form</p></li><li><p>Add a json viewer to event json copy</p></li><li><p>Trace router query add tempRelays support</p></li></ul></li><li><p>Keychat <a href="https://github.com/keychat-io/keychat-app/releases/tag/1.22.2%2B6277">v1.22.2</a></p><ul><li><p>Support Large Group Chat with OpenMLS Integration</p></li><li><p>New Bot Identity: Support Ecash Payments for ChatGPT-4o and ChatGPT-4o-mini Interaction, pay per message</p></li><li><p>Breaking change: Adopting nip17 to send signal hello message and use new signature scheme</p></li></ul></li><li><p>0xChat App</p><ul><li><p><a href="https://github.com/0xchat-app/0xchat-app-main/releases/tag/v1.4.4-release">v1.4.4</a></p><ul><li><p>Optimize the data storage performance of the Cashu wallet</p></li><li><p>Enable opening external images with 0xChat</p></li><li><p>Add support for customizing the Moment feature</p></li><li><p>Add support for the Persian language</p></li></ul></li><li><p><a href="https://github.com/0xchat-app/0xchat-app-main/releases/tag/v1.4.2-release">v1.4.2</a></p><ul><li><p>Add a text size adjustment setting</p></li><li><p>Add inbox/outbox relays setting</p></li></ul></li></ul></li><li><p>Voyage</p><ul><li><p><a href="https://github.com/dluvian/voyage/releases/tag/v0.17.1">v0.17.1</a></p><ul><li><p>Don&#8217;t allow saving empty lists</p></li><li><p>Treat empty list pairs as deleted</p></li></ul></li><li><p><a href="https://github.com/dluvian/voyage/releases/tag/v0.17.0">v0.17.0</a></p><ul><li><p>Features:</p><ul><li><p>Create polls</p></li><li><p>Filter HomeFeed by roots, cross and polls</p></li><li><p>Show poll end time in post details</p></li></ul></li><li><p>Improvements:</p><ul><li><p>Force nip22 usage when replying with 5 or less characters</p></li><li><p>Set t tags when nip22-replying hashtags</p></li><li><p>Adjust scroll behaviour</p></li></ul></li></ul></li></ul></li><li><p>Nos.social</p><ul><li><p><a href="https://github.com/planetary-social/nos/releases/tag/v1.0.3-294">v1.0.3</a></p><ul><li><p>Add support for user setting and displaying pronouns</p></li><li><p>Add display of website URLs for user profiles</p></li><li><p>Update note header UI to make it more readable</p></li></ul></li></ul></li><li><p>Citrine</p><ul><li><p><a href="https://github.com/greenart7c3/Citrine/releases/tag/v0.5.8">v0.5.8</a></p><ul><li><p>Move database view to a new screen</p></li><li><p>Don&#8217;t send received events to the same connection that sent them</p></li><li><p>Performance improvements when deleting events</p></li><li><p>Check if there&#8217;s a newer version of the event before saving the event to the database</p></li></ul></li><li><p><a href="https://github.com/greenart7c3/Citrine/releases/tag/v0.5.6">v0.5.6</a></p><ul><li><p>Add a option to fetch your events from relays</p></li><li><p>Add a delete all button</p></li><li><p>Feed by kind</p></li></ul></li></ul></li><li><p>Pokey</p><ul><li><p><a href="https://github.com/KoalaSat/pokey/releases/tag/v0.1.2-alpha">v0.1.2</a></p><ul><li><p>Implement Multi-account</p></li></ul></li><li><p><a href="https://github.com/KoalaSat/pokey/releases/tag/v0.1.1-alpha">v0.1.1</a></p><ul><li><p>Notifications now display NIP05 pictures if available</p></li><li><p>Prepare the code for multi-account</p></li><li><p>New APKs available per Arch</p></li></ul></li></ul></li><li><p>Amber <a href="https://github.com/greenart7c3/Amber/releases/tag/v3.0.0">v3.0.0</a></p><ul><li><p>New design (still a work in progress)</p></li><li><p>Open the permissions page with the correct account</p></li><li><p>Option to setup a custom pin for the app</p></li><li><p>Button to copy your public key</p></li><li><p>Better check for valid relays</p></li><li><p>Support for secret when using nostrconnect</p></li></ul></li><li><p>Zapstore <a href="https://github.com/zapstore/zapstore/releases/tag/0.1.7">v0.1.7</a></p><ul><li><p>Performance: Faster, background downloads</p></li><li><p>Feature: Full screen app images</p></li><li><p>Feature: Remember trusted signers</p></li><li><p>Feature: Show certificate mismatch before installing</p></li></ul></li><li><p>SatShoot <a href="https://njump.me/nevent1qqsxd04rw5uv5hygyxmuyu694sjjqgfx2sulk92dssw7xtr84sfefncpp4mhxue69uhkummn9ekx7mqpzemhxue69uhhyetvv9ujumn0wd68ytnzv9hxgq3q6p8v7varqwjes5hak6q7mz6pygqm4pwc6gve4mrned3xs8tz42gq9wasxp">v0.2.0</a> [<a href="https://github.com/Pleb5/satshoot">Github</a>]</p><ul><li><p>Cashu nip60 wallet and payment with nip61 nutzaps: multimint payments, mint exploration, manual and automatic backup and resync mechanisms</p></li><li><p>Rendering of nostr URI-s</p></li></ul></li></ul><h3><strong>Boosts</strong></h3><ul><li><p>Thanks to everyone who streamed sats, and shoutout to our top boosters:</p><ul><li><p>[&#127942; TOP BOOSTER] @forest (3,500 sats) &#8220;&#128074;&#8221;</p></li><li><p>@tac_btc (1,000 sats) &#8220;Thank you&#8221;</p></li><li><p>@Hugh Janus (200 sats) &#8220;https://media.tenor.com/OdfwhhIoccAAAAAC/i-see-south-park.gif&#8221;</p></li><li><p>@edblock &#8220;Great Episode joined by guests Stephan Livera, Rijndael &amp; Ben Carman about apps for Bitcoiners.&#8221;</p></li></ul></li></ul><h3><strong>Tech Tip of the Day</strong></h3><ul><li><p><a href="https://ssd.eff.org/#index">Surveillance Self-Defense</a>: Tips, Tools and How-tos for Safer Online Communications, a project from the Electronic Frontier Foundation</p><ul><li><p>A guide providing practical guides, tips and strategies to help individuals and organizations protect their privacy and security online.</p></li></ul></li></ul><h3><strong>Bitcoin Optech Newsletter</strong></h3><ul><li><p>Highlights from recent Bitcoin Optech Newsletters</p><ul><li><p><a href="https://bitcoinops.org/en/newsletters/2024/12/06/">332</a></p><ul><li><p>Transaction censorship vulnerability: Antoine Riard <a href="https://groups.google.com/g/bitcoindev/c/GuS36ldye7s">posted</a> to the Bitcoin-Dev mailing list about a method for preventing a node from broadcasting a transaction belonging to a connected wallet.</p></li><li><p>Continued discussion about consensus cleanup soft fork proposal: Antoine Poinsot <a href="https://delvingbitcoin.org/t/great-consensus-cleanup-revival/710/53">posted</a> to the existing Delving Bitcoin thread about the consensus cleanup soft fork proposal</p></li></ul></li><li><p><a href="https://bitcoinops.org/en/newsletters/2024/11/29/">331</a></p><ul><li><p>Lisp dialect for Bitcoin scripting: Anthony Towns made several posts about a continuation of his <a href="https://bitcoinops.org/en/topics/basic-bitcoin-lisp-language/">work</a> on creating a Lisp dialect for Bitcoin that could be added to Bitcoin in a soft fork.</p><ul><li><p>bll, symbll, bllsh</p></li><li><p>Implementing quantum-safe signatures in symbll versus GSR</p></li><li><p>Flexible coin earmarks</p></li></ul></li></ul></li></ul></li></ul><h3><strong>News &amp; Noteworthy</strong></h3><h4><strong>Lightning + L2+</strong></h4><ul><li><p>ZEUS Pay cuts lightning address fees and lowers minimum limit [<a href="https://blog.zeusln.com/zeus-pay-lightning-address-fees-slashed-to-zero/">Blog post</a>]</p><ul><li><p>ZEUS Pay announces zero fees for receivers, previously charged 2.5-10% depending on the payment amount. The minimum amount receivable has been reduced to 1 satoshi, previously set at 10 satoshis.</p></li></ul></li><li><p>Non-Custodial Ecash: A Trust-Minimized Payment System by Luke Childs [<a href="https://gist.github.com/lukechilds/307341239beac72c9d8cfe3198f9bfff">Proposal</a>]</p><ul><li><p>The proposal details a protocol leveraging Spillman payment channels, allowing users to hold self-custodial credits redeemable for ecash tokens during transactions. Custodial risk would only exist during payment processing.</p></li></ul></li><li><p>You can now buy a <a href="https://vpnstr.com/">Vpnstr</a> VPN with Cashu, making it the first VPN to accept ecash.</p></li></ul><h4><strong>Business &amp; Finance</strong></h4><ul><li><p>Casa announces <a href="https://casa.io/government">Praetorian by Casa</a>, an offering for governements willing to secure their national bitcoin reserves with self-custody protocols, removing reliance on third-party custodians [<a href="https://x.com/Nneuman/status/1866133180778217554">Announcement</a>]</p></li><li><p>Strike introduces Bill Pay for U.S. customers, allowing them to automate bill payments using either bitcoin or cash directly from their Strike accounts. [<a href="https://strike.me/blog/announcing-strike-bill-pay/">Blog post</a>]</p></li><li><p>BitGo launches BitGo Retail, a retail platform offering trading, custody, staking, and wallets with institutional-grade security and regulatory compliance. [<a href="https://www.businesswire.com/news/home/20241201410604/en/BitGo-Launches-Comprehensive-Retail-Platform">Business Wire</a>]</p></li><li><p>Fold now allows primary account holders to add up to three authorized users, each with their own Fold card. [<a href="https://blog.foldapp.com/add-authorized-users/">Blog post</a>]</p><ul><li><p>This feature enables families to collectively earn bitcoin rewards on eligible purchases under one account.</p></li></ul></li><li><p>Rumble&#8217;s Board of Directors approves allocating up to $20 million of excess cash reserves to Bitcoin, supporting its expansion into cryptocurrency. [<a href="https://corp.rumble.com/blog/rumble-announces-bitcoin-treasury-strategy/">Press release</a>]</p><ul><li><p>The company will determine Bitcoin purchases based on market conditions and business needs, with the strategy subject to change at any time.</p></li></ul></li><li><p>Swan customers are being charged up to $125 for a Fortress &#8216;Admin Fee&#8217;, after the company moved all Fortress Trust accounts to new services providers. [<a href="https://x.com/SwanBitcoin/status/1861566511011221754">Announcement</a>]</p><ul><li><p>The company will cover up to $250 of purchase fees for impacted users in the first half of 2025.</p></li></ul></li><li><p>DMM Bitcoin, a Japanese exchange, announces its closure following a 4503 BTC ($300 million) hack earlier this year. [<a href="https://bitcoin.dmm.com/news/20241202_01">Announcement</a>]</p><ul><li><p>The company agrees to transfer customer accounts and custodial assets to SBI by March 2025.</p></li></ul></li><li><p>MARA acquires a 240 MW interconnection wind farm in Hansford County, Texas, featuring 114 MW operational wind capacity. The project plans to leverage sustainable resources for near-zero energy cost and enable broader renewable energy deployment [<a href="https://ir.mara.com/news-events/press-releases/detail/1383/mara-acquires-wind-farm">Press release</a>]</p></li></ul><h4><strong>Quantum</strong></h4><ul><li><p>Google introduces Willow, a quantum chip with breakthroughs in reducing errors exponentially as more qubits are added. [<a href="https://blog.google/technology/research/google-willow-quantum-chip/">Press release</a>]</p><ul><li><p>In benchmark tests, Willow solves computations in minutes that would take leading supercomputers over 10^25 years.</p></li></ul></li></ul><h4><strong>Funding</strong></h4><ul><li><p>OpenSats <a href="https://opensats.org/blog/renewing-our-commitment-to-bitcoin">renews grant</a> to 9 projects advancing the ecosystem on various fronts: BTCPay Server, Stratum V2, Raspiblitz, LNbits, Vexl, Blixt, Krux, Bitaxe, and Labelbase.</p></li><li><p>Spiral announces two new grants to <a href="https://x.com/spiralbtc/status/1861804173932839174">Bob McElrath</a>, for his work on Braidpool, and <a href="https://x.com/spiralbtc/status/1864706606262255704">Rachel Rybarczyk</a>, core developer at Stratum v2 project.</p></li><li><p>Bitcoin Dev Kit Foundation <a href="https://bitcoindevkit.org/foundation/grantees/">announces</a> grants to Wei Chen, newest BDK&#8217;s full-time Rust maintainer, Evan Lin, part-time Rust maintainer, and Nymius, a new project grantee contributing to Silent Payments and general project maintenance.</p></li><li><p>OCEAN Pool now allows miners to donate rewards directly to the <a href="https://p2prights.org/">P2PRights fund</a> for Samourai Wallet&#8217;s legal defense. [<a href="https://atlas21.com/ocean-supports-samourai-wallets-legal-defense-despite-past-tensions/">Atlas21</a>]</p></li></ul><h4><strong>Mining</strong></h4><ul><li><p>U.S. Customs and Border Protection is holding shipments of Bitmain&#8217;s Antminer S21 and T21 ASIC miners at ports, following a request from the Federal Communications Commission. [<a href="https://blockspace.media/insight/officials-are-halting-bitmain-units-at-u-s-ports-industry-firms-report/">BlockSpace</a>]</p><ul><li><p>Seven U.S.-based bitcoin mining companies report delays of up to two months. Other ASIC manufacturers, such as MicroBT and Canaan, are not affected.</p></li></ul></li><li><p>Bitmain introduces a new production line in the U.S. to improve response times and efficiency for North American customers. [<a href="https://x.com/BITMAINtech/status/1866124016819339335">Announcement</a>]</p></li><li><p>The Public Utility Commission of Texas requires crypto mining facilities consuming over 75 MW to register with ERCOT, detailing their location, ownership, and power usage. [<a href="https://www.texastribune.org/2024/11/25/texas-cryptocurrency-mining-registration-public-utility-commission-er/">Texas Tribune</a>]</p></li><li><p>Bitcoin mining pool issues rewards in ecash, without an account being required. Miners can then withdraw ecash to the Lightning Network or on-chain [<a href="https://njump.me/nevent1qqsys3de3auph4wwcmqcxzzclj6vy5t0zwwe2pdkwke9klf6umuv50cpzemhxue69uhhyetvv9ujumn0wd68ytnzv9hxgq3q6vzjeglr653mrmyqvu0trwaq29az753wr9th3hyrm5p63kz2zu8qalcadd">Note</a>]</p></li></ul><h4><strong>Privacy</strong></h4><ul><li><p>U.S. agencies, including the FBI and <a href="https://www.cisa.gov/resources-tools/resources/enhanced-visibility-and-hardening-guidance-communications-infrastructure">CISA</a>, encourage Americans to adopt end-to-end encrypted messaging apps in response to ongoing cyber threats [<a href="https://arstechnica.com/tech-policy/2024/12/us-recommends-encrypted-messaging-as-chinese-hackers-linger-in-telecom-networks/">ArsTechnica</a>]</p><ul><li><p>U.S. officials reveal an ongoing breach targeting global telecom systems, attributed to the Chinese hacking group &#8220;Salt Typhoon&#8221;, which has compromised at least 8 U.S. telecom providers, more than initially reported.</p></li><li><p>The attack, which began in spring 2024, exploited vulnerabilities in over 80 telecom companies, compromising sensitive data such as call metadata and private communications of political and government-linked individuals.</p></li></ul></li><li><p>EU scrutiny on encrypted messaging: The High Level Group on Data Access highlights challenges law enforcement faces with &#8220;over-the-top&#8221; (OTT) messaging services like Signal, WhatsApp, and Telegram. [<a href="https://www.heise.de/en/news/EU-prosecutors-demand-Sanction-data-saving-messenger-services-10179849.html">Heise</a>]</p><ul><li><p>They advocate &#8220;lawful access by design&#8221; to enable real-time access to encrypted communications while ensuring court oversight for serious crimes.</p></li></ul></li><li><p>Coinbase advises users against using VPNs and ad blockers, citing that its risk models associate them with malicious activity. Product Director Scott Shapiro states these tools often raise security flags, even for legitimate users. [<a href="https://x.com/scottshapiro/status/1863691538661883925">Twitter post</a>]</p></li></ul><h4><strong>Protocol</strong></h4><ul><li><p>Libsecp256k1: Safegcd&#8217;s implementation formally verified by Blockstream Research [<a href="https://bitcoinmagazine.com/technical/safegcds-implementation-formally-verified">Bitcoin Magazine</a>]</p><ul><li><p>The safegcd modular inversion algorithm, implemented in libsecp256k1, was formally verified using the Coq proof assistant. This verification ensures its correct termination and accuracy in 256-bit inputs.</p></li></ul></li><li><p>Bitcoin Core #30039: dbwrapper: Bump LevelDB max file size to 32 MiB to avoid system slowdown from high disk cache flush rate [<a href="https://github.com/bitcoin/bitcoin/pull/30039">Merged</a>]</p></li><li><p>Bitcoin Core #31122: cluster mempool: Implement changeset interface for mempool [<a href="https://github.com/bitcoin/bitcoin/pull/31122">Merged</a>]</p><ul><li><p>Provides a changeset interface for the mempool, enabling a node to evaluate the impact of proposed changes on its state</p></li></ul></li><li><p>Bitcoin Core #30708: rpc: add getdescriptoractivity [<a href="https://github.com/bitcoin/bitcoin/pull/30708">Merged</a>]</p><ul><li><p>The RPC command scanblocks helps retrieve blockhashes with relevant activity for specific descriptors.</p></li></ul></li><li><p>Eclair #2935: Add force-close notification [<a href="https://github.com/ACINQ/eclair/pull/2935">Merged</a>]</p></li><li><p>NIP #1551: Instagram feeds [<a href="https://github.com/nostr-protocol/nips/pull/1551">Merged</a>]</p></li><li><p>NUT-19 Cached responses: The NUT adds idempotency to key endpoints, enhancing the reliability of the Cashu protocol. [<a href="https://github.com/cashubtc/nuts/blob/main/19.md">Merged</a>]</p></li></ul><h4><strong>Government &amp; Political</strong></h4><ul><li><p>Brazilian Congressman Eros Biondini introduces RESBit, a bill for a national bitcoin reserve, suggesting an allocation of up to 5% of Brazil&#8217;s $372 billion international reserves. [<a href="https://www.theblock.co/post/328448/brazilian-lawmaker-proposes-national-bitcoin-reserve-to-hedge-economic-risks">The Block</a>]</p><ul><li><p>The bill aims to diversify financial assets and strengthen Brazil&#8217;s resilience against currency fluctuations and geopolitical uncertainties.</p></li></ul></li><li><p>El Salvador considers adjusting bitcoin policy to secure IMF loan [<a href="https://archive.ph/4MU39#selection-1749.0-2505.0">Financial Times</a>]</p><ul><li><p>A proposed legal change would allow merchants to choose whether to accept bitcoin. This adjustment is part of conditions set by the IMF for a $1.3 billion loan, alongside $2 billion from other international lenders.</p></li></ul></li><li><p>Czech Republic removes capital gains tax on digital assets held for over 3 years, starting December 2024 [<a href="https://www.theblock.co/post/329788/czech-republic-scraps-capital-gains-tax-on-crypto-held-for-over-3-years">The Block</a>]</p></li><li><p>Fifth Circuit overturns Tornado Cash sanctions, citing overreach by OFAC [<a href="https://www.therage.co/fifth-circuit-lifts-tornado-cash-sanctions/">The Rage</a>]</p><ul><li><p>The court rejected the government&#8217;s claim that Tornado Cash operates as a service, explaining that its smart contracts are lines of code, not human-driven services. It also clarified that Tornado Cash cannot control its immutable contracts, distinguishing them from mutable, user-controlled systems.</p></li></ul></li><li><p>Damian Williams steps down as U.S. Attorney for the Southern District of New York after overseeing Samourai Wallet and Tornado Cash cases [<a href="https://www.justice.gov/usao-sdny/pr/us-attorney-damian-williams-announces-anticipated-resignation-southern-district-new">Press release</a>]</p></li><li><p>The Canton of Bern, in Switzerland, approves a feasibility study to explore Bitcoin mining&#8217;s potential within its energy framework. [<a href="https://atlas21.com/canton-bern-evaluates-bitcoin-mining-for-power-grid-stability/">Atlas21</a>]</p><ul><li><p>The study focuses on identifying surplus energy, collaborating with Swiss miners, and evaluating mining&#8217;s impact on grid stability.</p></li></ul></li><li><p>Operation Choke Point 2.0: U.S. regulators&#8217; actions against crypto activities revealed in FDIC letters [<a href="https://www.coindesk.com/policy/2024/12/05/u-s-regulator-told-banks-to-lay-off-crypto-letters-obtained-by-coinbase-reveal">CoinDesk</a>]</p><ul><li><p>The FDIC&#8217;s &#8220;pause letters&#8221; dated back to March 2022, with officials advising banks to halt crypto services until further risk assessments were made.</p></li></ul></li><li><p>Russia&#8217;s president signs a law recognizing digital currencies as property, enabling taxation of mining and transactions. [<a href="https://www.themoscowtimes.com/2024/11/29/putin-signs-law-on-cryptocurrency-tax-a87172">The Moscow Times</a>]</p><ul><li><p>Cryptocurrency mining and sales are exempt from VAT but subject to income tax at tiered rates. Corporate entities face a 25% tax starting next year.</p></li><li><p>A database of government-approved miners was launched in November. Another law permits the Central Bank to pilot cross-border cryptocurrency transactions.</p></li></ul></li><li><p>Morocco&#8217;s central bank is adopting a draft law to regulate cryptocurrencies, which have been banned since 2017. [<a href="https://www.reuters.com/technology/morocco-preparing-law-allow-cryptocurrencies-central-bank-chief-says-2024-11-26/">Reuters</a>]</p><ul><li><p>Bank Al Maghrib is also considering the development of a central bank digital currency (CBDC) to enhance financial inclusion.</p></li></ul></li><li><p>Taiwan&#8217;s Financial Supervisory Commission (FSC) enforces stricter AML rules for digital assets service providers starting November 30, 2024. [<a href="https://www.theblock.co/post/328729/taiwan-fast-tracks-aml-rules-stricter-crypto">The Block</a>]</p><ul><li><p>FSC officials emphasize fraud prevention and tighter oversight, including regulations on fiat custody, data security, complaint handling, and record-keeping.</p></li></ul></li></ul><h4><strong>Events</strong></h4><ul><li><p><a href="https://planb.sv/">Plan &#8383; Forum El Salvador</a></p><ul><li><p>Central America&#8217;s premier Bitcoin conference, uniting global leaders, technologists, and entrepreneurs.</p></li><li><p>January 30-31, 2025 in San Salvador, El Salvador</p></li></ul></li><li><p><a href="https://bitcoinmedellin.com/">Bitcoin Medellin</a></p><ul><li><p>The first ever Bitcoin Medellin Conference</p></li><li><p>January 17-18, 2025 in Medellin, Colombia</p></li></ul></li></ul><h3><strong>Reads</strong></h3><ul><li><p>Here&#8217;s a list of our top recently published reads:</p><ul><li><p>Erosion of the Meaning of Custody, by Nicolas Dorier [<a href="https://blog.nicolas-dorier.com/posts/custody/">Blog post</a>]</p></li><li><p>Buckets of blind signatures, by Callebtc [<a href="https://blog.cashu.space/buckets-of-blind-signatures/">Blog post</a>]</p></li><li><p>Financial surveillance in the United States: How the Federal Government weaponized the Bank Secrecy Act to spy on Americans [<a href="https://judiciary.house.gov/sites/evo-subsites/republicans-judiciary.house.gov/files/2024-12/2024-12-05-Financial-Surveillance-in-the-United-States.pdf">Report</a>]</p></li><li><p>Privacy in Public Part 3: Cash and Bitcoin, by BPI Fellows Andrew Bailey, Bradley Rettler, and Craig Warmke [<a href="https://www.btcpolicy.org/articles/privacy-in-public-part-3-cash-and-bitcoin">Bitcoin Policy Institute</a>]</p></li><li><p>Understanding Liability for Unlicensed Money Transmitting Businesses under &#167; 1960, by Daniel Barabander, Amanda Tuminelli and Jake Chervinsky [<a href="https://edit.financialcrimelitigators.org/api/assets/cd682a1c-1cb0-4c99-a491-ac6155f4bdc2.pdf">Paper</a>]</p></li><li><p>Hodlers: an apology, by the Financial Times [<a href="https://www.ft.com/content/8533f856-57f1-4765-a3dc-d866543092be">Article</a>]</p></li></ul></li></ul><h3><strong>Episode submission ideas</strong></h3><ul><li><p>We&#8217;re looking for ideas for interesting panel conversations. To send Bitcoin related questions, just go to <a href="https://bitcoin.review/">bitcoin.review</a> and follow the contact links at the bottom of the page.</p></li></ul><h3><strong>Get in touch with the pod</strong></h3><ul><li><p><a href="https://twitter.com/bitcoinreviewhq">Podcast Twitter</a></p></li><li><p><a href="https://twitter.com/nvk">NVK Twitter</a></p></li><li><p><a href="https://t.me/BitcoinReviewPod">Telegram</a></p></li><li><p><a href="mailto:producer@coinkite.com">Email</a></p></li><li><p>Nostr &amp; LN &#9889;nvk@nvk.org (not an email!)</p></li></ul>]]></content:encoded></item><item><title><![CDATA[Bitcoin Review Podcast BR088 - AnchorWatch, Bitkey, Krux, Primal, Proton Wallet, Kagi, Debifi, Namecheap $73M bitcoin revenue + MORE ft. Livera, Rijndael & Ben]]></title><description><![CDATA[I&#8217;m joined by guests Stephan Livera, Rijndael & Ben Carman to go through the list.]]></description><link>https://substack.bitcoin.review/p/bitcoin-review-podcast-br088-anchorwatch</link><guid isPermaLink="false">https://substack.bitcoin.review/p/bitcoin-review-podcast-br088-anchorwatch</guid><dc:creator><![CDATA[STACK TO THE FUTURE]]></dc:creator><pubDate>Wed, 27 Nov 2024 20:48:37 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a95ac75-ac77-4167-9383-9930a48690bb_1080x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I&#8217;m joined by guests <a href="https://twitter.com/stephanlivera">Stephan Livera</a>, <a href="https://twitter.com/rot13maxi">Rijndael</a> &amp; <a href="https://twitter.com/benthecarman">Ben Carman</a> to go through the list.</p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://bitcoin.review/podcast/episode-56/&quot;,&quot;text&quot;:&quot;Listen on your favorite podcast app&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://bitcoin.review/podcast/episode-56/"><span>Listen on your favorite podcast app</span></a></p><div><hr></div><h3><strong>Housekeeping</strong></h3><ul><li><p>00:05:29 <a href="https://bitcoin.review/podcast/episode-88/bitcoinblackfriday.org">Bitcoin Black Friday</a></p></li><li><p>00:06:05 AnchorWatch gains Lloyd&#8217;s of London Coverholder status [<a href="https://www.businesswire.com/news/home/20241118360660/en/AnchorWatch-Becomes-Lloyds-of-London-Coverholder-Set-to-Begin-Operations-in-December-2024">Business Wire</a>]</p><ul><li><p>Starting December 2024, it will offer insured bitcoin custody solutions backed by Lloyd&#8217;s syndicates, allowing coverage of up to $100M per customer.</p></li><li><p>Its proprietary Trident Vault integrates advanced security features with 1-to-1 insured custody, addressing theft, fraud, and catastrophic risks for retail and institutional investors.</p></li></ul></li></ul><h3><strong>Urgent Vulnerability Disclosures</strong></h3><ul><li><p>00:10:25 Krux releases security fix for AES-CBC encryption flaw [<a href="https://github.com/selfcustody/krux/releases/tag/v24.11.1">Github</a>]</p><ul><li><p>Issue #477 revealed camera-captured entropy wasn&#8217;t properly utilized in AES-CBC encryption, reducing its intended security strength. This affected backups stored on flash drives, SD cards, and encrypted QR codes by users who switched from the default AES-ECB mode.</p></li><li><p>Affected users are recommended install the latest update to resolve the issue. After updating, they should recreate all backups to apply the corrected encryption and restore full security.</p></li></ul></li></ul><h3><strong>Bitcoin</strong></h3><h4><strong>Software Releases &amp; Project Updates</strong></h4><ul><li><p>00:16:05 <a href="https://github.com/taproot-wizards/bitcoin-script-hints.nvim">bitcoin-script-hints</a>: A magical neovim plugin for Bitcoin Script by Taproot Wizards</p></li></ul><h3><strong>News &amp; Noteworthy</strong></h3><h4><strong>Business &amp; Finance</strong></h4><ul><li><p>Leading domain registrars Namecheap surpasses $73M in bitcoin revenue since its 2020 BTCPay integration [<a href="https://blog.btcpayserver.org/case-study-namecheap/">BTCPay Blog</a>]</p></li></ul><h3><strong>Bitcoin (Cont.)</strong></h3><h4><strong>Software Releases &amp; Project Updates</strong></h4><ul><li><p>00:17:14 BDK <a href="https://github.com/bitcoindevkit/bdk/releases/tag/v0.30.0">v0.30.0</a></p><ul><li><p>This release bumps the MSRV to 1.63.0 and updates the rusqlite dependency version to 0.31 to be aligned with the upcoming 1.0.0 release. These changes will prepare projects for migrating wallet data to the 1.0.0 version of BDK.</p></li></ul></li><li><p>00:17:38 BTCPay Server <a href="https://github.com/btcpayserver/btcpayserver/releases/tag/v2.0.3">v2.0.3</a></p><ul><li><p>&#8220;If you are using Boltcards, we advise you to update to this release.&#8221;</p></li><li><p>New features:</p><ul><li><p>Greenfield: Histograms: Add Lightning data and API endpoints</p></li><li><p>Greenfield: Add image upload for app items</p></li></ul></li></ul></li><li><p>00:19:53 Nunchuk Desktop <a href="https://github.com/nunchuk-io/nunchuk-desktop/releases/tag/1.9.40">v1.9.40</a> / Android <a href="https://github.com/nunchuk-io/nunchuk-android/releases/tag/android.1.9.54">v1.9.54</a></p><ul><li><p>Support Coldcard as inheritance key</p></li><li><p>Option to Send all remaining for batch transactions</p></li></ul></li><li><p>00:20:20 Proton Wallet <a href="https://x.com/ProtonWallet/status/1858533691422544035">Update</a></p><ul><li><p>Adds Replace-By-Fee (RBF), to speed up the confirmation speed of transactions</p></li></ul></li><li><p>00:23:58 Bitcoin Keeper</p><ul><li><p><a href="https://github.com/bithyve/bitcoin-keeper/releases/tag/v1.2.20">v1.2.20</a></p><ul><li><p>Redesign transaction priority screen</p></li><li><p>Enable remote Key sharing and signing for Blockstream Jade and seed key</p><ul><li><p>Improve transaction fee estimation</p></li></ul></li><li><p>Add transaction details to view while signing external PSBTs</p></li></ul></li><li><p><a href="https://github.com/bithyve/bitcoin-keeper/releases/tag/v1.2.19">v1.2.19</a></p><ul><li><p>Coldcard vault registration via NFC - Android bug fixed</p></li></ul></li></ul></li><li><p>00:24:40 Nix Bitcoin <a href="https://github.com/fort-nix/nix-bitcoin/releases/tag/v0.0.115">v0.0.115</a></p><ul><li><p>bitcoind: 27.1 -&gt; 28.0</p></li><li><p>clboss: 0.13.3 -&gt; 0.14.0</p></li><li><p>electrs: 0.10.5 -&gt; 0.10.6</p></li><li><p>trustedcoin: 0.8.2 -&gt; 2024-11-1</p></li><li><p>The lnd module&#8217;s ExecStartPost script is now extensible with custom scripts</p></li></ul></li><li><p>00:25:09 Krux <a href="https://github.com/selfcustody/krux/releases/tag/v24.11.0">v24.11.0</a></p><ul><li><p>Tamper Check Flash Hash and Tamper Check Code (Experimental): the feature verifies the integrity of the device&#8217;s flash memory by generating a unique tamper indicator that relies on hash properties</p></li><li><p>Add Flash Map: an auxiliary tool that allows users to visualize the regions of the device&#8217;s memory that are empty</p></li><li><p>Add Japanese Translation</p></li><li><p>BIP85: Allow Export Base64 Passwords</p></li><li><p>Vulnerability Fix: Block Import of Python Modules from SD Card</p></li><li><p>Add Compatibility to Partial Text Mnemonic QR Codes</p></li><li><p>Add Multi-keypad Position Indicator</p></li><li><p>Add Computer simulator for WonderMV device</p></li><li><p>Krux Ethos: Guidelines have been created to assist with decision-making regarding the Krux project&#8217;s interactions</p></li></ul></li><li><p>00:26:49 RoboSats <a href="https://github.com/RoboSats/robosats/releases/tag/v0.7.3-alpha">v0.7.3</a></p><ul><li><p>Websockets now working on Android app: this enables instant chat and Nostr order book features</p></li><li><p>First external coordinator now available: you can now see @lnp2pBot orders on RoboSats UI</p></li><li><p>Better display coordinator info on the Create Order form</p></li><li><p>Charts now depend on selected currency</p></li></ul></li><li><p>00:26:57 Bitkey App <a href="https://bitkey.world/en-US/releases">v2024.73.0</a></p><ul><li><p>Now see Coinbase offers alongside other partner exchanges when you sell bitcoin.</p></li><li><p>Bitkey introduces an inheritance feature, enabling users to designate a single beneficiary for simplified fund transfer after their passing. A 6-month waiting period safeguards against fraudulent or accidental claims. [<a href="https://bitkey.build/inheritance-simplifying-the-transfer-of-bitcoin-to-future-generations/">Blog post</a>]</p><ul><li><p>Beneficiaries must set up a Bitkey wallet to receive funds, but cannot view the benefactor&#8217;s wallet details. Owners retain control over beneficiary changes.</p></li></ul></li></ul></li><li><p>00:31:07 RewindBitcoin <a href="https://x.com/landabaso/status/1860353605305307560">v1.1.3</a></p><ul><li><p>Enhancements:</p><ul><li><p>Emergency Addresses are now pre-filled by default, with contextual help provided</p></li><li><p>The app is now more resilient: it operates independently, even if backend services are unavailable or the backend goes offline</p></li></ul></li><li><p>Robustness to Network Errors:</p><ul><li><p>Automated and reasonable retries for network failures</p></li><li><p>Improved handling of Electrum node disconnections</p></li><li><p>Friendly, actionable error messages for poor connectivity</p></li><li><p>Optimized timeouts for better performance in weak network conditions</p></li><li><p>Avoids unnecessary network usage while the app is in the background and resumes seamlessly when restored to the foreground</p></li></ul></li></ul></li><li><p>00:35:15 Umbrel <a href="https://github.com/getumbrel/umbrel/releases/tag/1.3.0-beta.3">v1.3.0</a></p><ul><li><p>Swappable apps: You can now choose which Bitcoin node app you want to run: Bitcoin Node, Bitcoin Knots, or Libre Relay, and select your preferred Electrum server app: Electrs, Fulcrum, or ElectrumX.</p></li><li><p>Cloudflare DNS: Enable Cloudflare DNS for improved reliability, or disable it to inherit DNS settings from your router.</p></li><li><p>Add Factory Reset option</p></li></ul></li><li><p>00:35:32 ESP-Miner <a href="https://github.com/skot/ESP-Miner/releases/tag/v2.4.0">v2.4.0</a></p><ul><li><p>Re-worked how we publish artifacts when releasing new builds</p></li><li><p>Use the same espressif/idf release for github and vscode</p></li><li><p>Add OLED Bitaxe logo screen</p></li><li><p>Add all in one factory file script</p></li><li><p>Replace default address with a prompt</p></li><li><p>Add info for check on update</p></li></ul></li><li><p>00:35:36 Boltz boltz-web-app <a href="https://github.com/BoltzExchange/boltz-web-app/releases/tag/v1.5.1">v1.5.1</a></p><ul><li><p>Disable EVM connect button for invalid pairs</p></li><li><p>Loading spinner when fetching signer balance</p></li><li><p>Add RSK to mainnet config</p></li></ul></li></ul><h4><strong>Project spotlight</strong></h4><ul><li><p>00:35:43 <a href="https://wallet.tether.io/">Wallet Dev Kit</a> (WDK) by Tether: a multi asset cryptocurrency wallet library in JavaScript. [<a href="https://docs.wallet.tether.io/">Documentation</a>]</p><ul><li><p>&#8220;An open-source, self-custodial toolkit for developers to create Bitcoin and USD&#8366; wallets for humans, AI and robots&#8221;</p></li></ul></li><li><p>00:35:51 ScriptLab: Uncomplicating Bitcoin Script: Learn and Code Scripts with blocks [<a href="https://github.com/bellujrb/scriptlab">Github</a>]</p><ul><li><p>Script Lab allows users to create Bitcoin scripts through an intuitive drag-and-drop interface or by generating basic scripts via chat</p></li></ul></li><li><p>00:36:04 Mempal: A Bitcoin mempool monitoring and notification app for Android. [<a href="https://github.com/aeonBTC/Mempal">Github</a>]</p><ul><li><p>&#8220;Mempal is a Bitcoin monitoring app that allows users to effortlessly track real-time fee rates and mempool depth for smarter transaction management.&#8221;</p></li></ul></li><li><p>00:36:44 <a href="https://debifi.com/">Debifi</a>: A Bitcoin-backed lending platform providing institutional-grade liquidity</p><ul><li><p>Debifi App <a href="https://x.com/debificom/status/1858897785044500642">Update</a></p><ul><li><p>Add support for Coldcard</p></li><li><p>Now available on the App Store</p></li></ul></li></ul></li><li><p>00:37:41 Dart-bip85 package: A Flutter binding for the rust-bip85 which is an updated version of the original rust-bip85. [<a href="https://pub.dev/packages/bip85">Repository</a>]</p></li><li><p>00:37:45 Descriptors Go: An experimental Go library to handle Bitcoin output descriptors, including miniscript and tapminiscript. [<a href="https://github.com/benma/descriptors-go/">Github</a>]</p></li><li><p>00:37:47 tick-tock-tui: A TUI app to handle Bitcoin data provided by Mempool: fees, blocks and price converter. [<a href="https://github.com/sectore/tick-tock-tui">Github</a>]</p></li><li><p>00:37:56 Awesome-bitcoin-guide: The Ultimate Bitcoin Guide: Secure, Private, and Informed Usage, by iAnonymous3000 [<a href="https://github.com/iAnonymous3000/awesome-bitcoin-guide">Github</a>]</p><ul><li><p>Comprehensive Bitcoin guide focusing on operational security, wallet management, privacy best practices, and risk mitigation</p></li></ul></li><li><p>00:38:30 BitAxe HAS Dashboard: A Home Assistant dashboard for BitAxe Miners [<a href="https://github.com/satoshiradio/bitaxe-HAS-dashboard">Github</a>]</p><ul><li><p>&#8220;This dashboard brings all your BitAxe miners and Satoshi Radio pool stats together in one clean, informative interface.&#8221;</p></li></ul></li><li><p>00:38:39 <a href="https://www.radpool.xyz/1/index.html">Radpool</a>: Syndicated Mining Pool</p><ul><li><p>Radpool introduces a syndicated design, using Mining Service Providers (MSPs) to decentralize bitcoin mining and reduce transaction censorship risks.</p></li></ul></li><li><p>00:38:43 <a href="https://satadelica.btcdir.org/">Satadelica</a>: A trippy Bitcoin price visualiser [<a href="https://github.com/BXL909/Satadelica">Github</a>]</p><ul><li><p>Updates real-time Bitcoin metrics like price, block height and hashrate, and allow users to visualize market movements through &#8216;trippy&#8217; graphics and tools.</p></li></ul></li></ul><h3><strong>Vulnerability Disclosures</strong></h3><ul><li><p>00:39:16 Nearest neighbor attack: exploiting nearby Wi-Fi for covert access [<a href="https://www.volexity.com/blog/2024/11/22/the-nearest-neighbor-attack-how-a-russian-apt-weaponized-nearby-wi-fi-networks-for-covert-access/">Volexity</a>]</p><ul><li><p>Russian APT GruesomeLarch&#8217;s novel Wi-Fi breach: The group leveraged nearby networks to infiltrate a Ukrainian-focused organization&#8217;s systems. Proximity was key in this &#8220;Nearest Neighbor Attack,&#8221; bypassing MFA-protected services by exploiting Wi-Fi credentials.</p></li></ul></li><li><p>00:39:27 New Ghost Tap attack exploits NFC mobile payments for fraud [<a href="https://www.bleepingcomputer.com/news/security/new-ghost-tap-attack-abuses-nfc-mobile-payments-to-steal-money/">Bleeping Computer</a>]</p><ul><li><p>The Ghost Tap attack exploits stolen credit card data and NFC technology to commit scalable financial fraud through global networks of money mules.</p></li><li><p>Attackers use banking malware and phishing to obtain payment credentials, relaying NFC card details remotely via servers.</p></li></ul></li><li><p>00:39:38 Leaked documents reveal Graykey, a phone unlocking tool, provides only partial access to iPhones running iOS 18 and 18.0.1, including the iPhone 12 through iPhone 16 series. [<a href="https://archive.ph/hdWRw">404Media</a>]</p><ul><li><p>Graykey&#8217;s capabilities with Android devices vary, with limited access on newer Pixel phones unless unlocked at least once, highlighting challenges due to the range of Android manufacturers.</p></li></ul></li><li><p>00:40:38 OverSecured researchers discover seven vulnerabilities in Android and Google Pixel devices, affecting millions of users worldwide.[<a href="https://blog.oversecured.com/Disclosure-of-7-Android-and-Google-Pixel-Vulnerabilities/">Oversecured</a>]</p><ul><li><p>Vulnerabilities allow unprivileged apps to access geolocation and grant VPN bypass privileges, posing significant security risks. Other issues include arbitrary file theft via WebView, incorrect Bluetooth permission checks, and HTML injection vulnerabilities, all of which have been fixed by Google.</p></li></ul></li><li><p>00:41:03 Apple urgently patches vulnerabilities affecting macOS and iOS, including CVE-2024-44308 (arbitrary code execution) and CVE-2024-44309 (cross-site scripting). [<a href="https://www.securityweek.com/apple-confirms-zero-day-attacks-hitting-intel-based-macs/">Security Week</a>]</p><ul><li><p>The flaws involve JavaScriptCore and WebKit, primarily targeting Intel-based macOS devices. Apple advises immediate updates to macOS Sequoia 15.1.1 and iOS versions.</p></li></ul></li><li><p>00:41:32 Decades-old security flaws in Ubuntu&#8217;s Needrestart Package [<a href="https://thehackernews.com/2024/11/decades-old-security-vulnerabilities.html">The Hacker News</a>]</p><ul><li><p>Researchers discover local privilege escalation vulnerabilities in Ubuntu&#8217;s needrestart package, installed since version 21.04. Exploits allow attackers to gain root access via manipulated environment variables like PYTHONPATH and RUBYLIB.</p></li></ul></li><li><p>00:41:48 Chinese man arrested in Bangkok for operating, from a van, a 3km-range SMS blaster targeting populated areas, sending one million phishing messages per hour [<a href="https://x.com/sickcodes/status/1859979785847570718">Twitter post</a>]</p></li><li><p>D-Link discontinues legacy routers over remote code execution flaw [<a href="https://www.bleepingcomputer.com/news/security/d-link-urges-users-to-retire-vpn-routers-impacted-by-unfixed-rce-flaw/">Bleeping Computer</a>]</p><ul><li><p>D-Link urges users to replace DSR-150 and DSR-250 VPN routers due to an unfixed remote code execution vulnerability. The issue affects all hardware and firmware versions, with no patch planned.</p></li></ul></li><li><p>00:42:28 Five dollar wrench attack:</p><ul><li><p>A gym trainer in Mira Road, Mumbai, was robbed of ~$56,000 by an eight-member gang during a USDT cryptocurrency deal. [<a href="https://www.latestly.com/india/news/cryptocurrency-scam-in-mumbai-gym-trainer-robbed-of-inr-13-5-lakh-by-gang-of-8-in-mira-road-while-trying-to-buy-usdt-cryptocurrency-case-registered-6421852.html">LatestLy</a>]</p></li></ul></li></ul><h3><strong>Privacy &amp; Other Related Bitcoin Projects</strong></h3><h4><strong>Software Releases &amp; Project Updates</strong></h4><ul><li><p>00:42:53 SimpleX</p><ul><li><p><a href="https://github.com/simplex-chat/simplex-chat/releases/tag/v6.2.0-beta.1">v6.2.0-beta.1</a></p><ul><li><p><a href="https://runonflux.com/">Flux</a> - the second pre-configured operator in the app to improve metadata privacy</p></li><li><p>Improved chat navigation (Android/desktop apps):</p><ul><li><p>Open chat on the first unread message</p></li><li><p>Jump to quoted messages anywhere in the conversation</p></li></ul></li></ul></li><li><p><a href="https://github.com/simplex-chat/simplex-chat/releases/tag/v6.2.0-beta.0">v6.2.0-beta.0</a></p><ul><li><p>Edge-to-edge interface with translucent toolbars*</p></li><li><p>Reachable UI in desktop apps - greatly reduces risks to send a message to a wrong chat accidentally</p></li><li><p>Conversation and settings toolbars moved to the bottom with reachable UI*</p></li><li><p>Don&#8217;t ask passcode/biometric to open your chat profiles (only required to add/delete)</p></li><li><p>Better stability of iOS notifications delivery</p></li><li><p>Android and desktop apps</p></li></ul></li></ul></li><li><p>00:43:06 Signal</p><ul><li><p>Introduces <a href="https://signal.org/blog/call-links/">Call Links</a> and enables users to share unique meeting URLs for quick access to calls without forming group chats. Admin controls and reusable links improve flexibility for recurring meetings.</p></li></ul></li></ul><h4><strong>Project spotlight</strong></h4><ul><li><p>00:43:28 <a href="https://deflock.me/">DeFlock</a>: An open-source crowdsourced project mapping Automated License Plate Readers (ALPRs) around the world</p><ul><li><p>The project aims to raise public awareness about the widespread use of ALPRs, the privacy implications, and the extent of surveillance networks.</p></li></ul></li></ul><h3><strong>Lightning + L2+</strong></h3><h4><strong>Project spotlight</strong></h4><ul><li><p>00:43:56 Phoenix Server Lightning Wallet: An open-source wallet built on top of phoenixd [<a href="https://github.com/ZapriteApp/phoenix-server-wallet">Github</a>]</p><ul><li><p>This project is a Lightning wallet interface built on top of Phoenixd server designed for Umbrel Server and Start9</p></li><li><p>It lets you easily manage your phoenixd transactions and leverage the power of Phoenixd for your Bitcoin Lightning wallet needs</p></li></ul></li><li><p>00:44:32 <a href="https://brrr.gandlaf.com/">Cashu Brrr</a>: Cashu ecash money printer [<a href="https://github.com/gandlafbtc/cashu-brrr">Github</a>]</p><ul><li><p>Print your own ecash notes using either ecash from the same mint or Lightning</p></li></ul></li><li><p>00:45:08 SING4SATS: Karaoke: A web client which allows users to request songs to be added to the queue, leveraging LNURL and Fedimod [<a href="https://github.com/JCm8/sing4sats-client">Github</a>]</p></li></ul><h4><strong>Software Releases &amp; Project Updates</strong></h4><ul><li><p>00:45:44 Primal <a href="https://github.com/PrimalHQ/primal-android-app/releases/tag/2.0.21">v2.0.21</a></p><ul><li><p>Updates:</p><ul><li><p>New tab: READS</p></li><li><p>New tab: EXPLORE</p></li><li><p>Feed Marketplace</p></li><li><p>Advanced Search</p></li></ul></li><li><p>Launch Primal Premium: obtain a Primal name and Nostr tools for power users for $7 per month.</p></li></ul></li><li><p>00:47:27 LND <a href="https://github.com/lightningnetwork/lnd/releases/tag/v0.18.4-beta.rc1">v0.18.4rc1</a></p><ul><li><p>The main channel state machine and database now allow for processing and storing custom Taproot script leaves, allowing the implementation of custom channel types</p></li><li><p>A new <code>protocol.simple-taproot-overlay-chans</code> configuration item/CLI flag was added to turn on custom channel functionality</p></li><li><p>Compatibility with bitcoind v28.0 was ensured by updating the version the CI pipeline is running against</p></li><li><p>Performance Improvements: A new method AssertTxnsNotInMempool has been added to lntest package to allow batch exclusion check in itest</p></li></ul></li><li><p>00:48:05 Cashu Development Kit <a href="https://github.com/cashubtc/cdk/releases/tag/v0.5.0">v0.5.0</a></p><ul><li><p>This release included support with NUT-17 websockets for the mint as well as many bug fixes and improvements.</p><ul><li><p>Add description to <code>MintQuoteBolt11Request</code></p></li><li><p>Add description to <code>mint_quote</code></p></li><li><p>Add <code>amount</code> and <code>fee_paid</code> to <code>Melted</code></p></li><li><p>Add <code>from_proofs</code> on <code>Melted</code></p></li><li><p>Add unit on <code>PaymentResponse</code></p></li><li><p>Add description for mint quote</p></li><li><p>Add cache to some endpoints</p></li><li><p>Add Proofs trait</p></li><li><p>Wallet verifies keyset id when first fetching keys</p></li><li><p>NUT18 payment request support</p></li><li><p>Add <code>Wallet::get_proofs_with</code></p></li><li><p>Mint NUT-17 Websocket support</p></li></ul></li></ul></li><li><p>00:48:36 Phoenix Wallet <a href="https://github.com/ACINQ/phoenix/releases/tag/android-v2.4.3">v2.4.3</a></p><ul><li><p>Redesigned the screen for sending payments: The contacts list and a free-form text input are now displayed first, instead of trying to open the scanner immediately. A button to read QR codes on images stored on disk has also been added.</p></li><li><p>Photos can now be attached to contacts (Android): You can also use an image from your device&#8217;s gallery. Photos are stored in the app private folder. Note that on iOS this feature was added in a previous version.</p></li></ul></li><li><p>00:48:47 Zeus</p><ul><li><p>Wallet <a href="https://github.com/ZeusLN/zeus/releases/tag/v0.9.3-beta1">v0.9.3-beta1</a></p><ul><li><p>Channel reserve display</p></li><li><p>Bitcoin denominated amounts: display with spaces</p></li><li><p>ZEUS Pay: UX improvements</p></li></ul></li><li><p>Zeus Pay <a href="https://njump.me/nevent1qgsrf5h4ya83jk8u6t9jgc76h6kalz3plp9vusjpm2ygqgalqhxgp9gqyrw6d974sgj6sf4m7x6zdv095y4ahenl59fv63rwde6hucr3ug2sg6sgvm8">Update</a></p><ul><li><p>All payments will incur no fee for the receiver (previously 2.5-10% depending on amount)</p></li><li><p>The minimum amount receivable has been lowered to 1 satoshi (previously 10 satoshis)</p></li></ul></li><li><p>Zeus introduces Zeus White: White glove node management, point of sale, and integrated enterprise solutions for businesses [<a href="https://blog.zeusln.com/introducing-zeus-white/">Announcement</a>]</p></li></ul></li><li><p>00:49:56 Nutstash <a href="https://github.com/gandlafbtc/nutstash-wallet/releases/tag/nutstash-v2.0.1">v2.0.1</a></p><ul><li><p>New re-build</p></li><li><p>Multi-mint selection</p></li><li><p>Wallet Backup</p></li><li><p>New Ui</p></li><li><p>Integrated Nostr DM</p></li><li><p>Contact list</p></li><li><p>Zap contacts</p></li></ul></li><li><p>00:49:59 Nutshell <a href="https://github.com/cashubtc/nutshell/releases/tag/0.16.3">v0.16.3</a></p><ul><li><p>Mint:</p><ul><li><p>bolt11 invoices with different units on the same mint now settle externally via the Lightning network</p></li><li><p>Turn on multipath payments (MPP) by default for LND and CLN</p></li><li><p>NUT-06: Signal alternative URLs to reach the mint from using <code>.env</code> var <code>MINT_INFO_URLS</code></p></li></ul></li><li><p>Wallet:</p><ul><li><p>Store Lightning invoices in new melt and mint quote tables</p></li><li><p>Sort outputs by amount to mitigate transaction amount privacy leaks</p></li></ul></li></ul></li><li><p>00:50:07 Fountain <a href="https://blog.fountain.fm/p/1-1-8">v1.1.8</a></p><ul><li><p>Add and upvote tracks in the queue</p></li><li><p>Support the artist currently playing</p></li><li><p>Post in the live chat</p></li><li><p>Save tracks to your library</p></li><li><p>Listen to Fountain Radio on other apps</p></li><li><p>Artist Takeovers: Artists can now take control of the music and host a listening party or an AMA</p></li><li><p>Add prompt to share to Nostr after creating a clip</p></li><li><p>Add OPML file explorer</p></li></ul></li><li><p>00:50:10 Breez SDK <a href="https://github.com/breez/breez-sdk-greenlight/releases/tag/0.6.4">v0.6.4</a> - Native (Greenlight Implementation)</p><ul><li><p>Improve sync performance by moving to an incremental sync</p></li><li><p>Improve trampoline payments reliability and fix fees passed to the trampoline node</p></li><li><p>Add list_swaps API</p></li><li><p>Auto recover network connections after hibernation</p></li><li><p>Stability fixes for trampoline payments</p></li></ul></li><li><p>Ride-The-Lightning <a href="https://github.com/Ride-The-Lightning/RTL/releases/tag/v0.15.4">v0.15.4</a></p><ul><li><p>Improve authentication logic for clearer error handling and validation during login and password reset processes</p></li><li><p>Refine application settings handling to ensure stricter validation of access keys</p></li></ul></li><li><p>00:50:14 Lnp2pBot <a href="https://github.com/lnp2pBot/bot/releases/tag/v0.11.1">v0.11.1</a></p><ul><li><p>Show the previous Status to DISPUTE in dispute message for solvers</p></li><li><p>Add MWK currency</p></li><li><p>Add community stats</p></li></ul></li><li><p>00:50:17 BoardWalk <a href="https://x.com/boardwalk_cash/status/1859278721301217477">Update</a></p><ul><li><p>Add support for Cashu payment requests</p></li><li><p>Add ability to request and send payments for specific amounts</p></li><li><p>All users now have a reusable ecash address to receive payments</p></li><li><p>Use dollars or bitcoin. Perfect for point of sale or tips</p></li></ul></li><li><p>00:50:19 Geyser <a href="https://about.geyser.fund/OLD/Archive/blog/november-2024-release-2">November second release</a></p><ul><li><p>Heroes Hall of Fame: a page that highlights the top projects and heroes driving Bitcoin adoption</p></li><li><p>Ambassadors: users can spread awareness of Bitcoin initiatives and earn recognition for their contributions</p></li><li><p>Hero Link: a unique link for users to share projects and earn points as ambassadors</p></li><li><p>Hero Card: a card displaying user rankings and impact across creator, contributor, and ambassador roles</p></li><li><p>Better Profile Stats: updated profiles now show detailed stats and rankings across all hero categories</p></li></ul></li><li><p>00:50:20 Aqua Wallet <a href="https://github.com/AquaWallet/aqua-wallet/releases/tag/v0.2.5">v0.2.5</a> - Make AQUA Great Again</p><ul><li><p>Phase 1 of UI refresh with new AQUA logo and colors</p></li><li><p>Watch-Only Wallet export for Bitcoin and Liquid</p></li><li><p>Add UTXO filtering to prevent errors when sending back-to-back Lowball transactions</p></li><li><p>Add second guard to prevent double-pay issue with Boltz sends</p></li></ul></li><li><p>00:50:47 Clams Remote <a href="https://github.com/clams-tech/Remote/releases/tag/remote-2.5.0">v2.5.0</a></p><ul><li><p>Add BIP353 support</p></li></ul></li></ul><h3><strong>Nostr</strong></h3><h4><strong>Project spotlight</strong></h4><ul><li><p>00:50:52 NDK Mobile: A React Native/Expo implementation of NDK (Nostr Development Kit) that provides a complete toolkit for building Nostr applications on mobile platforms. [<a href="https://github.com/nostr-dev-kit/ndk/tree/master/ndk-mobile">Github</a>]</p><ul><li><p>Features:</p><ul><li><p>Multiple signer implementations (NIP-07, NIP-46, Private Key)</p></li><li><p>SQLite-based caching for offline support</p></li><li><p>Subscription management with automatic reconnection</p></li><li><p>React Native and Expo compatibility</p></li><li><p>React hooks for easy state management</p></li><li><p>NDK Mobile is the library behind Olas and the (upcoming) Honeypot wallet</p></li></ul></li></ul></li><li><p>00:50:55 Olas: An Instagram-like client for iOS and Android [<a href="https://njump.me/nevent1qqs9wv8w0dmkcmdnez73l5way0kjj9zz8y09nfcjcqy9pft29l9ws6cpp4mhxue69uhkummn9ekx7mqzyrafsj7hmweg9ur7zmn6apajdg48hxuskujx53rhrux0ttjcqx84y89n8mh">Announcement</a>]</p><ul><li><p>&#8220;Olas 0.1 provides a feed of videos (like those on flare/highlighter/zap.stream), picture events (kind:20, a new kind that no client had implemented yet) and the classical short notes with images attached we are all used to.&#8221; [<a href="https://testflight.apple.com/join/2FMVX2yM">TestFlight</a>]</p></li></ul></li><li><p><a href="https://chachi.chat/">chachi.chat</a>: A relay-based group chat client for the web [<a href="https://git.v0l.io/verbiricha/chachi">Gitea</a>]</p><ul><li><p>&#8220;NIP-29 allows creating groups that can be read by anyone or only authenticated users. These groups can be open to new members or require explicit approval from the group admins.&#8221; [<a href="https://njump.me/nevent1qqsv25qz88gdhu2c5a9ykhpltychv90726ngnllel2ka96g7xewn76szypl62m6ad932k83u6sjwwkxrqq4cve0hkrvdem5la83g34m4rtqeggls2ps">Note</a>]</p></li></ul></li><li><p>00:51:26 Knox: A command-line Nostr bunker built with Deno. [<a href="https://gitlab.com/soapbox-pub/knox">Gitlab</a>]</p><ul><li><p>&#8220;Knox is a new Nostr bunker CLI for running a NIP-46 remote signer and granting credentials to members of your team&#8221;</p></li></ul></li><li><p>00:51:32 <a href="https://nostraut.net/">Nostraut</a>: Automate anything - on nostr</p><ul><li><p>Nostraut is a platform designed to automate interactions on Nostr (schedule an event, receive notifications about events, and automatically react to events)</p></li></ul></li><li><p>00:51:35 ezdvm: Simple DVM python implementation [<a href="https://github.com/dtdannen/ezdvm">Github</a>]</p><ul><li><p>Easily run any python code behind a DVM on Nostr. Just pick a kind (for basic text-to-text use 5050) and put the code you want to run in the <code>do_work()</code> function. Then run the DVM.</p></li></ul></li><li><p>00:51:40 Futr: A cross-platform nostr client app written in haskell and qt5 [<a href="https://github.com/futrnostr/futr">Github</a>]</p></li><li><p>00:51:45 <a href="https://nosey.vercel.app/">Nosey</a>: Nosey is a search app for nostr. Focus on supporting features similar to Twitter search directives. [<a href="https://github.com/akiomik/nosey">Github</a>]</p></li><li><p>00:51:49 nos2x for Firefox: nostr signer extension for Firefox [<a href="https://github.com/diegogurpegui/nos2x-fox">Github</a>]</p><ul><li><p>A fork from <a href="https://github.com/fiatjaf/nos2x">nos2x</a> by Fiatjaf, focused on Firefox and related browsers.</p></li></ul></li></ul><h4><strong>Software Releases &amp; Project Updates</strong></h4><ul><li><p>Damus</p><ul><li><p><a href="https://github.com/damus-io/damus/releases/tag/v1.11-10">v1.11-10</a></p><ul><li><p>Add Damus Share sheet action</p></li><li><p>Add new easy to use video controls for full screen video</p></li><li><p>Add Edit, Share, and Tap-gesture in Profile pic image viewer</p></li><li><p>Add Apple translation popovers for notes for iOS 17.4+ and macOS 14.4+</p></li><li><p>Allow multiple images to be uploaded at the same time</p></li><li><p>Add support for pasting images from the clipboard to the post composer</p></li><li><p>Add NDB search functionality to the universe view</p></li></ul></li><li><p>New <a href="https://njump.me/nevent1qgsraldwhvwcjgltmxwfu7kw8dqef2692yhzheuurd7k3kfy8cxjdqgqyz54jkm9xtzqkxeh54txnvt5zfsn3u0kgrttsvq8zw2dv5y7glsmcm5plac">TestFlight</a> available, with the following features:</p><ul><li><p>Improved video controls</p></li><li><p>Stability improvements to video support</p></li><li><p>New image share options on the full screen carousel</p></li><li><p>Hashtag suggestions</p></li></ul></li></ul></li><li><p>YakiHonne <a href="https://njump.me/nevent1qgszpxr0hql8whvk6xyv5hya7yxwd4snur4hu4mg5rctz2ehekkzrvcqyq0zhhc5pf4282h8culuavgjr8fyqf9d6t389ac2yjtuz9eer3wnysu8666">Update</a></p><ul><li><p>Mobile:</p><ul><li><p>Adjust your home feed with what interests you the most</p></li><li><p>Home suggestion box can be enabled and disabled</p></li><li><p>Profile preview can be enabled and disabled</p></li><li><p>Replies can be previewed and highlighted directly</p></li><li><p>Articles, videos and curations can be quoted inside notes for more exposure</p></li><li><p>Add the ability to link connected wallet to your profile for zaps receiving</p></li></ul></li><li><p>Web:</p><ul><li><p>Connected threads: A refined notes thread makes following entire discussions more intuitive</p></li><li><p>Users can now personalize their home feed by selecting their top interests</p></li><li><p>Replies can now be previewed directly from the note card, without needing to open the full note</p></li><li><p>Wallets can now be linked to your account directly from the wallet page</p></li><li><p>Drafts for notes and replies are now saved, allowing easy edits later</p></li><li><p>The suggestions box on the home page can now be hidden</p></li><li><p>Articles, videos and curations can now be quoted and shared as notes</p></li></ul></li></ul></li><li><p>Flotilla <a href="https://github.com/coracle-social/flotilla/releases/tag/0.1.0">v0.1.0</a></p><ul><li><p>Remove nip05 login, use nostrconnect instead</p></li><li><p>Add types file</p></li><li><p>Add notification badges</p></li><li><p>Add checked store and set data</p></li></ul></li><li><p>Pokey</p><ul><li><p><a href="https://github.com/KoalaSat/pokey/releases/tag/v0.1.0-alpha">v0.1.0</a></p><ul><li><p>Add Mute thread button for notifications</p></li></ul></li><li><p><a href="https://github.com/KoalaSat/pokey/releases/tag/v0.0.9-alpha">v0.0.9</a></p><ul><li><p>Notifications now display NIP05 names if available</p></li></ul></li></ul></li><li><p>Oxchat <a href="https://github.com/0xchat-app/0xchat-app-main/releases/tag/v1.4.1-release">v1.4.1</a></p><ul><li><p>Optimize video player UI with support for landscape mode</p></li><li><p>Add audio configuration in settings</p></li><li><p>Enable copying of ecash tokens from ecash messages</p></li><li><p>Support for media deletion</p></li></ul></li><li><p>Zapstore <a href="https://github.com/zapstore/zapstore/releases/tag/0.1.6">v0.1.6</a></p><ul><li><p>Performance: Background loading, remove deprecated</p></li><li><p>Allow sending system info and error report</p></li><li><p>Add Deeplink signer param support</p></li></ul></li><li><p>Grain <a href="https://github.com/0ceanSlim/grain/releases/tag/v0.2.0">v0.2.0</a></p><ul><li><p>Separate YAML Files for Blacklists and Whitelists: Moved the blacklist and whitelist configurations out of the main config.yml and into their own separate YAML files</p></li><li><p>Backup Relay Support: Introduced a new feature to configure a backup relay.</p></li><li><p>Support for Nostr Mutelists: Introduced the ability to consider one or multiple pubkeys&#8217; nostr mutelists as blacklists</p></li><li><p>Configurable Time Constraints: Added new configurations to reject events based on their <code>created_at</code> timestamps</p></li></ul></li><li><p>OpenLibrarian <a href="https://github.com/RydalWater/OpenLibrarian/releases/tag/v0.1.3">v0.1.3</a></p><ul><li><p>Add second round of testing (up to 77% coverage)</p></li><li><p>Separate features &amp; updates section</p></li><li><p>Add privacy policy</p></li><li><p>Include alternative secondary API for pulling book covers based on isbn</p></li></ul></li><li><p>Nostr-PHP <a href="https://github.com/nostrver-se/nostr-php/releases/tag/1.5.1">v1.5.1</a></p><ul><li><p>Support for PHP 8.4</p></li><li><p>Add id property to Subscription class</p></li><li><p>Update example snippets</p></li><li><p>AllowDynamicProperty in Filter class</p></li></ul></li><li><p>00:52:00 GifBuddy <a href="https://njump.me/nevent1qqs9kct03kpq3rx5jclzwdtzhgz8qvjdnp6j2ydlaaqd7s93m0jkrsgzyzl8xkxylegpfrxv4lqzags9mqq5tcjn3zd289vd4tagvdcy0jzqufkm7tm">Update</a></p><ul><li><p>Add your own gifs with uploads</p></li><li><p>Load more gifs to find what you want</p></li><li><p>Faster gif loading</p></li><li><p>Less memory intensive on the server</p></li></ul></li></ul><h3><strong>Boosts</strong></h3><ul><li><p>00:52:30 Thanks to everyone who streamed sats, and shoutout to our top boosters:</p><ul><li><p>[&#127942; TOP BOOSTER] @Chris (5,000 sats) &#8220;Is there a technical limitation that prevents Coldcard Q from being able to type a note, and export it encrypted with a deterministic encryption key, so that it can only be decrypted on another Q with the same seed AND same passphrase? Thanks!&#8221;</p></li><li><p>@podconf (500 sats) &#8220;THIS PODCAST IS NONCOMPLIANT&#8221;</p></li><li><p>@btconboard (300 sats) &#8220;Liana is massively underrated&#8221;</p></li></ul></li></ul><h3><strong>Bitcoin Optech Newsletter</strong></h3><ul><li><p>Highlights from recent Bitcoin Optech Newsletters</p><ul><li><p><a href="https://bitcoinops.org/en/newsletters/2024/11/22/">330</a></p><ul><li><p>Pluggable channel factories: ZmnSCPxj <a href="https://delvingbitcoin.org/t/pluggable-channel-factories/1252/">posted</a> to Delving Bitcoin a proposal to make a small set of changes to the BOLT specification to allow existing LN software to manage LN-Penalty payment channels within a channel factory using a software plugin.</p></li><li><p>Signet activity report: Anthony Towns <a href="https://delvingbitcoin.org/t/ctv-apo-cat-activity-on-signet/1257">posted</a> to Delving Bitcoin a summary of activity on the default signet related to proposed soft forks available through Bitcoin Inquisition.</p></li><li><p>Update to LNHANCE proposal: Moonsettler <a href="https://delvingbitcoin.org/t/op-paircommit-as-a-candidate-for-addition-to-lnhance/1216">posted</a> to Delving Bitcoin and also the Bitcoin-Dev mailing list a proposal for a new opcode, OP_PAIRCOMMIT, to be added to the LNHANCE soft fork proposal that includes OP_CHECKTEMPLATEVERIFY and OP_CHECKSIGFROMSTACK.</p></li><li><p>Covenants based on grinding rather than consensus changes: Ethan Heilman <a href="https://mailing-list.bitcoindevs.xyz/bitcoindev/CAEM=y+W2jyFoJAq9XrE9whQ7EZG4HRST01TucWHJtBhQiRTSNQ@mail.gmail.com/">posted</a> to the Bitcoin-Dev mailing list the summary of a paper he coauthored with Victor Kolobov, Avihu Levy, and Andrew Poelstra.</p></li></ul></li><li><p><a href="https://bitcoinops.org/en/newsletters/2024/11/15/">329</a></p><ul><li><p>MAD-based offchain payment resolution (OPR) protocol: John Law <a href="https://delvingbitcoin.org/t/a-fast-scalable-protocol-for-resolving-lightning-payments/1233">posted</a> to Delving Bitcoin the description of a micropayment protocol that requires both participants to contribute funds to a bond that can be effectively destroyed at any time by either participant.</p></li><li><p>Papers about IP-layer censorship of LN payments: Charmaine Ndolo <a href="https://delvingbitcoin.org/t/research-paper-on-ln-payment-censorship/1248">posted</a> to Delving Bitcoin summaries of two recent papers about reducing the privacy of LN payments and potentially censoring them.</p></li></ul></li></ul></li></ul><h3><strong>News &amp; Noteworthy (cont.)</strong></h3><h4><strong>Bitcoin</strong></h4><ul><li><p>00:55:05 Chaincode Labs launches the 2025 edition of its BOSS (Bitcoin Open-Source Software) program, a free, three-month program focused on Bitcoin and Lightning open-source software development [<a href="https://learning.chaincode.com/#BOSS">Website</a>]</p><ul><li><p>The program runs from January to April 2025. Applications close on December 31, 2024.</p></li></ul></li></ul><h4><strong>Lightning + L2+</strong></h4><ul><li><p><a href="https://dlcmarkets.com/">DLC Markets</a> has transitioned from signet to mainnet, offering a secure, non-custodial Bitcoin derivatives platform. [<a href="https://blog.dlcmarkets.com/engineering-behind-dlcmarkets/">Blog post</a>]</p><ul><li><p>Using Discreet Log Contracts and innovative features like Rust-based oracles and WebAssembly, it improves OTC trading efficiency.</p></li></ul></li><li><p>Boltz integrates Rootstock swaps with the Lightning Network, enabling users to seamlessly move funds between the two networks. [<a href="https://blog.boltz.exchange/p/hello-rootstock-swaps">Announcement</a>]</p></li></ul><h4><strong>Nostr</strong></h4><ul><li><p>00:55:49 Private and ad-free pay-per-query search engine <a href="https://kagi.com/">Kagi HQ</a>, joins Nostr [<a href="https://njump.me/nevent1qqsgldgngvxk5wfea5tny9sj4qj8zsv2caru44lr6c40avsd8jllaxgpzemhxue69uhhyetvv9ujumn0wd68ytnzv9hxgqg5waehxw309aex2mrp0yhxgctdw4eju6t0qy28wumn8ghj7mn0wd68ytn00p68ytnyv4mqygp5zpx7mu7vtymgqtyrpz3aqzg09ptaf2ayazmjptx276e2kpyedyynk2y2">Note</a>]</p></li></ul><h4><strong>Business &amp; Finance</strong></h4><ul><li><p>00:57:06 Block, Inc. announces Proto, a suite of bitcoin mining products and services aimed at decentralizing hardware supply and enhancing network resiliency [<a href="https://www.mining.build/blog/introducing-proto-building-the-future-of-bitcoin-mining-hardware-2/">Press release</a>]</p><ul><li><p>Its focus spans ASIC chips, mining rigs, and developer tools for diverse applications like home mining and energy reuse.</p></li></ul></li><li><p>00:57:11 Casa introduces Casa Enterprise, a specialized product designed to help businesses securely manage their bitcoin treasuries through self-custody solutions. [<a href="https://blog.casa.io/introducing-casa-enterprise/">Blog post</a>]</p></li><li><p>00:57:30 Swan Bitcoin sues former legal firm for conflict of interest in Tether case [<a href="https://x.com/theMiningPod/status/1860531063426080814">The Mining Pod</a>]</p><ul><li><p>Swan Bitcoin files a lawsuit against its former legal firm, Gibson Dunn &amp; Crutcher, alleging breach of fiduciary duty and attorney malpractice. Swan claims Gibson Dunn created a conflict of interest by representing Tether in a competing case.</p></li></ul></li></ul><h4><strong>Tradfi</strong></h4><ul><li><p>00:57:46 Revolut&#8217;s cryptocurrency exchange, Revolut X, expands to 30 European countries after successful UK launch. [<a href="https://www.coindesk.com/business/2024/11/13/revolut-expands-crypto-exchange-across-eu-after-successful-launch-in-uk/">Coin Desk</a>]</p></li><li><p>00:57:58 Private investment firm, Newmarket Capital, launches Battery Finance: Bitcoin-collateralized loan strategy. CEO explains bitcoin-backed private credit strategy on <a href="https://www.cnbc.com/video/2024/11/22/why-newmarket-capital-ceo-andrew-hohns-is-fusing-loans-with-bitcoin.html">CNBC</a></p></li></ul><h4><strong>Funding</strong></h4><ul><li><p>00:58:06 OpenSats announces:</p><ul><li><p><a href="https://opensats.org/blog/m1sterc001guy-receives-lts-grant">Long-term support</a> for m1sterc001guy for his continued contributions to the Bitcoin ecosystem.</p></li><li><p><a href="https://opensats.org/blog/3rd-wave-of-education-grants">Third wave of education grants</a>, dedicated to advancing Bitcoin literacy and community development across the globe:</p><ul><li><p>BTC Map</p></li><li><p>Yes Bitcoin Haiti</p></li><li><p>Entropy Bitcoin Education</p></li><li><p>Bitcoin 4all</p></li></ul></li><li><p><a href="https://opensats.org/blog/doubling-down-on-nostr">Doubling down on Nostr</a>, with additional grants to:</p><ul><li><p>Damus</p></li><li><p>Gossip</p></li><li><p>nostr.build</p></li><li><p>nostr-sdk-ios</p></li><li><p>ngit &amp; gitworkshop</p></li><li><p>nostr-relay (-nestjs, -tray)</p></li><li><p>Nostrocket</p></li><li><p>DVMDash</p></li></ul></li></ul></li></ul><h4><strong>Mining</strong></h4><ul><li><p>00:58:12 Russia bans winter digital currency mining in Siberia, North Caucasus, and occupied Ukraine to address energy shortages [<a href="https://www.themoscowtimes.com/2024/11/19/russia-bans-winter-cryptocurrency-mining-in-siberia-north-caucasus-and-occupied-ukraine-a87065">The Moscow Times</a>]</p><ul><li><p>The ban affects specific areas from December 1, 2024, to March 15, 2025, with annual restrictions in Siberia until 2031 and total bans in other regions.</p></li></ul></li></ul><h4><strong>Privacy</strong></h4><ul><li><p>00:58:40 U.S. Congress critiques Tornado Cash and urges for stricter regulations [<a href="https://www.therage.co/congress-letter-tornado-cash/">The Rage</a>]</p><ul><li><p>Seven U.S. Congress members urge the Treasury to finalize regulations on cryptocurrency mixers like Tornado Cash, citing misuse for laundering, terrorism, and sanctions evasion.</p></li></ul></li><li><p>00:58:44 Chinese government employees with access to vast surveillance systems are profiting by selling citizen data to private brokers [<a href="https://web.archive.org/web/20241121122224/https://www.wired.com/story/chineses-surveillance-state-is-selling-citizens-data-as-a-side-hustle/">Wired</a>]</p><ul><li><p>Brokers resell information ranging from phone numbers and bank details to encrypted passwords. Researchers reveal that even restrictions on accessing officials&#8217; data are easily bypassed.</p></li></ul></li><li><p>00:59:20 Mullvad VPN cancels remaining PayPal subscriptions in order to reduce stored customers&#8217; data and aligns with privacy-focused policy. [<a href="https://mullvad.net/en/blog/remaining-paypal-subscriptions-are-being-canceled">Announcement</a>]</p><ul><li><p>Users can still make one-time payments, including via PayPal, and will receive a notification from PayPal but retain unused account time.</p></li></ul></li></ul><h4><strong>Protocol</strong></h4><ul><li><p>Bitcoin Core #30239: Introduces a standard for ephemeral dust outputs, enabling zero-fee transactions with dust outputs to be included in the mempool. [<a href="https://github.com/bitcoin/bitcoin/issues/30239">Merged</a>]</p></li><li><p>Bitcoin Core #30930: Introduces a new peer services column in the netinfo command and an &#8220;outonly&#8221; filter to display only outgoing connections. [<a href="https://github.com/bitcoin/bitcoin/pull/30930">Merged</a>]</p></li><li><p>Bitcoin Core #30592: Removes the option to disable full Replace-by-Fee (RBF) and revert to opt-in RBF [<a href="https://github.com/bitcoin/bitcoin/pull/30592">Merged</a>]</p></li><li><p>Core Lightning #6980: introduces a <code>splice</code> command that supports either a JSON payload or a splice script. This command facilitates complex splicing actions and combines multiple channel operations into a single transaction. [<a href="https://github.com/ElementsProject/lightning/pull/6980">Merged</a>]</p></li><li><p>LDK #3283: Support paying directly to Human Readable Names using bLIP 32: introduces compatibility with BIP353 by enabling Bitcoin payments to use DNS-based human-readable addresses. [<a href="https://github.com/lightningdevkit/rust-lightning/issues/3283">Merged</a>]</p></li><li><p>NIP #1578: nip46: simple public key login using kind:10046 [<a href="https://github.com/nostr-protocol/nips/pull/1578">Open</a>]</p></li><li><p>NIP #1605: Kind-scoped follow: A way of following one or multiple kinds that are of interest [<a href="https://github.com/nostr-protocol/nips/pull/1605">Open</a>]</p></li><li><p>NIP #1587: Time-ordered event ids: Implementing temporal locality in primary keys, inspired by UUIDv7, increases the database efficiency by reducing memory usage and data rearrangement. [<a href="https://github.com/nostr-protocol/nips/pull/1587">Draft</a>]</p></li></ul><h4><strong>Cryptography</strong></h4><ul><li><p>1:00:59 Two mathematicians discovered an elliptic curve of rank 29, breaking an 18-year-old record. This rank measures the complexity of rational points on the curve. [<a href="https://www.quantamagazine.org/new-elliptic-curve-breaks-18-year-old-record-20241111/">Quanta Magazine</a>]</p><ul><li><p>Their finding highlights unresolved debates in mathematics, including whether there is an upper limit to elliptic curve rank, which remains unproven.</p></li></ul></li></ul><h4><strong>Government &amp; Political</strong></h4><ul><li><p>Shanghai&#8217;s Songjiang People&#8217;s Court clarifies that personal ownership of bitcoin is legal in China under property laws, despite restrictions on commercial activities. [<a href="https://www.scmp.com/tech/blockchain/article/3287415/shanghai-court-says-crypto-ownership-legal-under-china-law-amid-bitcoin-price-surge">South China Morning Post</a>]</p></li><li><p>Polish Presidential candidate S&#322;awomir Mentzen commits to establishing a Strategic Bitcoin Reserve if elected in 2025. [<a href="https://x.com/SlawomirMentzen/status/1858276016822603970">Twitter post</a>]</p></li><li><p>Pennsylvania is considering a bill, the Strategic Bitcoin Reserve Act, which would allow the state to invest up to 10% of its $7 billion treasury in Bitcoin. [<a href="https://atlas21.com/pennsylvania-opens-up-to-bitcoin-proposed-bill-for-a-strategic-reserve/">Atlas21</a>]</p></li><li><p>U.S. SEC Chair Gary Gensler announces his resignation, effective January 20, 2025, after serving since 2021. [<a href="https://x.com/GaryGensler/status/1859658192298574096">Twitter post</a>]</p></li><li><p>Five-year sentence for Bitfinex hacker Ilya Lichtenstein following $3.6 billion (120,000 units) bitcoin theft [<a href="https://www.justice.gov/usao-dc/pr/bitfinex-hacker-sentenced-money-laundering-conspiracy-involving-billions-stolen">Press release</a>]</p></li><li><p>Federal agents raid Polymarket CEO&#8217;s home, seizing electronic devices. Polymarket is under DOJ scrutiny for allegedly allowing U.S. users to access its platform despite prior restrictions. [<a href="https://www.coindesk.com/business/2024/11/13/fbi-reportedly-raids-polymarket-ceos-home/">CoinDesk</a>]</p></li></ul><h4><strong>Events</strong></h4><ul><li><p>1:01:22 <a href="https://satsnfacts.btc.pub/">SATS&#8217;N&#8217;FACTS</a>: Bitcoin Technical Unconference</p><ul><li><p>First edition conference diving into Scalability, Mining, Payments, Infrastructure, and much more.</p></li><li><p>February 8&#8212;10, 2025 in Chiang Mai, Thailand</p></li></ul></li><li><p>1:01:26 <a href="https://hackalajara.xyz/">Hackalajara</a>: Guadalajara&#8217;s first bitcoin-focused hackathon</p><ul><li><p>November 29-December 1, 2025 in Guadalajara, Mexico</p></li></ul></li><li><p>1:01:39 <a href="https://lu.ma/m788gz0a">Bengaluru BITDEVS</a>: BitDevs Summit</p><ul><li><p>Day-long gathering of Bitcoin and open-source contributors showcasing their cutting-edge work in panels, demos, and talks.</p></li><li><p>November 30, 2024 in Bangalore, India</p></li></ul></li></ul><h3><strong>Reads</strong></h3><ul><li><p>1:01:46 Here&#8217;s a list of our top recently published reads:</p><ul><li><p>High Risk, Low Reward, by Tony Giorgio [<a href="https://tonygiorgio.com/high-risk-low-reward/">Blog post</a>]</p></li><li><p>Boost Your Bitcoin Node Sync With UTXO Snapshots, by Jameson Lopp [<a href="https://blog.lopp.net/bitcoin-node-sync-with-utxo-snapshots/">Blog post</a>]</p></li><li><p>Bitcoin Core&#8217;s Loss of Focus, by Jamesob [<a href="https://x.com/jamesob/status/1860340932706730261">Twitter post</a>]</p></li><li><p>Analysis of the Crypto Policy Landscape Following the Elections, by Coin Center [<a href="https://www.coincenter.org/coin-centers-analysis-of-the-crypto-policy-landscape-following-the-elections/">Blog post</a>]</p></li><li><p>How decentralized is Bluesky really? by Christine Lemmer-Webber [<a href="https://dustycloud.org/blog/how-decentralized-is-bluesky/">Blog post</a>]</p></li><li><p>Bitcoin Dev Project&#8217;s guide on how to sign a MuSig transaction [<a href="https://bitcoindevs.xyz/decoding/musig">Guide</a>]</p></li><li><p>Does Sovereign Default Risk Explain Cryptocurrency Adoption? International Evidence from Mobile Apps [<a href="https://papers.ssrn.com/sol3/papers.cfm?abstract_id=5029660">Research paper</a>]</p></li><li><p>Bitcoin Under Volatile Block Rewards: How Mempool Statistics Can Influence Bitcoin Mining [<a href="https://arxiv.org/html/2411.11702v1">Research paper</a>]</p></li></ul></li></ul><h3><strong>Episode submission ideas</strong></h3><ul><li><p>We&#8217;re looking for ideas for interesting panel conversations. To send Bitcoin related questions, just go to <a href="https://bitcoin.review/">bitcoin.review</a> and follow the contact links at the bottom of the page.</p></li></ul><h3><strong>Get in touch with the pod</strong></h3><ul><li><p><a href="https://twitter.com/bitcoinreviewhq">Podcast Twitter</a></p></li><li><p><a href="https://twitter.com/nvk">NVK Twitter</a></p></li><li><p><a href="https://t.me/BitcoinReviewPod">Telegram</a></p></li><li><p><a href="mailto:producer@coinkite.com">Email</a></p></li><li><p>Nostr &amp; LN &#9889;nvk@nvk.org (not an email!)</p></li></ul>]]></content:encoded></item><item><title><![CDATA[BR087 - ColliderScript, BTCPay Server, OpenSecret, Matrix, Lottie player JS Attack, the Bullish Case for Vaults, LN Payment Censorship , EmailBTC, secp256k1-node vulnerability + MORE ft. Justin & Paul]]></title><description><![CDATA[I&#8217;m joined by guests Justin Moon & Future Paul & to go through the list.]]></description><link>https://substack.bitcoin.review/p/br087-colliderscript-btcpay-server</link><guid isPermaLink="false">https://substack.bitcoin.review/p/br087-colliderscript-btcpay-server</guid><dc:creator><![CDATA[STACK TO THE FUTURE]]></dc:creator><pubDate>Wed, 13 Nov 2024 21:34:19 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a95ac75-ac77-4167-9383-9930a48690bb_1080x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I&#8217;m joined by guests <a href="https://twitter.com/_JustinMoon_">Justin Moon</a> &amp; <a href="https://twitter.com/futurepaul">Future Paul</a> &amp; to go through the list.</p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://bitcoin.review/podcast/episode-56/&quot;,&quot;text&quot;:&quot;Listen on your favorite podcast app&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://bitcoin.review/podcast/episode-56/"><span>Listen on your favorite podcast app</span></a></p><div><hr></div><h3><strong>Quote of the Day</strong></h3><p>00:00:48 &#8220;Nobody knows anything.&#8221;</p><h3><strong>Housekeeping</strong></h3><ul><li><p>00:06:00 New COLDCARD Tutorials:</p><ul><li><p><a href="https://www.youtube.com/watch?v=xfHeUFCk4hY">How to Use the Secure Notes function on the COLDCARD Q</a>: Allows your COLDCARD the ability to store free-form text securely.</p></li><li><p><a href="https://www.youtube.com/watch?v=Ir1frVs1gNE">How to Use the Passwords function on the COLDCARD Q</a>: Allows your COLDCARD to function as a password manager.</p></li></ul></li></ul><h3><strong>Urgent Vulnerability Disclosures</strong></h3><ul><li><p>00:06:26 Critical severity: Private key extraction vulnerability in secp256k1-node affecting ECDH [<a href="https://github.com/cryptocoinjs/secp256k1-node/security/advisories/GHSA-584q-6j8j-r5pm">Security advisory</a>]</p><ul><li><p>A vulnerability in the secp256k1-node library&#8217;s ECDH functionality allows private key extraction by exploiting specific crafted public keys, affecting versions 3.8.0 and earlier.</p></li><li><p>Attackers can retrieve private keys using low-order curve points through only 11 ECDH sessions.</p></li></ul></li><li><p>00:08:01 Medium severity: Disclosure of hindered block propagation due to stalling peers [<a href="https://bitcoincore.org/en/2024/11/05/cb-stall-hindering-propagation/">Public disclosure</a>]</p><ul><li><p>Before Bitcoin Core v25.1, a vulnerability allows an attacker to delay block downloads by stalling peer nodes. The affected node waits up to 10 minutes before attempting another block download, leading to possible network degradation and mining delays.</p></li></ul></li></ul><h3><strong>Bitcoin</strong></h3><h4><strong>Software Releases &amp; Project Updates</strong></h4><ul><li><p>00:08:40 Bitcoin Core <a href="https://github.com/bitcoin/bitcoin/releases/tag/v27.2">v27.2</a></p><ul><li><p>net: fix race condition in self-connect detection</p></li><li><p>init: change shutdown order of load block thread and scheduler</p></li><li><p>RPC: Fix cases of calls to FillPSBT errantly returning complete=true</p></li><li><p>psbt: Check non witness utxo outpoint early</p></li><li><p>test: fix constructor of msg_tx</p></li><li><p>ci: move ASan job to GitHub Actions from Cirrus CI</p></li><li><p>ci: remove unused bcc variable from workflow</p></li></ul></li><li><p>00:09:11 Electrs <a href="https://github.com/romanz/electrs/releases/tag/v0.10.7">v0.10.7</a></p><ul><li><p>Support testnet4</p></li><li><p>Enable LTO in release build</p></li><li><p>Don&#8217;t sync mempool when bitcoind mempool is not yet loaded</p></li></ul></li><li><p>00:10:22 BTC Pay Server</p><ul><li><p><a href="https://github.com/btcpayserver/btcpayserver/releases/tag/v2.0.2">v2.0.2</a></p><ul><li><p>Critical vulnerability disclosure for Nostr or Blink plugin users: Without it, an attacker with access to a pull payment could drain the Lightning wallet without limit.</p></li></ul></li><li><p><a href="https://github.com/btcpayserver/btcpayserver/releases/tag/v2.0.0">v2.0.0</a></p><ul><li><p>New feature:</p><ul><li><p>Interface localization</p></li><li><p>New sidebar navigation</p></li><li><p>Improved onboarding flow</p></li><li><p>Improved branding options</p></li><li><p>Support pluginable rate providers</p></li><li><p>User: Add name and profile picture</p></li><li><p>Greenfield: Manage notifications</p></li><li><p>Greenfield: Add file endpoints and upload</p></li></ul></li></ul></li></ul></li><li><p>00:11:57 libsecp256k1 <a href="https://github.com/bitcoin-core/secp256k1/releases/tag/v0.6.0">v0.6.0</a></p><ul><li><p>Added:</p><ul><li><p>New module <code>musig</code> implements the MuSig2 multisignature scheme according to the BIP 327 specification. See:</p><ul><li><p>Header file <code>include/secp256k1_musig.h</code> which defines the new API</p></li><li><p>Document <code>doc/musig.md</code> for further notes on API usage</p></li><li><p>Usage example``examples/musig.c`</p></li></ul></li><li><p>New CMake variable <code>SECP256K1_APPEND_LDFLAGS</code> for appending linker flags to the build command</p></li></ul></li><li><p>Changed:</p><ul><li><p>API functions now use a significantly more robust method to clear secrets from the stack before returning</p></li><li><p>Any type <code>secp256k1_foo</code> can now be forward-declared using <code>typedef struct secp256k1_foosecp256k1_foo</code></p></li><li><p>Organized CMake build artifacts into dedicated directories to improve build output structure and Windows shared library compatibility</p></li></ul></li></ul></li><li><p>00:14:18 Bitcoin Keeper</p><ul><li><p>Mobile <a href="https://github.com/bithyve/bitcoin-keeper/releases/tag/v1.2.18">v1.2.18</a></p><ul><li><p>Select Electrum servers during app setup</p></li><li><p>Add support for TwentyTwo&#8217;s Portal</p></li><li><p>USB option enabled for Coldcard and Jade via the desktop app</p></li><li><p>TAPSIGNER - Verify initial status and backups count</p></li><li><p>Receive screen now enables multiple addresses management and address labeling</p></li><li><p>Send experience overhauled</p></li><li><p>Major design updates to UTXO management and transaction details</p></li></ul></li><li><p>Desktop <a href="https://github.com/bithyve/keeper-desktop/releases/tag/keeper-desktop-v0.1.3">v0.1.3</a></p><ul><li><p>Support Trezor Safe 5 and Ledger Stax and Flex (updating HWI to 3.1.0)</p></li><li><p>Fix unlocking Jade on testnet</p></li></ul></li></ul></li><li><p>00:14:56 Liana <a href="https://github.com/wizardsardine/liana/releases/tag/v8.0">v8.0</a> - A Template Haven</p><ul><li><p>Liana daemon/library: A new field <code>last_poll_timestamp</code> was added to the wallet table in order to track the last time the wallet was updated by the poller</p></li><li><p>Liana GUI:</p><ul><li><p>The new Bitcoind 28.0 version is now downloaded by the GUI</p></li><li><p>Bitbox02 devices can now be part of a Taproot descriptor set-up if their firmware version is greater than or equal to 9.21.0</p></li><li><p>The install process now includes examples of setups with fixed templates and explanatory descriptions to guide the user</p></li><li><p>Hardware wallets with the app not open had a confusing warning message about outdated version</p></li><li><p>Button for the pagination of past transactions was sometimes missing because of a wrong calculation of the page size</p></li><li><p>Resend authentication token request did not work for already created account</p></li></ul></li></ul></li><li><p>00:17:30 Bitcoin Safe</p><ul><li><p><a href="https://github.com/andreasgriffin/bitcoin-safe/releases/tag/1.0.0b3">v1.0.0b3</a></p><ul><li><p>Enable exporting of diagrams in SVG format for better quality and scalability</p></li><li><p>Add a portable exe for Windows</p></li><li><p>Users can now open file TX, PSBT, and wallet files directly via file associations</p></li></ul></li><li><p><a href="https://github.com/andreasgriffin/bitcoin-safe/releases/tag/1.0.0b2">v1.0.0b2</a></p><ul><li><p>Add German Language</p></li><li><p>Add GIF export for animated QR codes</p></li><li><p>Sync tab, which allows chat, synchronization and backup of labels, is now called SyncTalk</p></li></ul></li></ul></li><li><p>00:20:08 RoboSats</p><ul><li><p><a href="https://github.com/RoboSats/robosats/releases/tag/v0.7.2-alpha">v0.7.2</a></p><ul><li><p>Improve recovery robot form</p></li><li><p>Fast generate robot -&gt; fast generate order</p></li><li><p>Add Nostr order books</p></li><li><p>Add coordinator Alias to invoice description</p></li></ul></li><li><p><a href="https://github.com/RoboSats/robosats/releases/tag/v0.7.1-alpha">v0.7.1</a></p><ul><li><p>Multiple performance improvements</p></li><li><p>Better and faster web notifications</p></li><li><p>Add Android notification disable button</p></li><li><p>Remove Experimental and Satstralia coordinators</p></li></ul></li></ul></li><li><p>00:21:10 Bitkey Firmware <a href="https://bitkey.world/en-US/releases">v1.0.91</a></p><ul><li><p>Faster transaction signing: Hardware now signs transactions up to 5x faster</p></li></ul></li><li><p>00:21:20 Raspiblitz <a href="https://github.com/raspiblitz/raspiblitz/releases/tag/v1.11.3">v1.11.3</a></p><ul><li><p>Optimized to run on plain Debian 12 Linux for Proxmox/VM and x86 systems</p></li><li><p>Add Publicpool for solo mining</p></li><li><p>Add Telegraf for Grafana monitoring</p></li><li><p>Add Tailscale</p></li><li><p>Connect Zeus to CLN via CLNrest</p></li></ul></li><li><p>00:21:37 ESP-Miner <a href="https://github.com/skot/ESP-Miner/releases/tag/v2.3.1b1">v2.3.1b1</a></p><ul><li><p>Re-work how we publish artifacts when releasing new builds</p></li><li><p>Use the same espressif/idf release for github and vscode</p></li><li><p>Add all in one factory file script</p></li><li><p>Replace default address with a prompt</p></li></ul></li><li><p>00:22:14 BoltzExchange</p><ul><li><p>boltz-client <a href="https://github.com/BoltzExchange/boltz-client/releases/tag/v2.2.0">v2.2.0</a> - Offer accepted</p><ul><li><p>Add Bolt12 support for submarine swaps</p></li><li><p>Add support for amountless chain swaps</p></li></ul></li><li><p>boltz-web-app <a href="https://github.com/BoltzExchange/boltz-web-app/releases/tag/v1.5.0">v1.5.0</a></p><ul><li><p>Add Bolt12 support for submarine swaps</p></li><li><p>Implement Discount CT</p></li><li><p>Fetch BIP-353 with DNSSEC prover</p></li><li><p>Validate invoices fetched for offers</p></li><li><p>Add Ledger and Trezor support</p></li><li><p>Hardware custom derivation paths</p></li><li><p>Loading indicator for wallet selection</p></li><li><p>Remember custom derivation paths for swaps</p></li><li><p>Show EVM lockup transactions</p></li></ul></li><li><p>boltz-backend <a href="https://github.com/BoltzExchange/boltz-backend/releases/tag/v3.8.0">v3.8.0</a> - An offer you can&#8217;t refuse</p><ul><li><p>Support for a new CLN hold invoice plugin rewritten from scratch with a focus on performance</p></li><li><p>Amounts for Chain Swap can be renegotiated in case they are over- or underpaid. Also, the creation of Chain Swaps without an amount</p></li><li><p>Paying BOLT 12 invoices in submarine swaps and an API endpoint for fetching invoices for offers</p></li></ul></li></ul></li></ul><h4><strong>Project spotlight</strong></h4><ul><li><p>00:22:21 Frost: A flexible, round-optimized threshold signature library for BIP340 taproot [<a href="https://github.com/cmdruid/frost">Github</a>]</p></li><li><p>00:23:12 ColliderScript: Covenants in Bitcoin via 160-bit hash collisions [<a href="https://eprint.iacr.org/2024/1802">Research paper</a>]</p><ul><li><p>The paper introduces a method for enforcing covenants on Bitcoin outputs using hash collisions in SHA-1 and RIPEMD-160, allowing covenants without Bitcoin protocol changes.</p></li></ul></li><li><p>00:27:44 GreatRSI: Great Restored Script Interpreter [<a href="https://github.com/jonasnick/GreatRSI">Github</a>]</p><ul><li><p>The repository contains an experimental partial interpreter for the Great Script Restoration, a proposal aimed at re-enabling and refining Bitcoin script opcodes.</p></li><li><p>It also provides an implementation of the Winternitz One-Time Signature scheme (W-OTS) in Bitcoin Script, written in Bitcoin Script using the Great Script Restoration.</p></li></ul></li><li><p>00:28:16 Boltzmann TS monorepo: A Typescript library computing the entropy of Bitcoin transactions and the linkability of their inputs and outputs. [<a href="https://github.com/Dojo-Open-Source-Project/boltzmann">Github</a>]</p></li><li><p>00:28:55 Bitcoin hackerspace and community accelerator PlebLab, launches <a href="https://www.plebdevs.com/">PlebDevs</a>, a new Bitcoin developer education platform built on Lightning and Nostr. [<a href="https://x.com/PlebLab/status/1854636532470063391">Announcement</a>]</p></li><li><p>00:29:51 SatSale: A lightweight Bitcoin payment processor with the option of connecting to your own Bitcoin node or Lightning network node [<a href="https://github.com/SatSale/SatSale">Github</a>]</p><ul><li><p>Lightweight Bitcoin payment processor written in easily deployable Python.</p></li></ul></li><li><p>00:31:58 <a href="https://emailbtc.net/">EmailBTC</a>: Send Bitcoin to anyone that has an email address [<a href="https://github.com/esaminu/google-chain-signatures">Contract repository</a>]</p><ul><li><p>No wallet is needed to use the service, send Bitcoin to any email.</p></li></ul></li></ul><h3><strong>Vulnerability Disclosures</strong></h3><ul><li><p>00:33:21 XSS attack: Lottie player JS, a popular open-source npm package for web players, was compromised with a wallet drainer, impacting projects such as nostr client Primal and DeFi platform 1inch [<a href="https://github.com/airbnb/lottie-web/issues/3127">Github issue</a>]</p><ul><li><p>&#8220;Blockchain threat monitoring platform Scam Sniffer reports that at least one victim allegedly lost $723,000 worth of Bitcoin (10 bitcoin) due to the LottieFiles supply chain compromise.&#8221; [<a href="https://www.bleepingcomputer.com/news/security/lottiefiles-hacked-in-supply-chain-attack-to-steal-users-crypto/">Bleeping Computer</a>]</p></li></ul></li><li><p>00:38:38 Hackers misuse emergency data requests to access user data [<a href="https://techcrunch.com/2024/11/08/fbi-says-hackers-are-sending-fraudulent-police-data-requests-to-tech-giants-to-steal-peoples-private-information/">TechCrunch</a>]</p><ul><li><p>Hackers gain access to user data by exploiting emergency data requests using hacked law enforcement email accounts to bypass usual warrant requirements. They misuse legitimate communication channels to pose as police and request private information from tech companies.</p></li></ul></li><li><p>00:41:15 Tor relays targeted in IP spoofing campaign causing widespread disruptions [<a href="https://blog.torproject.org/defending-tor-mitigating-IP-spoofing/">Blog post</a>]</p><ul><li><p>A recent IP spoofing attack targeted the Tor network, impersonating non-exit relay IPs to trigger abuse complaints and temporarily disrupt operations. Although no Tor users were affected, relay operators faced hosting issues due to unwarranted blocklists.</p></li></ul></li><li><p>00:41:22 Critical zero-click flaw exposes Synology storage devices to ransomware and data theft [<a href="https://archive.ph/etdoI">Wired</a>]</p><ul><li><p>Security researchers reported that attackers could bypass authentication through Synology&#8217;s QuickConnect service, which lets users remotely access their devices. Even if not directly connected to the internet, many devices are still exploitable.</p></li></ul></li><li><p>00:42:03 Hidden Risk: North Korean hacker group BlueNoroff, deploy a new macOS malware campaign, targeting cryptocurrency firms. [<a href="https://www.bleepingcomputer.com/news/security/north-korean-hackers-use-new-macos-malware-against-crypto-firms/">Bleeping Computer</a>]</p><ul><li><p>The attacks use phishing emails disguised as crypto news to lure victims, and employs a persistence technique by modifying the &#8220;.zshenv&#8221; file, allowing it to evade macOS detection systems.</p></li></ul></li><li><p>00:44:45 Five dollar wrench attacks:</p><ul><li><p>Targeted break-in: Bitcoin host and narrator Guy Swann <a href="https://fountain.fm/episode/VFSxg8VDX9AAOtV70f28">reflects</a> on the break-in which happened at the Lugano Plan B conference, where an intruder entered his hotel room, likely aiming to find valuables often associated with Bitcoiners [<a href="https://x.com/TheGuySwann/status/1852359441489817727">Twitter post</a>]</p></li><li><p>A 23-year-old Ukrainian tourist visiting Phuket was ambushed in his friend&#8217;s hotel room by armed men. The attackers, threatening to break his fingers, demanded $500,000 in digital currency. [<a href="https://www.bangkokpost.com/thailand/general/2899637/ukrainian-robbed-of-b8m-in-digital-money-in-phuket">Bangkok Post</a>]</p><ul><li><p>The tourist transferred 250,000 USDT, after which the robbers left without harming him. He later reported the incident to authorities.</p></li></ul></li><li><p>A Toronto cryptocurrency CEO, Dean Skurka, was kidnapped and held for ransom in a daylight incident. The kidnappers forced him into a vehicle downtown and demanded a $1 million ransom, which was later paid, leading to Skurka&#8217;s release. [<a href="https://www.coindesk.com/policy/2024/11/08/ceo-of-canadian-crypto-holding-returns-safely-after-paying-720k-ransom-report/">CoinDesk</a>]</p></li><li><p>A gunman fatally shoots Ant&#244;nio Vin&#237;cius Lopes Gritzbach, a cryptocurrency businessman, and injures three others at S&#227;o Paulo&#8217;s international airport. Police link the attack to the First Capital Command (PCC), a powerful Brazilian crime syndicate. [<a href="https://www.theguardian.com/world/2024/nov/08/brazil-sao-paulo-airport-assassination-shooting">The Guardian</a>]</p></li></ul></li></ul><h3><strong>Privacy &amp; Other Related Bitcoin Projects</strong></h3><h4><strong>Software Releases &amp; Project Updates</strong></h4><ul><li><p>00:52:50 Reticulum MeshChat <a href="https://github.com/liamcottle/reticulum-meshchat/releases/tag/v1.13.2">v1.13.2</a></p><ul><li><p>Add bandwidth and spreading factors for 2.4GHz SX1280 RNode interfaces</p></li><li><p>Add the ability to select Direct, Opportunistic or Propagated delivery methods before sending a message</p></li></ul></li><li><p>00:53:14 Matrix <a href="https://matrix.org/blog/2024/10/29/matrix-2.0-is-here/">v2.0</a></p><ul><li><p>Instant login, instant launch, and instant sync (aka Simplified Sliding Sync, MSC4186)</p></li><li><p>Next Generation Auth (aka Native OIDC, MSC3861)</p></li><li><p>Native Matrix Encrypted Multiparty VoIP/Video (aka MatrixRTC, MSC4143)</p></li><li><p>Invisible Encryption (MSC4153 &amp; friends)</p></li></ul></li></ul><h3><strong>Lightning + L2+</strong></h3><h4><strong>Project spotlight</strong></h4><ul><li><p>00:54:52 Podcaster Boost Dashboard: Convert core-lightning&#8217;s listinvoices output to a podcasting 2.0 dashboard [<a href="https://github.com/jooray/podcaster-boost-dashboard">Github</a>]</p><ul><li><p>&#8220;This is a simple Python script that converts core lightning&#8217;s listinvoices output into a podcasting 2.0 dashboard.&#8221;</p></li></ul></li><li><p>00:55:06 <a href="https://zpay.live/">zPay.live</a>: Monetise virtually any digital content with Lightning paywalls</p><ul><li><p>A LN Paywall service that recently shifted its focus to the V4V model, and plans to implement the following features:</p><ul><li><p>CrowdWall: When a target is reached, content unlocks for everyone</p></li><li><p>V4V Paywalls (Flexible price) : Buyers can choose their own price, &amp; creators can set limits if they want</p></li><li><p>Blossom built-in storage &amp; multiple file/folder upload option</p></li></ul></li></ul></li><li><p>00:55:14 <a href="https://www.bullishnuts.cash/">BullishNuts</a>: A bullish Cashu PWA wallet [<a href="https://github.com/thebullishbitcoiner/bullishnuts">Github</a>]</p></li><li><p>00:55:19 <a href="https://athenut.com/">Athenut</a>: A privacy-preserving web search powered by Kagi and Cashu [<a href="https://github.com/thesimplekid/athenut-mint">Github</a>]</p><ul><li><p>The service includes an integrated Cashu wallet and offers a privacy-friendly pay-per-query web search engine using bitcoin through the Kagi API.</p></li><li><p>Payments are processed with locked ecash in the X-Cashu HTTP header, linking search and payment in one step.</p></li></ul></li><li><p>00:55:33 <a href="https://tiny-pine.netlify.app/">TinyPine</a>: A simple LN and CASHU ecash POS system for merchants [<a href="https://github.com/Egge21M/tiny-pine">Github</a>]</p></li></ul><h4><strong>Software Releases &amp; Project Updates</strong></h4><ul><li><p>00:55:41 <a href="https://github.com/fedimint/fedimint">Fedimint</a></p></li><li><p>00:56:34 Zeus <a href="https://github.com/ZeusLN/zeus/releases/tag/v0.9.2-rc2">v0.9.2-rc2</a></p><ul><li><p>Activity: Export transaction history to spreadsheets</p></li><li><p>Improved BIP-353 and BOLT 12 support</p><ul><li><p>Fix UI issues indicating BOLT 12 support</p></li><li><p>Fall back to BOLT 11 lightning address if not supported or not found</p></li><li><p>Support BIP-353 on-chain addresses</p></li><li><p>Support BOLT 12 offers encoded in BIP-21 URIs</p></li></ul></li><li><p>Spooky theme</p></li><li><p>Settings: Payments: add &#8216;Slide to Pay&#8217; threshold</p></li><li><p>Hardware wallet and external signer improvements</p></li></ul></li><li><p>00:58:19 Alby Go <a href="https://github.com/getAlby/go/releases/tag/v1.7">v1.7</a></p><ul><li><p>LNURL-withdraw support</p></li><li><p>Improve currency selection</p></li><li><p>Boostagram info in transaction details</p></li></ul></li><li><p>00:58:28 Ride-The-Lightning <a href="https://github.com/Ride-The-Lightning/RTL/releases/tag/v0.15.3">v0.15.3</a></p><ul><li><p>Add support to send payments for AMP invoices on LND</p></li><li><p>Add mempool information on on-chain Send Funds modal</p></li><li><p>Add Fee Rate Information on Send Funds Modal</p></li></ul></li><li><p>00:58:37 CLBOSS <a href="https://github.com/ZmnSCPxj/clboss/releases/tag/v0.14.1-rc2">v0.14.1-rc2</a> - Hand at the Grindstone</p><ul><li><p>Add <code>--lightning-dir</code> option to the contrib scripts</p></li><li><p>Add Nix Support: introduce <code>contrib-shell.nix</code> to facilitate running contrib scripts within Nix environments</p></li></ul></li><li><p>00:58:40 Nutshell <a href="https://github.com/cashubtc/nutshell/releases/tag/0.16.1">v0.16.1</a></p><ul><li><p>Add support for LND via gRPC for LndRPCWallet</p></li><li><p>NUT-15 Multinut payments for CLNRestWallet</p></li><li><p>Stability improvements</p></li></ul></li><li><p>00:59:00 Geyser <a href="https://about.geyser.fund/OLD/Archive/blog/november-2024-release">November 2024</a> - Email Enhancement</p><ul><li><p>Creators can now:</p><ul><li><p>Choose between 9 different types</p></li><li><p>Link Posts to Rewards and Goals</p></li><li><p>Link posts to Goals</p></li><li><p>Send Posts by email</p></li></ul></li><li><p>All Posts have been migrated to Markdown from Rich Text Editor</p></li></ul></li><li><p>00:59:24 Clams Remote <a href="https://github.com/clams-tech/Remote/releases/tag/remote-2.4.0">v2.4.0</a></p><ul><li><p>Add UI for BOLT12 Prism plugin</p></li></ul></li></ul><h3><strong>Nostr</strong></h3><h4><strong>Project spotlight</strong></h4><ul><li><p>00:59:36 <a href="https://snapnostr.app/">SnapNostr</a>: Create clean, customizable screenshots of Nostr posts for seamless sharing [<a href="https://github.com/djhemath/snap-nostr">Github</a>]</p><ul><li><p>&#8220;SnapNostr is an open-source web app designed for Nostr enthusiasts inspired by poet.so. It allows users to create visually appealing, customizable screenshots of Nostr posts. With a focus on simplicity and a clean user experience.&#8221;</p></li></ul></li><li><p>00:59:42 <a href="https://www.openlibrarian.com/">OpenLibrarian</a>: A website for tracking and sharing a love of books [<a href="https://github.com/RydalWater/OpenLibrarian/">Github</a>]</p><ul><li><p>OpenLibrarian utilizes the Nostr protocol and allow users to bring their profile and connections, or leave to other applications on the network</p></li></ul></li><li><p>00:59:49 Jumble: Yet another nostr desktop client [<a href="https://github.com/CodyTseng/jumble">Github</a>]</p><ul><li><p>Originally a feature of the nostr-relay-tray project, Jumble is now a standalone application with:</p><ul><li><p>Relay-Based Browsing: Explore content directly through relays without following specific users</p></li><li><p>Relay-Friendly Design: Minimized and simplified requests ensure efficient communication with relays</p></li><li><p>Relay Groups: Easily manage and switch between relay groups</p></li></ul></li></ul></li><li><p>00:59:54 Honeypot: A &#8220;multiple wallets, multiple currencies&#8221; project by PABLOF7z [<a href="https://njump.me/nevent1qqs8q443syq35fsvf53mw4mphts5nsfqcq7p8xzh2hrp900agfhmgqczyrafsj7hmweg9ur7zmn6apajdg48hxuskujx53rhrux0ttjcqx84yudfep3">Note</a>]</p></li><li><p>1:00:00 <a href="https://www.mutestr.com/">Mutestr</a>: Live Nostr muted list monitor</p><ul><li><p>&#8220;Monitor Nostr muted lists in real-time. Check who muted you, track mute list changes, and explore muting patterns across the Nostr network.&#8221;</p></li></ul></li><li><p>1:00:08 Nostr Gadgets: High-level utils for developing Nostr clients based on <a href="https://github.com/nbd-wtf/nostr-tools">nostr-tools</a> [<a href="https://github.com/nbd-wtf/nostr-gadgets">Github</a>]</p></li><li><p>1:00:16 Mostro Tools: Typescript Mostro library for developing Mostro clients [<a href="https://github.com/MostroP2P/mostro-tools">Github</a>]</p></li></ul><h4><strong>Software Releases &amp; Project Updates</strong></h4><ul><li><p>NDK <a href="https://njump.me/nevent1qgs04xzt6ldm9qhs0ctw0t58kf4z57umjzmjg6jywu0seadwtqqc75sqyrcas7t05mh4tz7g2rkhfy79qga4cg9um9exkr6s5wle0zy34xgj79ked8q">v2.10.5</a></p><ul><li><p>Fix reconnection bug</p></li></ul></li><li><p>Rust nostr <a href="https://github.com/rust-nostr/nostr/releases/tag/v0.36.0">v0.36.0</a></p><ul><li><p>Reduced atomic operations and switched to async concurrency</p></li><li><p>Add NostrSigner trait, better methods and struct names</p></li><li><p>Add LocalRelay and allow to easily serve it as hidden onion service with the embedded tor client</p></li><li><p>Allow to keep track of negentropy sync progress, almost halved the weight of JavaScript SDK bindings</p></li></ul></li><li><p>Primal <a href="https://njump.me/nevent1qqsprmuglutv9vz4rmrze0dpvdavheuv22akjfk786v49n9s0wz22zcpzemhxue69uhhyetvv9ujumn0wd68ytnzv9hxgq3q6c0nh3dnadzqpm76uctf5hqhe2lny344zsmpm6feee9p5rdxaa9q43m0ww">Miljan&#8217;s Note</a></p><ul><li><p>&#8220;Primal feeds are now available on Amethyst, Nostrudel, and any other Nostr client that supports DVM feeds. Yeah. We have a functional feed marketplace on Nostr.&#8221;</p></li></ul></li><li><p>Lume</p><ul><li><p><a href="https://github.com/lumehq/lume/releases/tag/v24.11.8">v24.11.8</a></p><ul><li><p>Add Sync All via Negentropy to Settings</p></li></ul></li><li><p><a href="https://github.com/lumehq/lume/releases/tag/v24.11.7">v24.11.7</a></p><ul><li><p>Use NIP22 for comment</p></li></ul></li><li><p><a href="https://github.com/lumehq/lume/releases/tag/v24.11.5">v24.11.5</a></p><ul><li><p>Add DVM feeds</p></li></ul></li><li><p><a href="https://github.com/lumehq/lume/releases/tag/v24.11.4">v24.11.4</a></p><ul><li><p>Allow user enter custom relay for relayfeeds</p></li></ul></li><li><p><a href="https://github.com/lumehq/lume/releases/tag/v24.11.0">v24.11.0</a></p><ul><li><p>Support multi accounts</p></li><li><p>Add discover newsfeeds column</p></li><li><p>Add discover interests column</p></li><li><p>Add relay viewer column</p></li></ul></li></ul></li><li><p>Mostro <a href="https://github.com/MostroP2P/mostro/releases/tag/v0.12.8">v0.12.8</a> - b4os</p><ul><li><p>Relays scheduled job publish only connected relays</p></li><li><p>Rabbit insipired unwrap removal</p></li><li><p>Implement request_id on mostro messages</p></li><li><p>Trick to avoid getting older events republished</p></li><li><p>Optional request id</p></li><li><p>Avoid sending unsolicited request-id</p></li></ul></li><li><p>YakiHonne <a href="https://njump.me/nevent1qqstx408pfrueymeufqu3mk59g0q6ruxtykxr4dkg24zau2pm9ywexsppamhxue69uhkummnw3ezumt0d5q3vamnwvaz7tmjv4kxz7fwdehhxarj9e3xzmnyqyw8wumn8ghj7mn0wd68ytfsxyh8jcttd95x7mnwv5hxxmmdqyw8wumn8ghj7mn0wd68ytfsxgh8jcttd95x7mnwv5hxxmmdqgszpxr0hql8whvk6xyv5hya7yxwd4snur4hu4mg5rctz2ehekkzrvck0zme9">v2.0</a></p><ul><li><p>Onboarding: add create a non-custodial wallet with Npub &amp; Nsec, experience zapping, or browse as a guest</p></li><li><p>Home &amp; Discover: &#8220;Discover&#8221; is designed for creators, focusing on rich formats like long-form content, videos, and curated works</p></li><li><p>Wallet: Simple setup with easy creation, direct YakiHonne node linking, and multi-wallet support</p></li><li><p>Dashboard: Manage all published and drafted content, check stats, and pick up right where you left off&#8212;all in one place</p></li><li><p>Notifications: Reactions, Reposts, Mentions, Zaps, Comments, and Follows now appear in clear, categorized cards</p></li></ul></li><li><p>Haven <a href="https://github.com/bitvora/haven/releases/tag/v1.0.0">v1.0.0</a></p><ul><li><p>Allow gift wrapped messages in chat relay</p></li><li><p>Remove kind 4 support</p></li><li><p>Add support for configurable binding address</p></li><li><p>Add gcp bucket backup</p></li><li><p>Add delete to inbox relay</p></li><li><p>Blossom Support</p></li></ul></li><li><p>Pokey</p><ul><li><p><a href="https://github.com/KoalaSat/pokey/releases/tag/v0.0.6-alpha">v0.0.6</a></p><ul><li><p>Publish inbox relay lists</p></li><li><p>You get a notification when your inbox list is too big</p></li><li><p>Better relay authorization</p></li></ul></li><li><p><a href="https://github.com/KoalaSat/pokey/releases/tag/v0.0.5-alpha">v0.0.5</a></p><ul><li><p>Zaps now display more info</p></li><li><p>Relay list manager</p></li><li><p>Configuration tab</p></li><li><p>Disable event device broadcast</p></li></ul></li><li><p><a href="https://github.com/KoalaSat/pokey/releases/tag/v0.0.4-alpha">v0.0.4</a></p><ul><li><p>New follow notification</p></li><li><p>NIP-42 Auth to Relays</p></li><li><p>Broadcast your inbox events to other apps in your device</p></li></ul></li></ul></li><li><p>Oxchat <a href="https://github.com/0xchat-app/0xchat-app-main/releases/tag/v1.4.0-release">v1.4.0</a></p><ul><li><p>Enhance UX for a Telegram-like experience</p></li><li><p>Update message and calling sounds</p></li><li><p>Add support for CashuB tokens in Cashu wallet</p></li><li><p>Add support for <code>input_fee_ppk</code> in Cashu wallet</p></li><li><p>Add compatibility with Android 9</p></li><li><p>Enable support for <code>kind 15</code> encrypted file messages</p></li></ul></li><li><p>Kyoto <a href="https://github.com/rustaceanrob/kyoto/releases/tag/v0.5.0">v0.5.0</a></p><ul><li><p>Client may fetch a <code>Header</code> at a particular height</p></li><li><p>Support for Testnet4 with new example</p></li></ul></li><li><p>Citrine <a href="https://github.com/greenart7c3/Citrine/releases/tag/v0.5.5">v0.5.5</a></p><ul><li><p>Only store 1 replaceable event</p></li><li><p>Temporally remove the restore contacts feature</p></li></ul></li><li><p>Nostr-PHP <a href="https://github.com/nostrver-se/nostr-php/releases/tag/1.5.0">v1.5.0</a></p><ul><li><p>Add NIP-42 support for client to relay authentication within the library</p></li><li><p>Set generic tags on filter for requestMessages + websocket client to relay improvements</p></li></ul></li><li><p>Keychat <a href="https://github.com/keychat-io/keychat-app/releases/tag/v1.20.3">v1.20.3</a></p><ul><li><p>Set room relays</p></li><li><p>Change sentry to firebase</p></li></ul></li><li><p>Fountain <a href="https://blog.fountain.fm/p/1-1-6">v1.1.6</a></p><ul><li><p>New Audio APIs</p></li><li><p>New Performance Upgrades</p></li><li><p>Add Nested Navigation</p></li></ul></li><li><p>Nak <a href="https://github.com/fiatjaf/nak/releases/tag/v0.7.9">v0.7.9</a></p><ul><li><p>Build arm binary for Raspberry Pi 32bit</p></li></ul></li></ul><h3><strong>Boosts</strong></h3><ul><li><p>1:08:57 Thanks to everyone who streamed sats, and shoutout to our top boosters:</p><ul><li><p>[&#127942; TOP BOOSTER] @Ape Mithrandir (2,112 sats) &#8220;Not long enough, was still awake at the end&#8221;</p></li><li><p>@btconboard (1,000 sats) &#8220;Great pod&#8221;</p></li><li><p>@VonPhoto (1,000 sats)</p></li><li><p>@AVERAGE_GARY (100 sats) &#8220;Red/green colorblind. Rekt from @NVK&#8217;s trading advice.&#8221;</p></li></ul></li></ul><h3><strong>Tech Tips of the Day</strong></h3><ul><li><p>1:10:45 <a href="https://localsend.org/">LocalSend</a>: An open-source cross-platform alternative to AirDrop [<a href="https://github.com/localsend/localsend">Github</a>]</p><ul><li><p>LocalSend enables secure communication between devices using a REST API and HTTPS encryption, and doesn&#8217;t require an internet connection or third-party servers.</p></li></ul></li><li><p>1:10:54 Disable 2G mobile connectivity for iPhone devices using Lockdown mode, helping protect against downgrade attacks from IMSI catchers or fake cell towers that exploit GSM vulnerabilities. [<a href="https://x.com/haxrob/status/1854679084330369047">HaxRob&#8217;s Twitter thread</a>]</p></li></ul><h3><strong>Bitcoin Optech Newsletter</strong></h3><ul><li><p>Highlights from recent Bitcoin Optech Newsletters</p><ul><li><p><a href="https://bitcoinops.org/en/newsletters/2024/11/08/">328</a></p><ul><li><p>Disclosure of a vulnerability affecting Bitcoin Core versions before 25.1: Antoine Poinsot <a href="https://mailing-list.bitcoindevs.xyz/bitcoindev/uJpfg8UeMOfVUATG4YRiGmyz5MALtZq68FCBXA6PT-BNstodivpqQfDxD1JAv5Qny_vuNr-A1m8jIDNHQLhAQt8hj8Ee9OT6ZFE5Z16O97A=@protonmail.com/">announced</a> to the Bitcoin-Dev mailing list the final vulnerability disclosure predating Bitcoin Core&#8217;s new disclosure policy.</p></li></ul></li><li><p><a href="https://bitcoinops.org/en/newsletters/2024/11/01/">327</a></p><ul><li><p>Timeout tree channel factories: ZmnSCPxj <a href="https://delvingbitcoin.org/t/superscalar-laddered-timeout-tree-structured-decker-wattenhofer-factories/1143">posted</a> to Delving Bitcoin and discussed with Optech contributors a proposal for a new multi-layer channel factory design named SuperScalar.</p></li><li><p>Draft BIP for DLEQ proofs: Andrew Toth <a href="https://mailing-list.bitcoindevs.xyz/bitcoindev/b0f40eab-42f3-4153-8083-b455fbd17e19n@googlegroups.com/">posted</a> to the Bitcoin-Dev mailing list a draft BIP and a link to an implementation for generating and verifying proofs of discrete log equality (DLEQ) for the elliptic curve used by Bitcoin (secp256k1).</p></li></ul></li></ul></li></ul><h3><strong>News &amp; Noteworthy</strong></h3><h4><strong>Bitcoin</strong></h4><ul><li><p><a href="http://lists.linuxfoundation.org/">Lists.linuxfoundation.org</a> is no longer active, all archives are now unavailable. The bitcoin-dev mailing list was moved earlier in 2024 in preparation for this. [<a href="https://x.com/kanzure/status/1853588622017990667">List moderator Bryan Bishop&#8217;s announcement</a>]</p></li></ul><h4><strong>Lightning + L2+</strong></h4><ul><li><p>1:12:38 Charmaine Ndolo and Florian Tschorsch publish <a href="https://drops.dagstuhl.de/storage/00lipics/lipics-vol316-aft2024/LIPIcs.AFT.2024.12/LIPIcs.AFT.2024.12.pdf">Payment Censorship in the Lightning Network Despite Encrypted Communication</a></p><ul><li><p>The research identifies that a network-level adversary, like an autonomous system (AS), can censor payments in the Lightning Network. The attack would leverage network-level information, including TCP headers, to track and interfere specifically with LN payment messages.</p></li><li><p>The study demonstrates that an AS can detect and delay specific payment messages without affecting other LN operations, allowing plausible deniability.</p></li></ul></li><li><p>1:14:01 Blockstream opens its newest research center in Lugano, Switzerland, focusing on Liquid and Lightning network advancements [<a href="https://njump.me/nevent1qqsq4hpyjtlf3xcn7s7p5cz0e0av4chmz3wzte26r02gssa54vct5qcpzemhxue69uhhyetvv9ujumn0wd68ytnzv9hxgqg0waehxw309ahx7um5wghx6mmdqgsfy229w70e8lgtxavlz9t78k06yrel6fxyhreteafqet8kfxhhwmgfj3f3p">Note</a>]</p></li><li><p>1:14:05 <a href="https://casaos.io/">CasaOS</a> integrates Alby Hub, a self-custodial lightning wallet and lightning network node [<a href="https://blog.getalby.com/alby-hub-brings-self-custodial-bitcoin-payments-to-casaos/">Announcement</a>]</p></li></ul><h4><strong>Business &amp; Finance</strong></h4><ul><li><p>1:14:46 Block refocuses on bitcoin mining equipment and Bitkey, reduces investments in Tidal and shutdowns TBD, Block&#8217;s decentralized Web5 project [<a href="https://www.coindesk.com/business/2024/11/07/jack-dorseys-square-to-invest-more-in-bitcoin-mining-and-shut-decentralized-web5-web-venture/">CoinDesk</a>] [<a href="https://s29.q4cdn.com/628966176/files/doc_financials/2024/q3/Shareholder_Letter_Block_3Q24.pdf">Shareholder letter</a>]</p></li><li><p>1:15:49 Fold App introduces insured deposits [<a href="https://blog.foldapp.com/introducing-insured-deposits/">Press release</a>]</p><ul><li><p>The feature allow users to deposit and receive bitcoin into an &#8220;institution-grade cold storage custody&#8221;, insured up to $250M.</p></li></ul></li><li><p>1:16:33 Strike introduces Bitcoin auto-withdrawals [<a href="https://x.com/Strike/status/1853839425735630918">Announcement</a>]</p></li><li><p>European Bitcoin store ShopinBit launches in Switzerland [<a href="https://x.com/shopinbit/status/1854819296037187902">Announcement</a>]</p></li><li><p>1:18:52 <a href="https://ten31.vc/">Ten31</a> launches <a href="https://fountain.fm/episode0wDNpldziJ3hBHZWKIdt">Bitcoin Alpha</a>, its new podcast</p></li><li><p>1:19:13 CleanSpark finalized its acquisition of GRIID Infrastructure, a Bitcoin mining infrastructure provider, for $155 million [<a href="https://www.prnewswire.com/news-releases/cleanspark-completes-acquisition-of-griid-infrastructure-inc-302292591.html">PR Newswire</a>]</p></li></ul><h4><strong>Nostr</strong></h4><ul><li><p>1:19:25 Nos.social is now live in Australia and New Zealand [<a href="https://njump.me/nevent1qgsq7gkqd6kpqqngfm7vdr6ks4qwsdpdzcya2z9u6scjcquwvx203dsqyruymaavz9pvxxsdnjc868wl3dzfye4fx4x8qam7q5l7chnj48xk24srqee">Announcement</a>]</p><ul><li><p>&#8220;Complete with an updated onboarding workflow designed to help new users understand keys, find people to follow, and create their first post.&#8221;</p></li></ul></li></ul><h4><strong>Hyperbitconization</strong></h4><ul><li><p>UK pension scheme incorporates bitcoin in asset allocation strategy [<a href="https://pensiontrusts.cartwright.co.uk/news-update-cartwright-advises-first-uk-pension-scheme-on-bitcoin-asset-allocation.html">Press release</a>]</p><ul><li><p>Cartwright has advised a UK pension scheme to allocate 3% of its portfolio to bitcoin, a pioneering step for the industry</p></li></ul></li><li><p>Detroit plans to become the largest U.S. city to accept Bitcoin and cryptocurrency for taxes and fees by mid-2025 [<a href="https://www.tftc.io/detroit-accepts-bitcoin-crypto-tax-payments/">TFTC</a>]</p><ul><li><p>This initiative, supported by PayPal&#8217;s secure platform, aims to improve payment accessibility, especially for unbanked citizens. [<a href="https://detroitmi.gov/news/detroit-become-largest-city-us-accept-cryptocurrency-payments-taxes-other-fees">Press release</a>]</p></li></ul></li></ul><h4><strong>Funding</strong></h4><ul><li><p>1:19:32 OpenSats announces its <a href="https://opensats.org/blog/8th-wave-nostr-grants">Eighth Wave of Nostr Grants</a>, directed at five projects:</p><ul><li><p>Formstr</p></li><li><p>Groups</p></li><li><p>Coop</p></li><li><p>Nostrability</p></li><li><p>NIP-44 Libraries Audit</p></li></ul></li></ul><h4><strong>Mining</strong></h4><ul><li><p>1:20:23 Deutsche Telekom&#8217;s subsidiary, MMS, collaborates with Bankhaus Metzler to pilot &#8220;Digital Monetary Photosynthesis&#8221;, a Bitcoin mining initiative to manage surplus energy and stabilize Germany&#8217;s power grid. [<a href="https://www.telekom.com/en/media/media-information/archive/test-bitcoin-mining-infrastructure-for-surplus-energy-1082684">Press release</a>]</p></li></ul><h4><strong>Privacy</strong></h4><ul><li><p>1:20:38 British activist and journalist Tommy Robinson, was sentenced to 18 months in prison after failing to unlock his phone for police under the Terrorism Act during a stop at the Channel Tunnel in July [<a href="https://www.zerohedge.com/geopolitical/tommy-robinson-jailed-18-months-contempt-court">Zero Hedge</a>]</p></li><li><p>1:20:47 Former TD Bank anti-money laundering employee, is indicted for unlawfully distributing customers&#8217; personal identifying information on Telegram [<a href="https://manhattanda.org/d-a-bragg-announces-indictment-of-td-bank-employee-who-distributed-customer-information-on-telegram/">Press release</a>]</p><ul><li><p>Evidence shows Sewell collected data from over 70 customers, including images of 255 checks, and advised accomplices on account-opening to deposit the checks, profiting from shared proceeds.</p></li></ul></li><li><p>1:21:02 Kenya to require incoming passengers to declare phone IMEI numbers from 2025 [<a href="https://androidkenya.com/2024/11/all-passengers-entering-kenya-to-declare-phone-imei-numbers-at-port-of-entry/">Android Kenya</a>]</p><ul><li><p>Starting January 1, 2025, travelers entering Kenya must declare all mobile phone IMEI numbers via the F88 passenger form.</p></li></ul></li><li><p>1:21:09 Apple adds &#8220;inactivity timer&#8221; feature in iOS 18.1 that reboots iPhones after prolonged inactivity [<a href="https://archive.ph/0kfDW">404 Media</a>]</p><ul><li><p>Researchers confirm the feature shifts iPhones from &#8220;After First Unlock&#8221; to the more secure &#8220;Before First Unlock&#8221; state, where standard forensic tools struggle to extract data.</p></li></ul></li></ul><h4><strong>Protocol</strong></h4><ul><li><p>1:22:16 Ren Crypto Fish, Steve Lee and Lyn Alden publish <a href="https://github.com/bitcoin-cap/bcap/blob/main/bcap_v1.0.pdf">Analyzing Bitcoin Consensus: Risks in Protocol Upgrades</a></p><ul><li><p>The paper examines the evolution of Bitcoin&#8217;s consensus mechanisms and potential risks involved in future protocol upgrades from both economic and technical perspectives. It outlines historical trends, changes, and contentious periods in Bitcoin&#8217;s consensus development since 2009. [<a href="https://github.com/bitcoin-cap/bcap">Github</a>]</p></li></ul></li><li><p>1:25:30 BIPs #1676: Updates the status of BIP85 to final, as it is now widely deployed and has reached a point where breaking changes are no longer introduced. This decision follows the recent merging and subsequent reversion of a breaking change. [<a href="https://github.com/bitcoin/bips/pull/1676">Merged</a>]</p></li><li><p>1:25:47 LDK #3207: Adds the ability to include invoice requests in the async payments&#8217; onion message when paying static BOLT12 invoices as an always online sender. [<a href="https://github.com/lightningdevkit/rust-lightning/pull/3207">Merged</a>]</p></li></ul><h4><strong>Government &amp; Political</strong></h4><ul><li><p>1:26:05 U.S. Department of Justice charges AurumXchange operator with laundering funds linked to Silk Road [<a href="https://cointelegraph.com/news/doj-accuses-crypto-exchange-operator-of-laundering-silk-road-money">Coin Telegraph</a>]</p><ul><li><p>The DOJ accuses the former operator of AurumXchange, of laundering over $30 million, including funds from the Silk Road darknet marketplace. He allegedly failed to register with the U.S. Treasury and neglected AML requirements, processing transactions without proper oversight.</p></li></ul></li><li><p>1:26:12 Bitcoin Fog alledged operator, Roman Sterlingov, has been sentenced to 12.5 years in prison for money laundering conspiracy [<a href="https://www.justice.gov/opa/pr/bitcoin-fog-operator-sentenced-money-laundering-conspiracy">DoJ Press release</a>]</p></li><li><p>1:26:34 Argentina&#8217;s central bank hosts a live Bitcoin mining art exhibit <a href="https://tn.com.ar/tecno/novedades/2024/10/31/el-banco-central-exhibe-mineras-de-criptomonedas-en-funcionamiento-nunca-se-hizo-esto-en-el-mundo/">titled</a> &#8220;Art, Artificial Intelligence, and the Future of the Economy&#8221; by Alberto Echegaray, becoming the first central bank to publicly mine bitcoin [<a href="https://bitcoinnews.com/adoption/argentina-central-bank-bitcoin-mining/">Bitcoin News</a>]</p></li><li><p>1:26:50 BIS to leave cross-border payments platform Project mBridge <a href="https://archive.ph/rQZOz">Reuters</a></p><ul><li><p>Project mBridge, launched in 2021 with central banks from China, Hong Kong, Thailand, and the UAE, was joined by Saudi Arabia in June. Despite reaching the &#8220;minimum viable product&#8221; stage, BIS General Manager Carstens emphasized that it is not yet ready to begin operations and will require many more years of development.</p></li></ul></li><li><p>1:26:56 Sovereignty concerns arise over digital euro as European Union and European Central Bank debate control [<a href="https://www.politico.eu/article/digital-euro-sparks-sovereignty-battle-eu-governments-ecb-monetary-tool-banking/">Politico</a>]</p><ul><li><p>The digital euro project has sparked tension between EU governments and the ECB over control and authority. Countries like France and Germany express concerns about ECB overreach, fearing that its control over digital wallet limits could threaten the banking sector&#8217;s stability.</p></li></ul></li></ul><h4><strong>Events</strong></h4><ul><li><p>1:27:22 <a href="https://btchel.com/">Btc Hel</a>: The first ever large scale bitcoin conference in the Nordics.</p><ul><li><p>August 15-16, 2025 in Helsinki, Finland</p></li></ul></li></ul><h3><strong>Reads</strong></h3><ul><li><p>1:27:46 Here&#8217;s a list of our top recently published reads:</p><ul><li><p>On Ossification by Jameson Lopp [<a href="https://blog.lopp.net/on-ossification/">Blog post</a>]</p></li><li><p>Quantum Computing: Between Hope and Hype by Scott Aaronson [<a href="https://scottaaronson.blog/?p=8329">Blog</a>]</p></li><li><p>Analyzing Bitcoin Consensus: Risks in Protocol Upgrades by Ren Crypto Fish, Steve Lee and Lyn Alden [<a href="https://github.com/bitcoin-cap/bcap/blob/main/bcap_v1.0.pdf">Github</a>]</p></li><li><p>Why I&#8217;m Betting Big on Nostr by Hivemind Ventures [<a href="https://hivemind.vc/nostr/">Blog</a>]</p></li><li><p>The case against edits by Fiatjaf [<a href="https://njump.me/nevent1qqsv4fja3va3rky8mfcc3ul7whpn67lgp57l33r0ysdzwkuswkygvaqzyqalp33lewf5vdq847t6te0wvnags0gs0mu72kz8938tn24wlfze6sanc9u">Note</a>]</p></li><li><p>Digital Gold: Evaluating a Strategic Bitcoin Reserve for the United States by Bitcoin Policy Institute [<a href="https://www.btcpolicy.org/articles/digital-gold-evaluating-a-strategic-bitcoin-reserve-for-the-united-states">Research paper</a>]</p></li></ul></li></ul><h3><strong>Episode submission ideas</strong></h3><ul><li><p>We&#8217;re looking for ideas for interesting panel conversations. To send Bitcoin related questions, just go to <a href="https://bitcoin.review/">bitcoin.review</a> and follow the contact links at the bottom of the page.</p></li></ul><h3><strong>Get in touch with the pod</strong></h3><ul><li><p><a href="https://twitter.com/bitcoinreviewhq">Podcast Twitter</a></p></li><li><p><a href="https://twitter.com/nvk">NVK Twitter</a></p></li><li><p><a href="https://t.me/BitcoinReviewPod">Telegram</a></p></li><li><p><a href="mailto:producer@coinkite.com">Email</a></p></li><li><p>Nostr &amp; LN &#9889;nvk@nvk.org (not an email!)</p></li></ul>]]></content:encoded></item><item><title><![CDATA[BR086 - Electrum, Wasabi, Bitkey, Bitcoin Safe, Spark, Bitcoin Keeper, OP_CAT Privacy, FROST X nostr, btcd FindAndDelete bug + MORE ft. Rijndael & Ben]]></title><description><![CDATA[I&#8217;m joined by guests Rijndael & Ben Carman to go through the list.]]></description><link>https://substack.bitcoin.review/p/br086-electrum-wasabi-bitkey-bitcoin</link><guid isPermaLink="false">https://substack.bitcoin.review/p/br086-electrum-wasabi-bitkey-bitcoin</guid><dc:creator><![CDATA[STACK TO THE FUTURE]]></dc:creator><pubDate>Thu, 31 Oct 2024 21:07:59 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a95ac75-ac77-4167-9383-9930a48690bb_1080x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I&#8217;m joined by guests <a href="https://twitter.com/rot13maxi">Rijndael</a> &amp; <a href="https://twitter.com/benthecarman">Ben Carman</a> to go through the list.</p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://bitcoin.review/podcast/episode-56/&quot;,&quot;text&quot;:&quot;Listen on your favorite podcast app&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://bitcoin.review/podcast/episode-56/"><span>Listen on your favorite podcast app</span></a></p><div><hr></div><h3><strong>Housekeeping</strong></h3><ul><li><p>00:00:51 <a href="https://nostrrising.com/">Nostr Rising</a> series has dropped!</p></li><li><p>00:01:36 New COLDCARD Tutorials:</p><ul><li><p><a href="https://youtu.be/9_0bP-TOXLM">Understanding Anti-Phishing</a>: Changing your PIN and using the anti-phishing words</p></li><li><p><a href="https://youtu.be/khu0Jqjisd0">Understanding CC caution lights</a>: Understanding the caution lights on your Coldcard Q and Mk4</p></li><li><p><a href="https://youtu.be/8hhda2wb_5c">Tapsigner Spend (Nunchuk)</a>: How to spend from a TAPSIGNER on Nunchuk</p></li></ul></li><li><p>00:01:40 Coinkite is opening an office in LATAM &#127774; [<a href="https://x.com/COLDCARDwallet/status/1849480948447928763">Announcement</a>]</p></li><li><p>00:01:50 Bitcoin per Share: new metric added to <a href="https://bitcointreasuries.net/">BitcoinTreasuries.net</a></p></li><li><p>00:01:54 <a href="https://store.coinkite.com/store/sc-hcb-1">Grumpy Surfer SATSCARD</a> is the latest collaboration with Spiral #HereComesBitcoin, all profits will be donated to Bitcoin Education.</p></li><li><p><a href="https://fuckthebears.org/">Fuckthebears.org</a> is now live</p></li></ul><h3><strong>Urgent Vulnerability Disclosures</strong></h3><ul><li><p>00:02:08 Disclosure of CVE-2024-38365: btcd <code>FindAndDelete</code> bug [<a href="https://delvingbitcoin.org/t/cve-2024-38365-public-disclosure-btcd-findanddelete-bug/1184/1">Public disclosure</a>]</p><ul><li><p>&#8220;Btcd prior to version 0.24.2 4 does not correctly implement the consensus rules for legacy signature verification. The incompatible behavior can be triggered by a standard transaction, making it possible for anyone to fork off vulnerable btcd nodes at virtually no cost.&#8221;</p></li></ul></li><li><p>00:05:32 Disclosure of CVE-2024-35202: Remotely reachable assertion crash in Bitcoin Core &lt;v25.0 [<a href="https://bitcoincore.org/en/2024/10/08/disclose-blocktxn-crash/">Public disclosure</a>]</p><ul><li><p>A high severity vulnerability in Bitcoin Core allowed attackers to remotely crash nodes by triggering an assertion in the blocktxn message handling logic.</p></li><li><p>Attackers could exploit the vulnerability without needing to trigger collisions, as they could simply include transactions not committed to in the block&#8217;s merkle root.</p></li></ul></li><li><p>00:06:54 Krux: A bug in Krux beta versions 24.10.beta6 to beta8 affects BIP85 password generation [<a href="https://x.com/odudex/status/1849279549860680038">Announcement</a>]</p><ul><li><p>Users should record and replace passwords created in these versions, as they may be incorrect</p></li><li><p>Version 24.10.beta9 contains a fix, and users are recommended to wait for the official release</p></li></ul></li><li><p>00:07:32 Nostr client Coracle has been unintentionally sending user session data to Bugsnag when reporting errors [<a href="https://njump.me/nevent1qqsrz6g5ds3dfht4a6zgdt7k593ujhnrz4njn6mke2fmpwxjc3sgafcpzemhxue69uhhyetvv9ujumn0wd68ytnzv9hxgqg6waehxw309aex2mrp0yh8wetnw3jhymnzw33jucm0d5q3gamnwvaz7tmjv4kxz7fwv3sk6atn9e5k7q3qjlrs53pkdfjnts29kveljul2sm0actt6n8dxrrzqcersttvcuv3q5afcmh">Holdbod&#8217;s note</a>]</p><ul><li><p>An error reporting misconfiguration in Coracle has sent users&#8217; session data, including private keys, to Bugsnag since December 5, 2023. Affected users include those who triggered an error while signed in with their private key.</p></li><li><p>A new Coracle version has been released, affected APKs have been deleted, all Bugsnag data has been erased and the Bugsnag project was deleted to ensure no further exposure.</p></li></ul></li></ul><h3><strong>Bitcoin</strong></h3><h4><strong>Software Releases &amp; Project Updates</strong></h4><ul><li><p>00:11:00 Electrum</p><ul><li><p><a href="https://github.com/spesmilo/electrum/releases/tag/4.5.7">v4.5.7</a></p><ul><li><p>General: new: add new historical exchange rate providers: Bitfinex and Bitstamp servers with weird TLS certs. As workaround, set pre-3.13 behaviour</p></li><li><p>Lightning: fix: send update_fee right away after channel_reestablish</p></li><li><p>Qt Desktop GUI: fix: show fee warnings also in the transaction dialog (c4fe2796)</p></li></ul></li><li><p><a href="https://github.com/spesmilo/electrum/releases/tag/4.5.6">v4.5.6</a></p><ul><li><p>General:</p><ul><li><p>new: add support for testnet4</p></li><li><p>changed: set stricter UNIX permissions for log files</p></li></ul></li><li><p>QML GUI (Android):</p><ul><li><p>new: show seed passphrase in WalletDetails</p></li><li><p>new: set max screen brightness when displaying QR codes</p></li></ul></li><li><p>Hardware wallets:</p><ul><li><p>ColdCard: export multisig wallet to coldcard over USB</p></li><li><p>Trezor: add support for new device &#8220;Safe 5&#8221;</p></li><li><p>Ledger: add support for new device &#8220;Flex&#8221;</p></li></ul></li><li><p>CLI/RPC: changed: require wallet password for lnpay and similar commands</p></li></ul></li><li><p>Electrum releases a reproducibly built version into the official F-Droid repository [<a href="https://github.com/spesmilo/electrum/issues/1700">Github</a>]</p></li><li><p>How to dump your xpriv on Electrum: <code>wallet.keystore.get_master_private_key('ur password')</code></p></li></ul></li><li><p>00:14:31 Nunchuk Android <a href="https://github.com/nunchuk-io/nunchuk-android/releases/tag/android.1.9.53">v1.9.53</a></p><ul><li><p>Revamped Home screen and user onboarding experience</p></li><li><p>Allow users to clone a Decoy wallet from existing wallets</p></li></ul></li><li><p>00:14:46 Bitcoin Keeper</p><ul><li><p><a href="https://github.com/bithyve/bitcoin-keeper/releases/tag/v1.2.17">v1.2.17</a></p><ul><li><p>TapSigner Experience Overhauled:</p><ul><li><p>Download encrypted backups of your TapSigner</p></li><li><p>Change the card&#8217;s PIN</p></li><li><p>Unblock the card if rate-limited</p></li></ul></li><li><p>Key/ Signer Improvements:</p><ul><li><p>Associate contacts with signing keys</p></li><li><p>Better options for exporting and securing keys</p></li></ul></li><li><p>Wallet Data Management:</p><ul><li><p>Enhanced wallet import and export options</p></li><li><p>Improved file sharing across the app</p></li></ul></li></ul></li><li><p><a href="https://github.com/bithyve/bitcoin-keeper/releases/tag/v1.2.15">v1.2.15</a></p><ul><li><p>Use Canary Wallet even for the Recovery Key</p></li><li><p>Flexibility to only create vault and hide/ delete them for security reasons</p></li></ul></li></ul></li><li><p>00:16:49 Bisq2 <a href="https://github.com/bisq-network/bisq2/releases/tag/v2.1.2">v2.1.2</a></p><ul><li><p>Optimized reputation system:</p><ul><li><p>Trade limits are now tied directly to the seller&#8217;s reputation score</p></li><li><p>Reputation earned through burning or bonding BSQ will now double over first year</p></li><li><p>Reputation requirements have been relaxed (eliminated) for trades up to 25 USD</p></li><li><p>The minimum required reputation score has been removed</p></li></ul></li><li><p>Consolidated chat rooms: based on user feedback, chats have been streamlined into fewer areas</p></li></ul></li><li><p>00:16:58 Wasabi Wallet <a href="https://github.com/WalletWasabi/WalletWasabi/releases/tag/v2.3.0.0">v2.3.0.0</a></p><ul><li><p>Enhance Tor integration</p></li><li><p>Better BTC amount formatting</p></li><li><p>More insight on transactions</p></li><li><p>[Beta] Payment in coinjoin (RPC only)</p></li><li><p>Add Trezor Safe 5 &amp; ColdCard Q support</p></li></ul></li><li><p>00:22:32 Fully Noded releases <a href="https://apps.apple.com/us/app/fully-noded-join-market/id6651860963">Fully Noded</a> and <a href="https://apps.apple.com/us/app/unify-payjoin-wallet/id6504735719">Unify</a> on the App Store</p><ul><li><p>Fully Noded - Join Market is a dedicated Join Market client: connect over Tor, no private keys on device, full maker/taker/fidelity bond functionality, and more.</p></li><li><p>Unify - Payjoin Wallet is a Payjoin capable Bitcoin Core client: p2p over nostr and connect via Tor</p></li></ul></li><li><p>00:22:59 Krux-installer <a href="https://github.com/selfcustody/krux-installer/releases/tag/v0.0.20-beta">v0.0.20-beta</a> - Major update</p><ul><li><p>Now user can, after download and verify an official firmware, select between:</p><ul><li><p>to flash;</p></li><li><p>or make an airgapped update:</p><ul><li><p>user will be requested to insert a (or more) SDCard(s) on computer;</p></li><li><p>installer will recognize it (them);</p></li><li><p>user can select one of them;</p></li><li><p>both firmware.bin and firmware.bin.sig will be copied to sdcard;</p></li><li><p>after the copy, user will be requested to eject sdcard and insert it on device;</p></li><li><p>at same time, the firmware.bin&#8217;s computed hash will appear to compare with the computed hash on device</p></li></ul></li></ul></li></ul></li><li><p>00:23:14 BoltzExchange Client <a href="https://github.com/BoltzExchange/boltz-client/releases/tag/v2.1.10">v2.1.10</a></p><ul><li><p>Support creating swaps with lnurls and lnaddresses</p></li></ul></li><li><p>00:23:31 Utreexo <a href="https://github.com/utreexo/utreexo/releases/tag/v0.2.0">v0.2.0</a></p><ul><li><p>utils: simplify and export proofpositions</p></li><li><p>Revert &#8220;utils: simplify and export proofpositions&#8221;</p></li><li><p>utreexo: use slices from standard lib</p></li><li><p>utils: simplify and proof positions</p></li></ul></li><li><p>00:23:42 Bitcoin Safe <a href="https://github.com/andreasgriffin/bitcoin-safe/releases/tag/1.0.0b1">v1.0.0b1</a> - BETA Version, Use with Caution</p><ul><li><p>Easy Multisig-Wallet Setup:</p><ul><li><p>Step-by-Step instructions for a secure MultiSig setup with PDF backup sheets</p></li><li><p>Test transactions ensure that all hardware signers are ready</p></li><li><p>Full support for Coldcard, Coldcard Q, Bitbox02, Blockstream Jade, and Specter DIY, supporting QR, USB, SD-card</p></li></ul></li><li><p>Secure: Hardware signers only</p><ul><li><p>All wallets require hardware signers/wallets for safe seed storage</p></li><li><p>Powered by BDK</p></li></ul></li><li><p>Multi-Language</p></li><li><p>Simpler address labels by using categories</p><ul><li><p>Automatic coin selection within categories</p></li><li><p>Transaction flow diagrams, visualizing inputs and outputs, click on inputs and output to trace the money flow</p></li></ul></li><li><p>Sending for non-technical users</p><ul><li><p>1-click fee selection via mempool-blocks</p></li><li><p>Automatic merging of utxos when fees are low</p></li></ul></li><li><p>Collaborative:</p><ul><li><p>Label synchronization between different computers and encrypted cloud backup</p></li><li><p>Wallet chat and PSBTs sharing between different computers</p></li></ul></li></ul></li><li><p>00:27:06 Joinstr App <a href="https://gitlab.com/invincible-privacy/joinstr-kmp/-/releases/v0.1.1">v0.1.1</a></p><ul><li><p>Remove BIP 32 derivation paths from signed PSBT</p></li><li><p>Wallet selection in settings</p></li><li><p>Riseup VPN implementation</p></li><li><p>Support Testnet and Mainnet</p></li></ul></li><li><p>00:27:13 Bitkey App <a href="https://bitkey.world/en-US/releases">v2024.71.0</a></p><ul><li><p>You can now select MoonPay in the Bitkey app to sell bitcoin</p></li><li><p>AUD or CAD are now available as display currencies</p></li><li><p>Transaction history and wallet descriptor now available for export</p></li><li><p>Currency display is now Appearance in the Settings menu</p></li></ul></li><li><p>00:28:30 Bitcoin Jungle Mobile <a href="https://apps.apple.com/tt/app/bitcoin-jungle/id1600313979">v1.3.0</a></p><ul><li><p>This update adds a new transaction statistics screen from settings allowing you to do some reporting on your own transaction history.</p></li></ul></li><li><p>00:28:47 Simple Bitcoin Wallet <a href="https://github.com/akumaigorodski/wallet/releases/tag/2.6">v2.6</a></p><ul><li><p>Drop hardware wallet support</p></li><li><p>Drop built-in Tor support</p></li><li><p>Drop LNURL support</p></li></ul></li><li><p>00:29:26 DATUM Gateway <a href="https://github.com/OCEAN-xyz/datum_gateway/releases/tag/v0.2beta">v0.2-beta</a> - Initial public release</p><ul><li><p>OCEAN releases the DATUM Gateway source code, as well as the Linux binaries and a StartOS node runners package</p></li></ul></li><li><p>00:30:28 ESP-Miner <a href="https://github.com/skot/ESP-Miner/releases/tag/v2.3.0">v2.3.0</a></p><ul><li><p>Allow connecting to open WiFi networks</p></li><li><p>Set default cpu freq to 240mhz</p></li><li><p>Add support for TPS546D24S as a drop in replacement for the TPS546D24A</p></li><li><p>Protect against negative frequency and voltage values</p></li><li><p>Add warnings for consecutive timeout responses (no rx) from the chip</p></li><li><p>Add overheat button and change loading service</p></li></ul></li><li><p>00:30:42 Braiins Toolbox <a href="https://x.com/BraiinsMining/status/1848743113382097105">v24.09</a></p><ul><li><p>Add full support for Antminer S21 Pro with AML control board</p></li><li><p>Add BETA support for Antminer S21 XP with AML control board</p></li><li><p>Power estimations and power measuring has been made more accurate, and there now are more available underclocking targets</p></li><li><p>Implement DPS cycling prevention and mitigated unwanted tunings</p></li></ul></li><li><p>00:30:46 Blockstream Green iOS <a href="https://github.com/Blockstream/green_ios/releases/tag/release_4.0.36">v4.0.36</a></p><ul><li><p>Allow redeposit of expired utxos in liquid multisig accounts</p></li><li><p>QR mode for singlesig watch-only</p></li><li><p>Recovery phrase: improve QR view</p></li></ul></li><li><p>00:31:07 Defibi App <a href="https://njump.me/nevent1qqsdusen0aymmme80r8e78a0uhjkjm38xcv200zndw4q0v8sy07ru6gpz4mhxue69uhhyetvv9ujuerpd46hxtnfduhsygpfzgk72hyql95jr35ywwdjvu4p4ulgezqgys6kafl2yrrzq52jzqpsgqqqqqqs27wz8u">v0.0.52</a></p><ul><li><p>Coldcard MK4 Integration: Now you can store your escrow keys directly on the Coldcard MK4 hardware wallet</p></li><li><p>Explore Page: Find useful content right in the app</p></li></ul></li><li><p>00:31:45 Nirvati <a href="https://nirvati.org/blog/nirvati-0-1-0-launch">v0.1.0</a></p><ul><li><p>Open-source: Nirvati adopts a copyleft license to ensure users retain rights over the software</p></li><li><p>Decentralization and data redundancy: Current solutions often concentrate data in one location, posing risks of loss; nirvati enables data distribution across multiple devices for better redundancy and failover options.</p></li><li><p>Security: Existing systems lack secure communication and app isolation, allowing potential security risks; nirvati enforces encrypted connections and isolates apps to improve data safety.</p></li><li><p>Remote access: Many self-hosting platforms restrict access to local networks; nirvati uses Tailscale to provide secure remote access without extra configurations.</p></li><li><p>Reversible updates: Conventional systems do not support app rollback options, locking users into new versions; nirvati includes app snapshots to enable simple update reversions.</p></li><li><p>Multi-user support: Standard systems limit safe multi-user functionality; nirvati introduces a permission-based account system for user isolation on shared servers.</p></li></ul></li><li><p>00:32:08 BTCmap-android <a href="https://github.com/teambtcmap/btcmap-android/releases/tag/v0.8.0">v0.8.0</a></p><ul><li><p>Show place comments</p></li><li><p>Hide ATMs by default</p></li><li><p>Show places offering delivery</p></li></ul></li><li><p>00:32:18 Kyoto <a href="https://github.com/rustaceanrob/kyoto/releases/tag/v0.4.0">v0.4.0</a></p><ul><li><p>New <code>HeaderCheckpoint</code> constructor from height</p></li><li><p><code>shutdown</code>, <code>add_scripts</code>, <code>broadcast_transaction</code> methods have blocking APIs</p></li><li><p>Add a <code>TrustedPeer</code> while the node is running</p></li><li><p>Add change the peer timeout while the node is running</p></li></ul></li><li><p>00:33:03 Bitcoin Dictionary <a href="https://github.com/LoicPandul/Dictionnaire-de-Bitcoin/releases/tag/v0.2-online">v2.0</a></p><ul><li><p>Add a &#8216;double title&#8217; system, for terms that cannot be translated</p></li><li><p>Add .epub version</p></li><li><p>Add and remove definitions, bring the total number to 803 technical terms defined in both french and english</p></li><li><p>The glossary is also available on <a href="https://planb.network/fr/resources/glossary">PlanB Network</a>, in a different user interface</p></li></ul></li></ul><h4><strong>Project spotlight</strong></h4><ul><li><p>00:33:17 [<a href="https://2140.dev/">2140.dev</a>]: European non-profit organization dedicated to supporting Bitcoin research and development</p><ul><li><p>Started by Bitcoin researcher and contributor @RubenSomsen and @josibake, the fund intends to provide a more stable career path to protocol veterans and aspiring contributors who want to work on Bitcoin full-time.</p></li></ul></li><li><p>00:34:24 <a href="https://lclhost.org/">Localhost Research</a>: A Bitcoin-Focused Research Center in the Bay Area [<a href="https://x.com/lclhostresearch/status/1850978751452233788">Announcement</a>]</p></li><li><p>00:34:49 <a href="https://rewindbitcoin.com/">Rewind Bitcoin</a>: Bitcoin wallet in beta that lets you reverse theft [<a href="https://x.com/landabaso/status/1839537481709981981">Trailer</a>]</p><ul><li><p>Rewind&#8217;s Vaults lock funds, starting a countdown when unlocking to allow for response to unauthorized access</p></li><li><p>Users can assign a trusted individual to assist in emergencies, helping to secure funds under certain situations</p></li></ul></li><li><p>00:35:30 <a href="https://bitcoinutils.dev/">bitcoinutils.dev</a>: Utility resource website offering various Bitcoin-related cryptographic and encoding tools by <a href="https://x.com/vostrnad">Vojt&#283;ch Strnad</a></p></li><li><p>00:35:46 Standalone Bitcoin Consensus Engine: A standalone binary exposing the historical bitcoin consensus engine [<a href="https://github.com/ariard/standalone-bitcoinkernel">Github</a>]</p><ul><li><p>This repository contains the historical bitcoin consensus Engine exposed in an experimental standalone binary, i.e <code>bitcoin-chainstate</code>. This is a fork of the libbitcoinkernel project from its 27.0 release tag.</p></li></ul></li><li><p>00:35:54 Fabric: a trustless, distributed DNS resolver for Bitcoin Spaces [<a href="https://github.com/spacesprotocol/fabric">Github</a>]</p><ul><li><p>Fabric enables spaces to publish Bitcoin-signed zone files on a permissionless DHT without storing anything on-chain. Currently default to Testnet4</p></li></ul></li><li><p>00:36:06 <a href="https://crates.io/crates/l402_middleware">l402_middleware</a>: A middleware library for rust that provides handler functions to accept microtransactions before serving ad-free content or any paid APIs [<a href="https://github.com/DhananjayPurohit/l402_middleware">Github</a>]</p></li><li><p>00:36:19 NodeWatch: a CLI dashboard for monitoring your Bitcoin fullnode, providing essential information such as node status, transaction fee estimate, bitcoin price, and more [<a href="https://github.com/caesrcd/NodeWatch">Github</a>]</p></li><li><p>00:36:32 Bitcoind Quick: A dockerized bitcoin core container for quickly spinning up a (pruned) node with zmq support for running public-pool [<a href="https://github.com/gobrrrme/bitcoind_quick">Github</a>]</p></li><li><p>00:36:44 <a href="https://chorly.co/bitcoin">Chorly</a>: reward your kids with sats for completing chores, create a custom chore list for your kids and set up automatic payouts</p></li><li><p>00:36:53 <a href="https://satoffee.com/">Satoffee</a>: Bitcoin coffee machines</p><ul><li><p>Satoffee sells coffee machines that accept Bitcoin payments, allowing users to purchase coffee with Bitcoin through the Lightning Network. The company offers ready-made machines and DIY kits for customization.</p></li></ul></li><li><p>00:37:00 <a href="https://koinvote.com/en">Koinvote</a>: Endorse your candidate with Bitcoin</p><ul><li><p>Koinvote is a weighted voting platform using Bitcoin Signature technology</p></li></ul></li><li><p>00:37:14 <a href="https://www.bitcoinprediction.info/">Bitcoin Prediction Market</a>: Place bets by sending lightning payments and receive winnings to you lightning address.</p></li><li><p>00:37:24 <a href="https://liquisabi.com/">LiquiSabi</a>: Coinjoin explorer: Monitor and publish WabiSabi&#8217;s coordinators advertised on Nostr [<a href="https://github.com/turbolay/LiquiSabi">Github</a>]</p><ul><li><p>LiquiSabi tracks coinjoin transactions and allows you to filter them by the coordinator that staged it.</p></li></ul></li><li><p>00:37:34 <a href="https://coindemo.io/">Coin Demo</a>: A interactive visual introduction into how mining works</p></li></ul><h3><strong>Vulnerability Disclosures</strong></h3><ul><li><p>00:37:42 GoldenJackal&#8217;s specialized toolsets for targeting air-gapped systems in espionage campaigns [<a href="https://www.welivesecurity.com/en/eset-research/mind-air-gap-goldenjackal-gooses-government-guardrails/">We Live Security</a>]</p><ul><li><p>ESET research uncovers two toolsets from GoldenJackal, an APT group, targeting air-gapped systems in Europe and South Asia since 2019. The toolsets include GoldenHowl and GoldenRobo, enabling system infiltration, data collection, and exfiltration through customized malware.</p></li><li><p>ESET&#8217;s findings highlight GoldenJackal&#8217;s expertise in breaching highly secure networks, demonstrating their capability to infiltrate isolated systems that lack internet connections.</p></li></ul></li><li><p>00:38:03 Radiant Capital hack exploits multisig approval process and hardware wallet compromise [<a href="https://x.com/danielvf/status/1847023591117795708">Analysis</a>]</p><ul><li><p>On October 16, 2024, Radiant Capital suffered a security breach totaling $50 million, targeting three trusted, geographically distributed developers through sophisticated malware that intercepted hardware wallet transactions, enabling unauthorized transfer actions like <code>transferOwnership</code>.</p></li><li><p>Attackers leveraged the Safe{Wallet} (Gnosis Safe) interface and normal transaction resubmission behavior to gather signatures without arousing suspicion, while front-end and simulation tools displayed standard transaction data. [<a href="https://medium.com/@RadiantCapital/radiant-post-mortem-fecd6cd38081">Post Mortem</a>]</p></li></ul></li><li><p>00:38:25 Locate X: U.S. law enforcement tool enables warrantless smartphone tracking [<a href="https://archive.ph/B7UhF">404 Media</a>]</p><ul><li><p>The tool, by Babel Street, is available to both government contractors and private investigators, while its lack of usage restrictions poses concerns about unchecked surveillance and data exploitation.</p></li><li><p>Privacy advocates show that this type of surveillance can identify people based on unique identifiers like mobile advertising IDs, breaching presumed privacy safeguards.</p></li></ul></li><li><p>00:38:38 Hackers target Android users with Qualcomm zero-day vulnerability [<a href="https://techcrunch.com/2024/10/09/hackers-were-targeting-android-users-with-qualcomm-zero-day/">TechCrunch</a>]</p><ul><li><p>A zero-day vulnerability was found to affect about 64 different Qualcomm chipsets has been exploited by hackers to target Android users</p></li></ul></li><li><p>00:39:03 Research, conducted by Jonas Hofmann and Kien Tuong Truong with the Applied Cryptography Group at ETH Zurich, discovers flaws in five end-to-end encrypted cloud services [<a href="https://brokencloudstorage.info/">Research paper</a>]</p><ul><li><p>&#8220;End-to-End Encrypted Cloud Storage in the Wild: A Broken Ecosystem&#8221; is an analysis of five E2EE providers&#8212;Sync, pCloud, Icedrive, Seafile, and Tresorit&#8212;reveals severe cryptographic vulnerabilities.</p></li></ul></li><li><p>00:39:20 Security analysis reveals weaknesses in WeChat&#8217;s mmtls encryption protocol [<a href="https://citizenlab.ca/2024/10/should-we-chat-too-security-analysis-of-wechats-mmtls-encryption-protocol/">CitizenLab</a>]</p><ul><li><p>The report highlights the continued use of &#8220;business-layer encryption&#8221; from earlier WeChat versions, despite MMTLS adoption. This legacy encryption adds vulnerabilities due to inconsistencies and lacks essential features like forward secrecy, raising security concerns given WeChat&#8217;s wide user base.</p></li></ul></li><li><p>00:39:34 <a href="https://imprompter.ai/">Imprompter</a>: a tool tricking LLM agents into improper tool use demonstrates the risks of AI chatbot exploitation by hidden malicious prompts [<a href="https://arxiv.org/abs/2410.14923">Research paper</a>]</p><ul><li><p>Security researchers reveal that hackers can trick AI chatbots into disclosing user data by embedding hidden commands in gibberish-like prompts. Attackers exploit the chatbots&#8217; response systems to send sensitive information back to servers controlled by hackers.</p></li></ul></li><li><p>00:39:46 Tails <a href="https://tails.net/news/version_6.8.1/">v6.8.1</a> releases an emergency release to fix a critical security vulnerability in Tor Browser.</p><ul><li><p>&#8220;Update Tor Browser to 13.5.7, which fixes MFSA 2024-51, a major use-after-free vulnerability. Using this vulnerability, an attacker could take control of Tor Browser, but probably not deanonymize you in Tails.&#8221;</p></li></ul></li><li><p>00:39:56 A critical &#8220;use-after-free&#8221; vulnerability (CVE-2024-9680) in Firefox 131.0.2&#8217;s animation timeline allows attackers to execute arbitrary code and take complete control of a machine. Mozilla reports this issue is being exploited in the wild [<a href="https://www.mozilla.org/en-US/security/advisories/mfsa2024-51/">Mozilla Security Advisory</a>]</p></li></ul><h3><strong>Privacy &amp; Other Related Bitcoin Projects</strong></h3><h4><strong>Software Releases &amp; Project Updates</strong></h4><ul><li><p>00:40:38 SimpleX <a href="https://github.com/simplex-chat/simplex-chat/releases/tag/v6.1.1">v6.1</a></p><ul><li><p>Improve calls</p></li><li><p>Improve iOS notifications</p></li><li><p>Improve user experience</p><ul><li><p>Add new conversation layout and customizable messages</p></li><li><p>Add switch between user profiles</p></li><li><p>Increase speed: deletion, moderation and forwarding of messages</p></li></ul></li><li><p>New security audit: SimpleX announces cryptographic design review by Trail of Bits</p></li></ul></li><li><p>00:40:41 SideBand <a href="https://github.com/markqvist/Sideband/releases/tag/1.1.1">v1.1.1</a></p><ul><li><p>Add support for RNode device types that were added in the latest RNS release</p></li><li><p>Update RNS to version 0.8.2</p></li><li><p>Update LXMF to version 0.5.5</p></li></ul></li><li><p>00:40:48 Reticulum MeshChat <a href="https://github.com/liamcottle/reticulum-meshchat/releases/tag/v1.13.1">v1.13.1</a></p><ul><li><p>Add support for high quality audio messages using opus codec</p></li><li><p>Add message attachment sizes to message info dialog</p></li><li><p>Update suggested interface to new domain name</p></li><li><p>Update to RNS v0.8.4</p></li><li><p>Update to LXMF v0.5.6</p></li></ul></li><li><p>00:40:52 Tor Browser <a href="https://blog.torproject.org/new-release-tor-browser-140/">v14.0</a></p><ul><li><p>Add new circuit for Android</p></li><li><p>Extend support for legacy platforms</p></li></ul></li></ul><h4><strong>Project spotlight</strong></h4><ul><li><p>00:40:56 <a href="https://pubky.app/">Pubky Core</a>: An open protocol for per-public-key backends for censorship resistant web applications [<a href="https://github.com/pubky/pubky-core">Github</a>]</p><ul><li><p>It enables public-key-based authentication and third-party authorization without relying on central databases, combining elements of decentralized technology with familiar web standards.</p></li><li><p>PKDNS: A decentralized, censorship-resistant DNS built on Pubky&#8217;s identity layer [<a href="https://github.com/pubky/pkdns">Github</a>]</p><ul><li><p>&#8220;A DNS server providing self-sovereign and censorship-resistant domain names. It resolves records hosted on the Mainline DHT, the biggest DHT on the planet with ~15M nodes that services torrents since 15 years.&#8221;</p></li></ul></li><li><p>Pubky Notes: Note taking app using pubky protocol [<a href="https://github.com/pubky/pubky-notes">Github</a>]</p><ul><li><p>&#8220;Since the data is stored via the Pubky protocol, your notes are not locked into a single app or service&#8212;they&#8217;re portable and reusable&#8221;</p></li></ul></li></ul></li><li><p><a href="https://pubky.tech/">awesome-pubky</a>: A curated list of awesome Pubky resources, libraries, tools and applications [<a href="https://github.com/aljazceru/awesome-pubky">Github</a>]</p></li><li><p><a href="https://pluja.github.io/awesome-privacy/">Awesome Privacy</a>: List of free, open source and privacy respecting services and alternatives to privative services [<a href="https://github.com/pluja/awesome-privacy">Github</a>]</p></li></ul><h3><strong>Lightning + L2+</strong></h3><h4><strong>Project spotlight</strong></h4><ul><li><p>00:42:00 Blockstream launches Simplicity on Liquid testnet and introduces <a href="https://github.com/BlockstreamResearch/simfony">Simfony</a>, a high-level language for writing Bitcoin smart contracts [<a href="https://blog.blockstream.com/simplicity-arrives-on-liquid-testnet/">Blog post</a>]</p><ul><li><p>Simplicity aims to provide a more secure and flexible environment for developers compared to Bitcoin Script.</p></li><li><p>Simfony is a Rust-like high-level language that compiles down to Simplicity bytecode. Work in progress. [<a href="https://github.com/BlockstreamResearch/simfony">Github</a>]</p></li></ul></li><li><p>00:42:09 <a href="https://spark.info/">Spark</a>: A trust-minimized solution designed to scale Bitcoin and extend the Lightning Network</p><ul><li><p>Lightspark announces new Bitcoin L2 and upgrades its Universal Money Address (UMA) standard with the release of UMA Extend, UMA Auth and UMA Request. [<a href="https://x.com/buildonspark/status/1849833055839727821">Announcement</a>]</p></li></ul></li><li><p>00:44:39 <a href="https://blockbuster.fewsats.com/">Blockbuster</a>: Seamless content monetization with the Lightning Network</p><ul><li><p>&#8220;Blockbuster is a media server that allows creators to upload and sell their videos, ebooks, and other content from any application that implements the L402 protocol.&#8221;</p></li><li><p>&#8220;The objective is to be able to share a unique link (L402 URI) that can be consumed across platforms like Nostr, Twitter, or Farcaster.&#8221;</p></li></ul></li></ul><h4><strong>Software Releases &amp; Project Updates</strong></h4><ul><li><p>00:44:45 Core Lightning <a href="https://github.com/ElementsProject/lightning/releases/tag/v24.08.2">v24.08.2</a> - Steel Backed-up Channels</p><ul><li><p>pay: Now remembers and updates channel hints across payments</p></li><li><p>pay: Discarding an overly long or expensive route does not blacklist channels anymore</p></li><li><p>grpc: Channel type <code>anchors/even</code> was added to the grpc bindings</p></li><li><p>Improve pathfinding speed for large nodes</p></li></ul></li><li><p>00:44:54 LDK Node <a href="https://github.com/lightningdevkit/ldk-node/releases/tag/v0.4.0">v0.4.0</a></p><ul><li><p>Add support for multiple chain sources</p></li><li><p>Add support for sourcing chain and fee estimation data from a Bitcoin Core RPC backed</p></li><li><p>Add initial experimental support for an encrypted VSS remote storage backend</p></li><li><p>Add support for setting the NodeAlias in public node announcements</p></li><li><p>Add support for generating and paying unified QR codes</p></li><li><p>Add support for quantity and payer_note fields when sending or receiving BOLT12 payments</p></li><li><p>Add support for setting additional parameters when sending BOLT11 payments</p></li></ul></li><li><p>00:44:58 Phoenix</p><ul><li><p>Phoenixd</p><ul><li><p><a href="https://github.com/ACINQ/phoenixd/releases/tag/v0.4.2">v0.4.2</a></p><ul><li><p>Support fee bumping for on-chain transactions</p></li><li><p>Add a CSV export</p></li></ul></li><li><p><a href="https://github.com/ACINQ/phoenixd/releases/tag/v0.4.0">v0.4.0</a></p><ul><li><p>Support for new on-the-fly funding</p></li><li><p>Use the distribution plugin for all platforms</p></li></ul></li></ul></li><li><p>Phoenix Wallet transitions to new open protocol for Phoenix LSP: The new protocol builds on the Lightning BOLT standard and includes features like dual funding and splicing.</p></li></ul></li><li><p>00:45:01 Zeus <a href="https://github.com/ZeusLN/zeus/releases/tag/v0.9.1">v0.9.1</a></p><ul><li><p>LND: BOLT 11 blinded paths</p></li><li><p>LND: spend full UTXOs</p></li><li><p>LND: Inbound routing fees</p></li><li><p>[Experimental] Rescans for external wallets</p></li><li><p>Simplified open channel UX</p></li><li><p>Linked contacts showing in Channel view</p></li><li><p>LNDHub: dismiss custodial warning</p></li><li><p>POS: add option to default to Keypad view</p></li><li><p>View on-chain address list</p></li></ul></li><li><p>00:45:06 Breez SDK Core (Greenlight) <a href="https://github.com/breez/breez-sdk-greenlight/releases/tag/0.6.2">v0.6.2</a></p><ul><li><p>Greenlight signer fix for de-sync</p></li><li><p>Use invoice destination for trampoline</p></li></ul></li><li><p>00:45:12 Alby</p><ul><li><p>lightning-browser-extension <a href="https://github.com/getAlby/lightning-browser-extension/releases/tag/v3.9.2">v3.9.2</a> - Messier 24: Sagittarius Star Cloud</p><ul><li><p>feat: setup your keys -&gt; setup master key in default view cards</p></li><li><p>Onboarding for node_required accounts</p></li><li><p>Translations update from Hosted Weblate</p></li></ul></li><li><p>Go <a href="https://github.com/getAlby/go/releases/tag/v1.6">v1.6</a> - Security (protect wallet with biometrics, face unlock, PIN, etc) - Link handling support (Lightning links, BIP21) - Improve LNURL handling (fixed amount LNURLs, LUD9 lnurl successActions)</p></li></ul></li><li><p>00:45:15 CashuMe now supports restoring ecash from a seed phrase [<a href="https://x.com/CashuBTC/status/1850462983018705042">Announcement</a>]</p></li><li><p>00:46:11 Microbolt <a href="https://github.com/microbolt-guide/website/releases/tag/v2.0">v2.0</a></p><ul><li><p>Add new firewall: <code>awall</code></p></li><li><p>Add new reverse proxy: <code>caddy</code></p></li><li><p>Add new expl btc: <code>mempool</code></p></li><li><p>Add new section: <code>nostr</code></p></li><li><p>Remove <code>fail2ban</code>, applied firewall level mechanism</p></li><li><p>Bitcoin*: no more patches, except for ordinals</p></li><li><p>Microbolt cloud: automatic deployment of microbolt through ansible</p></li></ul></li><li><p>00:46:18 Geyser <a href="https://about.geyser.fund/OLD/Archive/blog/release-oct-2024">October 2024</a></p><ul><li><p>Private messages: Contributors can now drop a private comment to the creator when funding a project or buying a reward</p></li><li><p>Creator can request buyer Npub: Creators can now request specific information from reward buyers such as their npubs, or reward specifications</p></li><li><p>Creator reward confirmation message: Creators can now tie each reward with a success message. This allows them to automate giving access to certain digital content or spaces</p></li><li><p>Multiple rewards and project images: Creators can now properly showcase their rewards by adding multiple images to them. And project banners can also have multiple images.</p></li><li><p>Add login with email</p></li><li><p>Rebrand Geyser bot to @GeyserSpirit</p></li><li><p>Launch announcement banner</p></li><li><p>Increase creator fees to 5% in the coming 2 weeks for lightning addresses, node-runners will remain on a value-for-value plan</p></li></ul></li><li><p>00:47:08 LN Markets</p><ul><li><p>Add option to Cash In from trade margin</p></li></ul></li><li><p>00:47:14 Zaprite introduces Sandbox Environments [<a href="https://blog.zaprite.com/sandbox-environments-now-available/">Blog post</a>]</p><ul><li><p>Users can now simulate both bitcoin and fiat transactions to test their custom API integrations</p></li></ul></li></ul><h3><strong>Nostr</strong></h3><h4><strong>Project spotlight</strong></h4><ul><li><p>00:47:20 Pokey: Nostr &#8220;Pull Notifications&#8221; on Android [<a href="https://github.com/KoalaSat/pokey">Github</a>)</p><ul><li><p>Receive live notifications for your nostr events and allow other apps to receive and interact with them.</p></li></ul></li><li><p>00:47:25 White Noise</p><ul><li><p>JeffG shares his progress made on implementing MLS messaging on Nostr [<a href="https://njump.me/nevent1qqs92vwt83v4u0ggth29x2pwsz7ssg3s0v4r2rl934vza9lp0gfg2zcpp4mhxue69uhkummn9ekx7mqzyqtnnkfhmjxqcums4gn4skfccyv7yhzp7mzyrfwnf3kns5p7xymw703ceu3">Note</a>]</p></li></ul></li><li><p>00:47:41 Nostrastic: Bridge to publish Nostr posts and send/receive DMs over LoRa using Meshtastic [<a href="https://github.com/quixotesystems/nostrastic">Github</a>]</p></li><li><p>00:49:14 AlgoRelay: An algorithm relay for nostr [<a href="https://github.com/bitvora/algo-relay">Github</a>]</p><ul><li><p>&#8220;AlgoRelay is the first nostr native relay capable of serving personalized, algorithmic feeds without the use of external or proprietary APIs or DVMs.&#8221;</p></li></ul></li><li><p>00:49:22 ppe-relay: A paid relay that charges on per-event basics. [<a href="https://github.com/ptrio42/ppe-relay">Github</a>]</p></li><li><p>00:49:27 Search Relay: A NIP-50 search relay [<a href="https://github.com/ptrio42/search-relay">Github</a>]</p><ul><li><p>Full text search relay using Elasticsearch as backend</p></li></ul></li><li><p>00:49:31 <a href="https://flotilla.coracle.social/">Flotilla</a>: A nostr relay-based communities PWA modeled after discord by Coracle [<a href="https://github.com/coracle-social/flotilla">Github</a>]</p><ul><li><p>&#8220;A discord-like nostr client based on the idea of &#8220;relays as groups&#8221;. WIP.&#8221;</p></li></ul></li><li><p>nostr-editor: A full text editor + note parser for Nostr based on Tiptap / ProseMirror [<a href="https://github.com/cesardeazevedo/nostr-editor">Github</a>]</p><ul><li><p><code>nostr-editor</code> is a collection of Tiptap extensions designed to enhance the user experience when creating and editing nostr notes. It also provides tools for parsing existing notes into a structured content schema.</p></li></ul></li><li><p>Zapchat: A Nostr App Design [<a href="https://njump.me/naddr1qvzqqqrcvgpzp22rfmsktmgpk2rtan7zwu00zuzax5maq5dnsu5g3xxvqr2u3pd7qyt8wumn8ghj7mnfv4kzumn0wd68yvfwvdhk6tcpz9mhxue69uhkummnw3ezuamfdejj7qq00fshqcmgv96z6urjda4x2cm5lrswda">Project description</a>]</p><ul><li><p>Nostr-specific UX/UI for conversations and monetization around any content type, using interoperable communities [<a href="https://www.figma.com/community/file/1430887635327548022/zapchat-a-nostr-app-design">Design system</a>]</p></li></ul></li><li><p>00:51:40 <a href="https://nosweet.net/">nosweet.net</a>: Share or clone any tweet on nostr with a url and without any permission or integration needed [<a href="https://github.com/untreu2/nosweet.net">Github</a>]</p></li><li><p>00:51:54 <a href="https://docstr.app/">Docstr</a>: A simple document management system on Nostr</p><ul><li><p>Docstr allow users to create and delegate documents, only publicly for now.</p></li></ul></li><li><p>00:52:13 Translator: A new nostr service, offering automated translation of notes, videos and memes [<a href="https://njump.me/npub10sa7ya5uwmhv6mrwyunkwgkl4cxc45spsff9x3fp2wuspy7yze2qr5zx5p">Note</a>]</p></li><li><p>00:52:18 rx-nostr: A library based on RxJS, which allows Nostr applications to easily communicate with relays [<a href="https://github.com/penpenpng/rx-nostr">Github</a>]</p></li></ul><h4><strong>Software Releases &amp; Project Updates</strong></h4><ul><li><p>Damus <a href="https://njump.me/nevent1qqstnfe3v66td4y22lvtsrmyu0v5cctmfhr9tu0cnk9pm3r0kq55u7gppamhxue69uhkummnw3ezumt0d5qs6amnwvaz7tmwdaejumr0dsq3vamnwvaz7tmjv4kxz7fwdehhxarj9e3xzmnyqgsraldwhvwcjgltmxwfu7kw8dqef2692yhzheuurd7k3kfy8cxjdqg66lc3n">New TestFlight version</a></p><ul><li><p>Multiple image uploads</p></li><li><p>Seamless scroll</p></li><li><p>Improve text and profile search</p></li><li><p>New side menu</p></li><li><p>Less sensitive thread view notes when scrolling</p></li></ul></li><li><p>Amethyst</p><ul><li><p><a href="https://github.com/vitorpamplona/amethyst/releases/tag/v0.92.4">v0.92.4</a></p><ul><li><p>Makes Amethyst a share target for texts, images and videos</p></li><li><p>Changes the new post screen to use the non-disappearing version of the scaffold</p></li><li><p>Correctly maps the write status of the outbox relays</p></li></ul></li><li><p><a href="https://github.com/vitorpamplona/amethyst/releases/tag/v0.92.2">v0.92.2</a></p><ul><li><p>Moves the API with amber from signature to result</p></li><li><p>Ad new fields on vision prescriptions</p></li><li><p>Prioritise search results that start with the search term</p></li><li><p>Add some test cases for video compressions</p></li><li><p>Add Unknown media type test</p></li><li><p>Use &#8220;use&#8221; blocks to close resources automatically</p></li><li><p>Faster logout processing without closing the account switcher dialog.</p></li><li><p>Add animation to notification chart</p></li><li><p>Add animation to FABs</p></li><li><p>Add animation to zap and reaction popups</p></li><li><p>Support for login with hex key when using amber</p></li></ul></li><li><p>A user <a href="https://njump.me/nevent1qqstx0jy5jvzgh7wr6entjuw7h58d7mapupfdpt9hkf7s4gze34a0vszyrtud5q5kdpgzkazn3y0x3y7fuq88huy7jk4szhpwdfcqsdx4wmtsdx8jl4">shared</a> having successfully used the &#8216;journalist&#8217;s mode&#8217;, temporarly logging into Amethyst using an ncryptsec on a NFC tag</p></li></ul></li><li><p>Coracle</p><ul><li><p><a href="https://github.com/coracle-social/coracle/releases/tag/0.4.15">v0.4.15</a> - Security Release</p><ul><li><p>In past versions of Coracle, user session objects were inadvertently sent to my error reporting platform</p><ul><li><p>Hack in accommodation of algorithmic relay feeds</p><ul><li><p>Downgrade typescript to save my sanity</p></li><li><p>Show links/images as blocks when at the end of a paragraph</p></li><li><p>Implement new profile page and summary designs</p></li><li><p>Stop sending user to bugsnag</p></li></ul></li></ul></li></ul></li><li><p><a href="https://github.com/coracle-social/coracle/releases/tag/0.4.13">v0.4.13</a></p><ul><li><p>Add support for nip05 urls</p></li><li><p>Re-work notification rendering and loading</p></li><li><p>Use Intl api for list formatting (zmjohnson)</p></li><li><p>Update nostr signer version to support app icon url</p></li></ul></li></ul></li><li><p>Iris publishes new Iris version source code [<a href="https://github.com/irislib/iris-client">Github</a>]</p></li><li><p>Lume <a href="https://github.com/lumehq/lume/releases/tag/v4.3.0">v4.3.0</a></p><ul><li><p>Add support for multiple follow sets (NIP-51)</p></li><li><p>Add support for multiple interest sets (NIP-51)</p></li><li><p>Add support for event deletion (NIP-09)</p></li><li><p>Automatically restore window state when reopen app</p></li><li><p>Prioritize query from local database instead of relay</p></li><li><p>Improve search performance, overal performance and stability</p></li></ul></li><li><p>nos.social <a href="https://github.com/planetary-social/nos/releases/tag/v1.0.0-289">v1.0.0</a></p><ul><li><p>Add relay.mostr.pub to the default relay list</p></li><li><p>Add a tip to Discover to prompt first-time users to go to their Feed</p></li><li><p>Add a tip to the Feed to welcome first-time users and explain how the Feed works</p></li><li><p>Add a tag to published contact lists to help us detect the source of lost contact lists</p></li><li><p>Update the onboarding screens with a new design</p></li><li><p>Add new authors and categories to the Discover tab</p></li><li><p>Nos now hides the notes from blocked users when viewing their profile page</p></li></ul></li><li><p>Nostrmo <a href="https://github.com/haorendashu/nostrmo/releases/tag/2.9.3">v2.9.3</a></p><ul><li><p>Add NIP-55 content-resolver support</p></li><li><p>Add cache relay support</p></li><li><p>Live&#8217;s Naddr address link to zap.stream</p></li><li><p>Change filed name for NIP-55&#8217;s meger</p></li><li><p>Change Group&#8217;s sync time</p></li><li><p>Add user change to use the login page</p></li><li><p>Add support for pick multi file for editor</p></li></ul></li><li><p>Mostro <a href="https://github.com/MostroP2P/mostro/releases/tag/v0.12.7">v0.12.7</a></p><ul><li><p>When taking an order, check the status first and then the quantity</p></li><li><p>Update README.md to have instructions for Mac</p></li><li><p>Tonic-lnd</p></li><li><p>Add Cross.toml for protoc compiler inside docker sandbox</p></li></ul></li><li><p>Blossom introduces Onion-routing for event publishing [<a href="https://njump.me/nevent1qvzqqqqqqypzp75cf0tahv5z7plpdeaws7ex52nmnwgtwfr2g3m37r844evqrr6jqy2hwumn8ghj7un9d3shjtnyv9kh2uewd9hj7qg6waehxw309ac8junpd45kgtnxd9shg6npvchxxmmd9uqzpvh9xwwp382kyhe4lztpa90mdvyk33n6uzrdveu2jdxru0dw3xla5srder">Announcement</a>]</p><ul><li><p>This technique hides both the sender&#8217;s identity and IP address, even from the relay used for publishing.</p></li><li><p>&#8220;The sender can include small ecash tokens inside each onion layer to pay for the routing.&#8221; -@Pablof7z</p></li></ul></li><li><p>Citrine <a href="https://github.com/greenart7c3/Citrine/releases/tag/v0.5.2">v0.5.2</a></p><ul><li><p>Support for tor proxy when restoring contact list</p></li><li><p>Support for auto backup every 24 hours</p></li><li><p>Check if port is in use</p></li></ul></li><li><p>Voyage</p><ul><li><p><a href="https://github.com/dluvian/voyage/releases/tag/v0.16.0">v0.16.0</a></p><ul><li><p>Render nip88 polls</p></li><li><p>Vote on nip88 polls</p></li></ul></li><li><p><a href="https://github.com/dluvian/voyage/releases/tag/v0.15.0">v0.15.0</a></p><ul><li><p>Support nip22 comments</p></li><li><p>Always use nip22 when replying to nip22 comment</p></li><li><p>Optionally force nip22 usage</p></li><li><p>Show client, full date time and unix timestamp in post details</p></li><li><p>Create generic repost when cross-posting nip22 comment</p></li><li><p>Show hint when nip22 comment parent is not supported</p></li></ul></li></ul></li><li><p>Chronicle <a href="https://github.com/dtonon/chronicle/releases/tag/v0.2.1">v0.2.1</a></p><ul><li><p>Upgrade dgraph-io/badger</p></li></ul></li><li><p>YakiHonne iOS/Android <a href="https://njump.me/nevent1qgszpxr0hql8whvk6xyv5hya7yxwd4snur4hu4mg5rctz2ehekkzrvcqyqxmhknr9vcd3j2v6ukup9k7028ttrtltkmt2dqhkh3xnq5fdcercja40th">v1.4.1</a></p><ul><li><p>Outbox model support</p></li><li><p>A complete new core with enhanced features that ensures a better performance and lightning speed while browsing</p></li><li><p>Notes media has been enhanced</p></li><li><p>Notes threads are now efficiently displayed</p></li><li><p>Accounts switching enhancements</p></li><li><p>Private messaging optimization</p></li></ul></li><li><p>Zapstore <a href="https://github.com/zapstore/zapstore/releases/tag/0.1.4">v0.1.4</a></p><ul><li><p>Curated app sets</p></li><li><p>Load more releases (show all)</p></li><li><p>Better app cards and version/install state</p></li><li><p>Performance: Complete rework of internals, preloading, caching, background work</p></li></ul></li><li><p>Nostream <a href="https://github.com/cameri/nostream/releases/tag/v2.1.0">v2.1.0</a></p><ul><li><p>Add dark theme support for static html files</p></li></ul></li><li><p>strfry <a href="https://github.com/hoytech/strfry/releases/tag/1.0.2">v1.0.2</a></p><ul><li><p>New config param: relay.info.nips which allows you to override the NIPs that are claimed to be supported</p></li><li><p>New connectionTimeout parameter in router config</p></li></ul></li><li><p>Nostr-PHP</p><ul><li><p><a href="https://github.com/nostrver-se/nostr-php/releases/tag/2.0.0-alpha1">v2.0.0-alpha1</a></p><ul><li><p>Add <code>valtzu/guzzle-websocket-middleware</code> to execute async concurrent websocket requests with the Http/Guzzle client</p></li></ul></li><li><p><a href="https://github.com/nostrver-se/nostr-php/releases/tag/1.4.2">v1.4.2</a></p><ul><li><p>phpdoc + examples</p></li><li><p>Remove build dir phpdoc.nostr-php.dev from repo</p></li><li><p>Some improvements in the Filter class to handle multiple authors</p></li></ul></li></ul></li><li><p>BitBanana <a href="https://github.com/michaelWuensch/BitBanana/releases/tag/v0.8.7">v0.8.7</a></p><ul><li><p>More flexible fiat currency setup</p></li></ul></li><li><p>Fountain <a href="https://blog.fountain.fm/p/1-1-5">v1.1.5</a></p><ul><li><p>Simpler Library Architecture: makes offline playback more reliable and reduce system resource requirements, reduces mobile data and memory usage, and fixes long-standing playback issues</p></li><li><p>Pay BOLT-11 Invoices: withdraw funds by generating a lightning invoice using any app that supports lightning payments</p></li><li><p>Add artist Pages: From any Track or Album page you can now tap through to the Artist page to see all tracks</p></li></ul></li></ul><h3><strong>Boosts</strong></h3><ul><li><p>00:52:39 Thanks to everyone who streamed sats, and shoutout to our top boosters:</p><ul><li><p>[&#127942; TOP BOOSTER] @Ape Mithrandir (7,777 sats) &#8220;Listening to end if you count 30 minutes of sleep listening at the end &#128517;&#8221;</p></li><li><p>@tdub (5,000 sats) &#8220;Proof of Listrning (PoL): Here&#8217;s how to make a classic grilled cheese sandwich (&#8230;)&#8221;</p></li><li><p>@btconboard (1,111 sats) &#8220;More miniscript please. I am not Rob.&#8221;</p></li><li><p>@AVERAGE_GARY (1,000 sats) &#8220;SatsLink revival?!?! But I already used my preorder money for a second Q. &#128565;&#8205;&#128171;&#8221;</p></li><li><p>@VonPhoto (500 sats)</p></li><li><p>@BrightSats (121 sats) &#8220;Keep an eye on your wife flash attack vectors!&#8221;</p></li></ul></li></ul><h3><strong>00:54:14 Tech Tip of the Day</strong></h3><ul><li><p>00:54:16 <a href="https://dearrow.ajay.app/">DeArrow</a>: an open source browser extension for crowdsourcing better titles and thumbnails on YouTube [<a href="https://github.com/ajayyy/DeArrow">Github</a>] (Recommended by <a href="https://njump.me/nevent1qqsqqqzwwzewegpzwy2cqq3fh9zxnsmxz9elqrc9y9h2ppzfq5xwwwgpzemhxue69uhhyetvv9ujumn0wd68ytnzv9hxgq3q80cvv07tjdrrgpa0j7j7tmnyl2yr6yr7l8j4s3evf6u64th6gkws8llpgn">fiatjaf</a>)</p><ul><li><p>&#8220;The goal is to make titles accurate and reduce sensationalism. No more arrows, ridiculous faces, and no more clickbait.&#8221;</p></li></ul></li><li><p>00:54:26 <a href="https://eartho.io/">Eartho</a>: The open-source, privacy-focused alternative to Google sign-in [<a href="https://github.com/eartho-group/eartho">Github</a>]</p><ul><li><p>Eartho allows developers to integrate authentication without relying on third-party data collection services.</p></li></ul></li></ul><h3><strong>Bitcoin Optech Newsletter</strong></h3><ul><li><p>Highlights from recent Bitcoin Optech Newsletters</p><ul><li><p><a href="https://bitcoinops.org/en/newsletters/2024/10/25/">326</a></p><ul><li><p>Updates to the version 1.75 channel announcements proposal: Elle Mouton <a href="https://delvingbitcoin.org/t/updates-to-the-gossip-1-75-proposal-post-ln-summit-meeting/1202/">posted</a> to Delving Bitcoin a description of several proposed changes to the new channel announcements protocol that will support advertising simple taproot channels</p></li><li><p>Draft BIP for sending silent payments with PSBTs: Andrew Toth <a href="https://mailing-list.bitcoindevs.xyz/bitcoindev/cde77c84-b576-4d66-aa80-efaf4e50468fn@googlegroups.com/">posted</a> to the Bitcoin-Dev mailing list a draft BIP for allowing wallets and signing devices to use PSBTs to coordinate the creation of a silent payment.</p></li></ul></li><li><p><a href="https://bitcoinops.org/en/newsletters/2024/10/18/">325</a></p><ul><li><p>LN Summit 2024 notes: Olaoluwa Osuntokun <a href="https://delvingbitcoin.org/t/ln-summit-2024-notes-summary-commentary/1198">posted</a> to Delving Bitcoin a summary of his notes (with additional commentary) from a recent LN developer conference.</p></li></ul></li><li><p><a href="https://bitcoinops.org/en/newsletters/2024/10/11/">324</a></p><ul><li><p>Disclosure of vulnerabilities affecting Bitcoin Core versions before 25.0: Niklas G&#246;gge <a href="https://mailing-list.bitcoindevs.xyz/bitcoindev/2df30c0a-3911-46ed-b8fc-d87528c68465n@googlegroups.com/">posted</a> to the Bitcoin-Dev mailing list links to the announcements of three vulnerabilities affecting versions of Bitcoin Core that have been past their end of life since at least April 2024.</p></li><li><p>CVE-2024-38365 btcd consensus failure: as announced in last week&#8217;s newsletter, Antoine Poinsot and Niklas G&#246;gge <a href="https://delvingbitcoin.org/t/cve-2024-38365-public-disclosure-btcd-findanddelete-bug/1184">disclosed</a> a consensus failure vulnerability affecting the btcd full node.</p></li><li><p>Guide for wallets employing Bitcoin Core 28.0: As mentioned in last week&#8217;s newsletter, the newly released version 28.0 of Bitcoin Core contains several new features for the P2P network, including one parent one child (1P1C) package relay, topologically restricted until confirmation (TRUC) transaction relay, package RBF and sibling eviction, and a standard pay-to-anchor (P2A) output script type</p></li></ul></li></ul></li></ul><h3><strong>News &amp; Noteworthy</strong></h3><h4><strong>Bitcoin</strong></h4><ul><li><p><a href="https://bitcoinops.org/en/bitcoin-core-28-wallet-integration-guide/">Guide for Wallets Employing Bitcoin Core 28.0 Policies</a>: A guide to address Bitcoin Core v28.0 updates for wallet developers, detailing new P2P and mempool policies that aid in handling various transactions, including coinjoins, Lightning Network, and Ark transactions.</p></li><li><p>Bitcoin live dashboard <a href="https://timechainstats.com/">TimechainStats</a>, has added an Arcade game <a href="https://timechainstats.com/arcade">section</a> on its website</p></li><li><p>LNhance, a soft fork proposal for Bitcoin, has launched a new <a href="https://lnhance.org/">website</a></p></li></ul><h4><strong>Lightning + L2+</strong></h4><ul><li><p>Lightning Network + introduces Group Channel Opens [<a href="https://lightningnetwork.plus/posts/594">Announcement</a>]</p><ul><li><p>Group Channel Opens on LN+ enables up to 5 Lightning Network channels to open through a single bitcoin transaction, reducing costs and block space usage by approximately 52&#8211;62% depending on group size.</p></li></ul></li><li><p>@Roasbeef publishes his <a href="https://delvingbitcoin.org/t/ln-summit-2024-notes-summary-commentary/1198">Notes &amp; Summary</a> of the LN Summit 2024 in Tokyo, Japan</p></li><li><p>CashuBTC launches its new website: <a href="https://cashu.space/">cashu.space</a></p></li></ul><h4><strong>Business &amp; Finance</strong></h4><ul><li><p>00:58:48 River now offers 3.8% interest on cash with bitcoin payouts [<a href="https://x.com/River/status/1848718565005779205">Announcement</a>]</p><ul><li><p>Users can withdraw cash at any time, with funds FDIC-insured up to $250,000. The service has no hidden fees or minimum deposit requirements.</p></li></ul></li><li><p>Mt. Gox announced an extension to its repayment deadline for creditors to October 31, 2025 [<a href="https://www.coindesk.com/markets/2024/10/11/mt-gox-postpones-repayment-deadline-to-2025-allaying-concerns-of-bitcoin-sell-pressure/">CoinDesk</a>]</p><ul><li><p>This decision aims to give creditors additional time to navigate complex administrative requirements that have hindered the timely return of funds</p></li></ul></li><li><p>Dutch bitcoin-only exchange BL3P will shut down by December 20, 2024, citing new regulations, including MiCA, as a driver for the decision. [<a href="https://bl3p.eu/news/92/Important+Notice%3A+BL3P+shutting+down+by+December+20th+%E2%80%93+Transition+to+Bitonic">Press release</a>]</p><ul><li><p>Following closure, remaining funds and trading history will transition to users&#8217; Bitonic accounts, which will adopt some BL3P features.</p></li></ul></li><li><p>Bitkey announces new partner: users of the Bitkey App can now sell, buy or transfer bitcoin using MoonPay [<a href="https://x.com/BitkeyOfficial/status/1849165142497325206">Announcement</a>]</p></li><li><p>Decentralized exchange platform HoldHold discontinues support for most cryptocurrencies as payment methods, keeps supporting stablecoins and Bitcoin second-layer solutions [<a href="https://x.com/hodlhodl/status/1846885104120914297">Announcement</a>]</p></li></ul><h4><strong>Tradfi</strong></h4><ul><li><p>U.S. SEC approves NYSE options trading on spot Bitcoin ETFs [<a href="https://watcher.guru/news/sec-approves-nyse-options-trading-on-spot-bitcoin-etfs">Watcher Guru</a>]</p></li></ul><h4><strong>Art</strong></h4><ul><li><p>00:59:46 Bitcoin illustrator NoGood releases The art of NoGood &#8211; a self-published art book showcasing five years of bitcoin themed illustration [<a href="https://geyser.fund/project/nogoodartbook/">Geyser page</a>]</p></li></ul><h4><strong>Funding</strong></h4><ul><li><p>00:59:58 Bitcoin and Freedom Technologies Research firm 1a1z releases <a href="https://s3.amazonaws.com/1a1z.com/files/1A1z%20-%20Funding%20Bitcoin%20-%20Part%201.pdf">report</a> covering how Bitcoin Core development is funded</p><ul><li><p>Part 1 covers the organizations that raise and distribute funds to core devs</p></li></ul></li><li><p>1:00:06 OpenSats announces:</p><ul><li><p><a href="https://opensats.org/blog/8th-wave-of-bitcoin-grants">Eighth Wave of Bitcoin Grants</a>, the four projects of this funding wave are:</p><ul><li><p>Citadel-Tech</p></li><li><p>Lampo</p></li><li><p>Cashu Nutshell</p></li><li><p>PickhardtPayments Plugin</p></li></ul></li><li><p>Long-term support for <a href="https://opensats.org/blog/greenart7c3-receives-lts-grant">Greenart7c3</a>, creator and lead developer of Citrine and Amber, for his ongoing contributions to the nostr ecosystem.</p></li></ul></li><li><p>1:00:13 Spiral announces grant renewals to:</p><ul><li><p><a href="https://x.com/spiralbtc/status/1848391224547230035">Somsen Ruben</a>, Spiral grantee and long-time bitcoin wizard, co-author of Silent Payments</p></li><li><p><a href="https://x.com/spiralbtc/status/1849839498781200477">VLSProject (Validating Lightning Super)</a>, a library and reference implementation for a signer module to secure Lightning nodes.</p></li><li><p><a href="https://x.com/spiralbtc/status/1848741207502885101">@spacebear21</a>, one of the contributors behind the Payjoin Dev Kit project</p></li></ul></li><li><p>Bitcoin development fund Brink receives a $250,000 contribution to their funding efforts from The Draper Foundation [<a href="https://x.com/bitcoinbrink/status/1848395071353458701">Announcement</a>]</p></li><li><p>Donor-advised fund, UI Charitable (University Impact), makes first Bitcoin grant to support Bitcoin education [<a href="https://www.uicharitable.org/blog/ui-charitable-issues-first-ever-bitcoin-grant">Press release</a>]</p><ul><li><p>The scholarship fund, directed to Base58, a nonprofit promoting bitcoin engineering education, targets software engineers learning bitcoin fundamentals</p></li></ul></li><li><p>OKX announces a grant to the <a href="https://2140.dev/">2140 Foundation</a> [<a href="https://www.okx.com/learn/okx-bitcoin-developer-grant">Press release</a>]</p></li><li><p>Germany&#8217;s Sovereign Tech Fund boosts open-source development with $25 million across 60 open-source projects [<a href="https://www.sovereigntechfund.de/news/celebrating-two-years-of-empowering-public-digital-infrastructure">Blog release</a>]</p></li><li><p>Non-profit organization Btrust launches new <a href="https://www.btrust.tech/">website</a></p></li><li><p>Donations to the Tor Project will be matched, by Power Up Privacy, dollar-for-dollar up to $300,000 through the end of 2024 [<a href="https://blog.torproject.org/2024-fundraiser-donations-matched/">Announcement</a>]</p></li><li><p>Blockstream secures $210 million in convertible note financing, led by Fulgur Ventures, to advance Bitcoin integration into global finance. [<a href="https://www.bloomberg.com/news/articles/2024-10-15/blockstream-raises-210-million-through-fulgur-led-convertible-note-offering">Press release</a>]</p></li></ul><h4><strong>Mining</strong></h4><ul><li><p>Bitmain introduces the Antminer S21+ series, featuring two models: the S21+ Hyd and the S21+ [<a href="https://www.bitmain.com/news-detail/bitmain-launches-the-antminer-s21-series-358">Press release</a>]</p><ul><li><p>The S21+ Hyd model delivers a hashrate of 319 TH/s at 15 J/TH, while the S21+ provides 216 TH/s at 16.5 J/TH</p></li></ul></li></ul><h4><strong>Privacy</strong></h4><ul><li><p>A New York court dismisses YieldNodes&#8217; defamation suit against Chainalysis, citing Anti-SLAPP laws protecting public speech. [<a href="https://www.therage.co/chainalysis-defamation-dismissed/">The Rage</a>]</p><ul><li><p>Judge Lyle Frank states that statements made in Chainalysis&#8217; Reactor subscription service, are within public interest, akin to private Facebook group discussions.</p></li></ul></li><li><p>1:00:51 SimpleX publishes <a href="https://simplex.chat/blog/20241016-wired-attack-on-privacy.html">Wired&#8217;s Attack on Privacy</a>, a critical response to Wired&#8217;s article on neo-Nazis moving to SimpleX Chat following Telegram privacy policy changes</p></li><li><p>Encrypted chat app Session relocates to Switzerland following Australian police visit [<a href="https://archive.ph/RaWnW">404 Media</a>]</p><ul><li><p>After Australian Federal Police visited a Session employee regarding the app and a specific user, Session&#8217;s leadership decided to relocate to Switzerland under the newly formed Session Technology Foundation (STF) [<a href="https://getsession.org/blog/introducing-the-session-technology-foundation">Announcement</a>]</p></li></ul></li><li><p>A recent amendment to Norway&#8217;s Financial Contracts Act mandates businesses to accept cash if they offer other payment options at physical sales premises, if the amount is below ~$1800 [<a href="https://www.norges-bank.no/en/topics/notes-and-coins/the-right-to-pay-cash/">Announcement</a>]</p></li><li><p>VPN provider Mullvad introduces Shadowsocks obfuscation for WireGuard [<a href="https://mullvad.net/en/blog/introducing-shadowsocks-obfuscation-for-wireguard">Blog post</a>]</p><ul><li><p>Shadowsocks obfuscates data, making it harder for firewalls to block</p></li></ul></li><li><p>Transak, a cryptocurrency onramp API platform used by companies such as Binance US, Coinbase, Ledger and Bitpay, was hit by a data breach in October 2024, leaking the KYC information of ~57,000 users [<a href="https://www.coindesk.com/tech/2024/10/21/crypto-on-ramp-service-transak-targeted-in-data-breach/">CoinDesk</a>]</p><ul><li><p>The breached information includes names, dates of birth, ID documents, and selfie photos and videos of affected customers [<a href="https://transak.com/blog/transak-security-incident-oct-2024">Transak&#8217;s Security incident report</a>]</p></li></ul></li><li><p>Fidelity data breach exposes personal data of 77,000 customers, accessing social Security numbers, driver&#8217;s licenses, and names over a two-day period between August 17 and August 19, 2024 [<a href="https://www.cnet.com/personal-finance/fidelity-data-breach-exposed-the-personal-data-of-77000-customers/">CNET</a>]</p></li><li><p>The Internet Archive, a nonprofit organization that maintains digital archives of the internet, has suffered a data breach affecting 31 million accounts [<a href="https://www.zdnet.com/article/internet-archive-breach-compromises-31-million-accounts-what-you-need-to-know/">ZDNet</a>]</p><ul><li><p>DDoS attack: the incident was caused by an unauthorized third-party accessing a database backup from June 2020.</p></li></ul></li></ul><h4><strong>Protocol</strong></h4><ul><li><p>1:01:09 Libsecp256k1 #1479: Add module &#8220;musig&#8221; that implements MuSig2 multi-signatures (BIP 327) [<a href="https://github.com/bitcoin-core/secp256k1/pull/1479">Merged</a>]</p></li><li><p>Bitcoin Core #30955: implements two new methods to the Mining interface, compatible with Stratum V2 requirements [<a href="https://github.com/bitcoin/bitcoin/pull/30955">Merged</a>]</p></li><li><p>Rust Bitcoin #3450: Add version three variant to transaction version. Topologically restricted transactions are now considered standard as of Bitcoin 28.0. [<a href="https://github.com/rust-bitcoin/rust-bitcoin/pull/3450">Merged</a>]</p></li><li><p>Eclair #2927: Enforce recommended feerate for on-the-fly funding [<a href="https://github.com/ACINQ/eclair/pull/2927">Merged</a>]</p></li><li><p>Eclair #2922: Remove support for splicing without quiescence [<a href="https://github.com/ACINQ/eclair/pull/2922">Merged</a>]</p></li><li><p>NIP-60 and NIP-61 are the first Cashu NIPs to have been made into the Nostr specifications [<a href="https://github.com/nostr-protocol/nips/pull/1369">Merged</a>]</p><ul><li><p>NIP-60 describes portable Cashu wallets that live inside nostr relays</p></li><li><p>NIP-61 describes nutzaps, a new, instant way to zap users and events by posting ecash locked to their public key</p></li></ul></li></ul><h4><strong>Government &amp; Political</strong></h4><ul><li><p>Two senior researchers at the European Central Bank publish <a href="https://papers.ssrn.com/sol3/papers.cfm?abstract_id=4985877">The distributional consequences of Bitcoin</a>, a paper detailing the redistributive impact of a rising Bitcoin market</p><ul><li><p>The paper claims that while early adopters benefit, rising Bitcoin prices generate wealth at the expense of non-holders and late investors</p></li></ul></li><li><p>The Minneapolis Fed publishes a <a href="https://www.minneapolisfed.org/research/working-papers/unique-implementation-of-permanent-primary-deficits">research paper</a> and argues that Bitcoin disrupts a government&#8217;s ability to maintain a unique, permanent primary deficit by introducing multiple economic equilibria, solvable through Bitcoin prohibition or taxation.</p></li><li><p>Craig Wright has filed a &#163;911 billion lawsuit against Bitcoin Core developers in the UK High Court [<a href="https://www.forbes.com/sites/digital-assets/2024/10/18/craig-wright-who-is-not-satoshi-launches-bitcoin-core-legal-battle/">Forbes</a>]</p><ul><li><p>His argument centers on the claim that modifications by Bitcoin Core, such as SegWit and Taproot, deviate from Bitcoin&#8217;s original design, which he says was meant to be a decentralized cash system, not a store of value.</p></li></ul></li><li><p>FinCEN&#8217;s recent alert underscores that Hezbollah primarily relies on bulk cash transfers and smuggling for financing, rather than cryptocurrencies [<a href="https://www.fincen.gov/sites/default/files/shared/FinCEN-Alert-Hizballah-Alert-508C.pdf">FinCEN&#8217;s notice</a>]</p></li><li><p>The FBI arrested an individual for allegedly hacking the SEC&#8217;s account on X in January 2024. The suspect reportedly gained access to the account using a SIM swap attack, announced the launch of a fake Bitcoin ETF and profited from it. [<a href="https://www.forbes.com/sites/digital-assets/2024/10/18/fbi-arrests-hacker-behind-sec-x-account-fake-bitcoin-etf-announcement/">Forbes</a>]</p></li><li><p>Nigerian government drops charges against Binance Executive Tigran Gambaryan [<a href="https://www.reuters.com/world/africa/nigeria-drops-money-laundering-charges-against-binance-executive-2024-10-23/">Reuters</a>]</p></li><li><p>The Danish Minister of Taxation proposes a bill to tax unrealized capital gains on cryptocurrencies. [<a href="https://skm.dk/aktuelt/presse-nyheder/pressemeddelelser/ny-rapport-fra-skattelovraadet-kryptoaktiver-boer-fremover-lagerbeskattes">Announcement</a>]</p></li><li><p>Italy raises bitcoin capital gains tax from 26% to 42% in its 2025 budget [<a href="https://www.reuters.com/markets/europe/italy-stiffens-terms-digital-services-tax-2025-budget-2024-10-16/">Reuters</a>]</p></li></ul><h4><strong>Bitcoin (cont.)</strong></h4><ul><li><p>BitKey releases its new white paper <a href="https://assets.ctfassets.net/mtmp6hzjjvnd/6Qjcs8zgMiyffC0Uk8cx4V/6d1553946b50b132209518be8ff3026f/Unlocking_Mass_Market_Self_Custody_-10-24-.pdf">Unlocking Mass-Market Self-Custody: Secure and Private Smartphone Bitcoin Wallets</a></p><ul><li><p>&#8220;This paper details an innovative design for a smartphone-based Bitcoin wallet that aims to make self-custody both safe and user-friendly for the mass market.&#8221;</p></li></ul></li></ul><h4><strong>Events</strong></h4><ul><li><p>Three events have announced the dates of their 2025 editions:</p><ul><li><p><a href="https://6.tabconf.com/">TABConf 7</a></p><ul><li><p>October 13-16, 2025 in Atlanta, Georgia</p></li></ul></li><li><p><a href="https://bitcoinfilmfest.com/">Bitcoin FilmFest</a></p><ul><li><p>April 25-27, 2025 in Warsaw, Poland</p></li></ul></li><li><p><a href="https://www.bitcoinireland.eu/">Bitcoin Ireland</a></p><ul><li><p>May 24, 2025 in Dublin, Ireland</p></li></ul></li></ul></li></ul><h3><strong>Reads</strong></h3><ul><li><p>Here&#8217;s a list of our top recently published reads:</p><ul><li><p>The Mental Accounting Barrier to Micropayments by Nick Szabo [<a href="https://nakamotoinstitute.org/library/the-mental-accounting-barrier-to-micropayments/">Satoshi Nakamoto Institute</a>]</p></li><li><p>Digital Value by Andrew M. Bailey [<a href="https://andrewmbailey.com/DigitalValue.pdf">Philosophy &amp; Digitality</a>]</p></li><li><p>Slow Block Validation Attacks by Jameson Lopp [<a href="https://blog.lopp.net/slow-block-validation-attacks/">Blog post</a>]</p></li><li><p>How Bitcoin CoinJoins help facilitate pro-democracy protests by Bradley Rettler [<a href="https://www.forbes.com/sites/digital-assets/2024/10/09/how-bitcoin-coinjoins-help-facilitate-pro-democracy-protests/">Forbes</a>]</p></li><li><p>The Great Capitulation by Alexandre Stachtchenko [<a href="https://medium.com/@AlexStach/the-great-capitulation-a738a2969116">Blog post</a>]</p></li></ul></li></ul><h3><strong>Episode submission ideas</strong></h3><ul><li><p>We&#8217;re looking for ideas for interesting panel conversations. To send Bitcoin related questions, just go to <a href="https://bitcoin.review/">bitcoin.review</a> and follow the contact links at the bottom of the page.</p></li></ul><h3><strong>Get in touch with the pod</strong></h3><ul><li><p><a href="https://twitter.com/bitcoinreviewhq">Podcast Twitter</a></p></li><li><p><a href="https://twitter.com/nvk">NVK Twitter</a></p></li><li><p><a href="https://t.me/BitcoinReviewPod">Telegram</a></p></li><li><p><a href="mailto:producer@coinkite.com">Email</a></p></li><li><p>Nostr &amp; LN &#9889;nvk@nvk.org (not an email!)</p></li></ul>]]></content:encoded></item><item><title><![CDATA[BR085: Nostr Rising 08 - Nostr Funding ft. Lyn Alden, Max & Odell]]></title><description><![CDATA[I&#8217;m joined by guests Lyn Alden, Max & Odell to discuss nostr funding.]]></description><link>https://substack.bitcoin.review/p/br085-nostr-rising-08-nostr-funding</link><guid isPermaLink="false">https://substack.bitcoin.review/p/br085-nostr-rising-08-nostr-funding</guid><dc:creator><![CDATA[STACK TO THE FUTURE]]></dc:creator><pubDate>Wed, 30 Oct 2024 18:28:34 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/751acf49-7359-4845-868b-5e36b6814aa3_1920x1080.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I&#8217;m joined by guests <a href="https://primal.net/p/npub1a2cww4kn9wqte4ry70vyfwqyqvpswksna27rtxd8vty6c74era8sdcw83a">Lyn Alden</a>, <a href="https://primal.net/p/npub18lzls4f6h46n43revlzvg6x06z8geww7uudhncfdttdtypduqnfsagugm3">Max</a> &amp; <a href="https://njump.me/npub1qny3tkh0acurzla8x3zy4nhrjz5zd8l9sy9jys09umwng00manysew95gx">Odell</a> to discuss nostr funding.</p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://bitcoin.review/podcast/episode-56/&quot;,&quot;text&quot;:&quot;Listen on your favorite podcast app&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://bitcoin.review/podcast/episode-56/"><span>Listen on your favorite podcast app</span></a></p><div><hr></div><h3><strong>Chapters</strong></h3><ul><li><p>(00:00:00) Introduction to Nostr funding concepts</p></li><li><p>(00:01:04) Importance of decentralized funding in tech</p></li><li><p>(00:02:07) Discussion on Nostr&#8217;s scalability and funding potential</p></li><li><p>(00:06:17) Analysis of community-driven funding models</p></li><li><p>(00:12:01) Benefits of open-source funding approaches</p></li><li><p>(00:18:02) Comparison of Nostr&#8217;s funding capabilities with traditional platforms</p></li><li><p>(00:19:00) Potential challenges for funding in decentralized systems</p></li><li><p>(00:28:32) Exploration of funding solutions using Bitcoin</p></li><li><p>(00:33:17) Incentives for developers in the Nostr ecosystem</p></li><li><p>(00:41:34) Role of privacy in funding models</p></li><li><p>(00:46:22) Future of funding mechanisms in Nostr</p></li><li><p>(00:49:01) Community engagement and its impact on funding success</p></li><li><p>(00:53:33) Scalability of Nostr vs. traditional funding platforms</p></li><li><p>(00:54:14) Announcement of a bounty related to Nostr funding</p></li><li><p>(00:54:26) Optimism about the future of funding in the Nostr community</p></li></ul><h3><strong>Episode submission ideas</strong></h3><ul><li><p>We&#8217;re looking for ideas for interesting panel conversations. To send Bitcoin related questions, just go to <a href="https://bitcoin.review/">bitcoin.review</a> and follow the contact links at the bottom of the page.</p></li></ul><h3><strong>Get in touch with the pod</strong></h3><ul><li><p><a href="https://twitter.com/bitcoinreviewhq">Podcast Twitter</a></p></li><li><p><a href="https://twitter.com/nvk">NVK Twitter</a></p></li><li><p><a href="https://t.me/BitcoinReviewPod">Telegram</a></p></li><li><p><a href="mailto:producer@coinkite.com">Email</a></p></li><li><p>Nostr &amp; LN &#9889;nvk@nvk.org (not an email!)</p></li></ul>]]></content:encoded></item><item><title><![CDATA[BR084: Nostr Rising 07 - Long Form Content ft. DK & Miljan]]></title><description><![CDATA[I&#8217;m joined by guests DK & Miljan to discuss long form content.]]></description><link>https://substack.bitcoin.review/p/br084-nostr-rising-07-long-form-content</link><guid isPermaLink="false">https://substack.bitcoin.review/p/br084-nostr-rising-07-long-form-content</guid><dc:creator><![CDATA[STACK TO THE FUTURE]]></dc:creator><pubDate>Mon, 28 Oct 2024 18:51:50 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/06c8fe2b-b865-4d85-b842-7e6518dee109_1920x1080.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I&#8217;m joined by guests <a href="https://primal.net/p/npub1kuy0wwf0tzzqvgfv8zpw0vaupkds3430jhapwrgfjyn7ecnhpe0qj9kdj8">DK</a> &amp; <a href="https://primal.net/p/npub16c0nh3dnadzqpm76uctf5hqhe2lny344zsmpm6feee9p5rdxaa9q586nvr">Miljan</a> to discuss long form content.</p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://bitcoin.review/podcast/episode-56/&quot;,&quot;text&quot;:&quot;Listen on your favorite podcast app&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://bitcoin.review/podcast/episode-56/"><span>Listen on your favorite podcast app</span></a></p><div><hr></div><h3><strong>Chapters</strong></h3><ul><li><p>(00:00:00) Introduction to long form content on Nostr</p></li><li><p>(00:03:15) Challenges of content distribution on Nostr</p></li><li><p>(00:06:42) Nostr as a decentralized platform for creators</p></li><li><p>(00:11:20) The role of relays in content storage and competition</p></li><li><p>(00:15:47) Building user-centric tools for long-form content</p></li><li><p>(00:19:33) Balancing short-form and long-form content on Nostr</p></li><li><p>(00:22:58) Algorithmic feeds and user-controlled algorithms</p></li><li><p>(00:28:40) Primal&#8217;s focus on algorithm marketplace development</p></li><li><p>(00:34:15) Human-curated algorithms and user-selected feeds</p></li><li><p>(00:39:48) Ethical advertising and user choice in ads</p></li><li><p>(00:43:22) Importance of competition in relays, clients, and algorithms</p></li><li><p>(00:46:58) Creating customizable algorithms for users</p></li><li><p>(00:48:09) Potential for ethical, non-intrusive advertising</p></li><li><p>(00:50:26) Nostr as a global town square for nuanced discourse</p></li><li><p>(00:51:34) Learning from torrents: the importance of better UX</p></li><li><p>(00:52:24) Closing thoughts on Nostr&#8217;s future and appeal to creators</p></li></ul><h3><strong>Episode submission ideas</strong></h3><ul><li><p>We&#8217;re looking for ideas for interesting panel conversations. To send Bitcoin related questions, just go to <a href="https://bitcoin.review/">bitcoin.review</a> and follow the contact links at the bottom of the page.</p></li></ul><h3><strong>Get in touch with the pod</strong></h3><ul><li><p><a href="https://twitter.com/bitcoinreviewhq">Podcast Twitter</a></p></li><li><p><a href="https://twitter.com/nvk">NVK Twitter</a></p></li><li><p><a href="https://t.me/BitcoinReviewPod">Telegram</a></p></li><li><p><a href="mailto:producer@coinkite.com">Email</a></p></li><li><p>Nostr &amp; LN &#9889;nvk@nvk.org (not an email!)</p></li></ul>]]></content:encoded></item><item><title><![CDATA[BR083: Nostr Rising 06 - Zap the Planet and Nostr Money ft. Calle, Pablo & Miljan]]></title><description><![CDATA[I&#8217;m joined by guests Calle, Pablo & Miljan to discuss zaps and nostr money.]]></description><link>https://substack.bitcoin.review/p/br083-nostr-rising-06-zap-the-planet</link><guid isPermaLink="false">https://substack.bitcoin.review/p/br083-nostr-rising-06-zap-the-planet</guid><dc:creator><![CDATA[STACK TO THE FUTURE]]></dc:creator><pubDate>Fri, 25 Oct 2024 13:08:18 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/04653790-65fe-407f-8bdb-5415cb7194ba_1920x1080.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I&#8217;m joined by guests <a href="https://primal.net/p/npub12rv5lskctqxxs2c8rf2zlzc7xx3qpvzs3w4etgemauy9thegr43sf485vg">Calle</a>, <a href="https://primal.net/p/npub1l2vyh47mk2p0qlsku7hg0vn29faehy9hy34ygaclpn66ukqp3afqutajft">Pablo</a> &amp; <a href="https://primal.net/p/npub16c0nh3dnadzqpm76uctf5hqhe2lny344zsmpm6feee9p5rdxaa9q586nvr">Miljan</a> to discuss zaps and nostr money.</p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://bitcoin.review/podcast/episode-56/&quot;,&quot;text&quot;:&quot;Listen on your favorite podcast app&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://bitcoin.review/podcast/episode-56/"><span>Listen on your favorite podcast app</span></a></p><div><hr></div><h3><strong>Chapters</strong></h3><ul><li><p>(00:00:00) Introduction</p></li><li><p>(00:05:12) Building a permissionless public square on Nostr</p></li><li><p>(00:12:25) Challenges in decentralized social media and privacy</p></li><li><p>(00:18:43) Cashu protocol integration with Nostr</p></li><li><p>(00:22:50) Role of ecash in relays and wallets</p></li><li><p>(00:28:16) Nostr as an open social graph for applications</p></li><li><p>(00:31:42) Innovation in digital payments and Zaps on Nostr</p></li><li><p>(00:35:14) Open-source culture and project monetization</p></li><li><p>(00:39:23) Bitcoin integration in social media platforms</p></li><li><p>(00:42:38) Scaling challenges and user adoption</p></li><li><p>(00:47:06) Nostr&#8217;s impact on new market designs</p></li><li><p>(00:48:25) Future of Zaps in expanding Bitcoin user base</p></li><li><p>(00:49:24) Social feedback and micro-transactions</p></li><li><p>(00:50:20) Infinite innovation potential with Nostr and Zaps</p></li><li><p>(00:51:57) Nostr&#8217;s role in enhancing app social features</p></li><li><p>(00:54:29) Regulatory challenges and JavaScript as a platform</p></li><li><p>(00:55:12) Closing thoughts</p></li></ul><h3><strong>Episode submission ideas</strong></h3><ul><li><p>We&#8217;re looking for ideas for interesting panel conversations. To send Bitcoin related questions, just go to <a href="https://bitcoin.review/">bitcoin.review</a> and follow the contact links at the bottom of the page.</p></li></ul><h3><strong>Get in touch with the pod</strong></h3><ul><li><p><a href="https://twitter.com/bitcoinreviewhq">Podcast Twitter</a></p></li><li><p><a href="https://twitter.com/nvk">NVK Twitter</a></p></li><li><p><a href="https://t.me/BitcoinReviewPod">Telegram</a></p></li><li><p><a href="mailto:producer@coinkite.com">Email</a></p></li><li><p>Nostr &amp; LN &#9889;nvk@nvk.org (not an email!)</p></li></ul>]]></content:encoded></item><item><title><![CDATA[BR082: Nostr Rising 05 - Podcasting 2.0 ft. Kieran, Odell, Hodlbod & Oscar Merry]]></title><description><![CDATA[I&#8217;m joined by guests Kieran, Odell, Hodlbod & Oscar Merry to discuss podcasting 2.0.]]></description><link>https://substack.bitcoin.review/p/br082-nostr-rising-05-podcasting</link><guid isPermaLink="false">https://substack.bitcoin.review/p/br082-nostr-rising-05-podcasting</guid><dc:creator><![CDATA[STACK TO THE FUTURE]]></dc:creator><pubDate>Wed, 23 Oct 2024 17:55:53 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/b3b0b5a1-23a7-4bbf-9126-f83fc6607c66_1920x1080.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I&#8217;m joined by guests <a href="https://njump.me/npub1v0lxxxxutpvrelsksy8cdhgfux9l6a42hsj2qzquu2zk7vc9qnkszrqj49">Kieran</a>, <a href="https://njump.me/npub1qny3tkh0acurzla8x3zy4nhrjz5zd8l9sy9jys09umwng00manysew95gx">Odell</a>, <a href="https://primal.net/p/npub1jlrs53pkdfjnts29kveljul2sm0actt6n8dxrrzqcersttvcuv3qdjynqn">Hodlbod</a> &amp; <a href="https://primal.net/p/npub1unmftuzmkpdjxyj4en8r63cm34uuvjn9hnxqz3nz6fls7l5jzzfqtvd0j2">Oscar Merry</a> to discuss podcasting 2.0.</p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://bitcoin.review/podcast/episode-56/&quot;,&quot;text&quot;:&quot;Listen on your favorite podcast app&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://bitcoin.review/podcast/episode-56/"><span>Listen on your favorite podcast app</span></a></p><div><hr></div><h3><strong>Chapters</strong></h3><ul><li><p>(00:00:00) &#8211; Introduction and overview of the discussion on Nostr and podcasting.</p></li><li><p>(00:01:10) &#8211; Importance of Nostr in decentralization and censorship resistance.</p></li><li><p>(00:10:30) &#8211; Integrating Bitcoin and Lightning Payments with Nostr.</p></li><li><p>(00:19:12) &#8211; Value-for-value model and podcast monetization using Nostr.</p></li><li><p>(00:26:50) &#8211; Challenges of onboarding new users and improving user experience on Nostr.</p></li><li><p>(00:35:15) &#8211; The future of podcasting with Nostr and potential for listener engagement.</p></li><li><p>(00:41:20) &#8211; The potential for creating decentralized, censorship-resistant content.</p></li><li><p>(00:48:30) &#8211; Vision for integrating games with Nostr and Lightning Payments.</p></li><li><p>(00:59:18) &#8211; Opportunities in gaming and Nostr&#8217;s role in gaming&#8217;s future.</p></li><li><p>(01:00:19) &#8211; The importance of owning your social graph on Nostr.</p></li><li><p>(01:01:10) &#8211; Discussing podcasting analytics and user platforms.</p></li><li><p>(01:02:27) &#8211; The need for more apps and users in the Nostr ecosystem.</p></li><li><p>(01:03:25) &#8211; Audience breakdown by platform, including Spotify, Fountain, and Overcast.</p></li><li><p>(01:04:06) &#8211; Issues with Spotify&#8217;s closed analytics and data control.</p></li><li><p>(01:05:17) &#8211; Simplifying Nostr onboarding and improving the user experience.</p></li><li><p>(01:06:41) &#8211; Challenges of niche adoption and the importance of positive feedback loops.</p></li><li><p>(01:07:42) &#8211; Nostr&#8217;s future growth driven by censorship on other platforms.</p></li><li><p>(01:08:09) &#8211; Optimism for Nostr&#8217;s long-term success despite short-term challenges.</p></li></ul><h3><strong>Episode submission ideas</strong></h3><ul><li><p>We&#8217;re looking for ideas for interesting panel conversations. To send Bitcoin related questions, just go to <a href="https://bitcoin.review/">bitcoin.review</a> and follow the contact links at the bottom of the page.</p></li></ul><h3><strong>Get in touch with the pod</strong></h3><ul><li><p><a href="https://twitter.com/bitcoinreviewhq">Podcast Twitter</a></p></li><li><p><a href="https://twitter.com/nvk">NVK Twitter</a></p></li><li><p><a href="https://t.me/BitcoinReviewPod">Telegram</a></p></li><li><p><a href="mailto:producer@coinkite.com">Email</a></p></li><li><p>Nostr &amp; LN &#9889;nvk@nvk.org (not an email!)</p></li></ul>]]></content:encoded></item><item><title><![CDATA[BR081: Nostr Rising 04 - DMs and Groupchats ft. Fiatjaf, Hodlbod & Jeff G]]></title><description><![CDATA[I&#8217;m joined by guests Fiatjaf, Hodlbod & Jeff G to discuss DMs and groupchats.]]></description><link>https://substack.bitcoin.review/p/br081-nostr-rising-04-dms-and-groupchats</link><guid isPermaLink="false">https://substack.bitcoin.review/p/br081-nostr-rising-04-dms-and-groupchats</guid><dc:creator><![CDATA[STACK TO THE FUTURE]]></dc:creator><pubDate>Mon, 21 Oct 2024 13:29:57 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/3384ffdb-0f9d-4969-be3e-20d6c8fd3900_1920x1080.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I&#8217;m joined by guests <a href="https://njump.me/npub180cvv07tjdrrgpa0j7j7tmnyl2yr6yr7l8j4s3evf6u64th6gkwsyjh6w6">Fiatjaf</a>, <a href="https://primal.net/p/npub1jlrs53pkdfjnts29kveljul2sm0actt6n8dxrrzqcersttvcuv3qdjynqn">Hodlbod</a> &amp; <a href="https://primal.net/p/npub1zuuajd7u3sx8xu92yav9jwxpr839cs0kc3q6t56vd5u9q033xmhsk6c2uc">Jeff G</a> to discuss DMs and groupchats.</p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://bitcoin.review/podcast/episode-56/&quot;,&quot;text&quot;:&quot;Listen on your favorite podcast app&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://bitcoin.review/podcast/episode-56/"><span>Listen on your favorite podcast app</span></a></p><div><hr></div><h3><strong>Chapters</strong></h3><ul><li><p>(00:00) - Introduction to the discussion</p></li><li><p>(02:32) - Overview of MLS Messaging Layer Security and its role in group chats.</p></li><li><p>(10:03) - Addressing spam and impersonation in group communications.</p></li><li><p>(14:16) - Managing group keys and group membership.</p></li><li><p>(21:10) - Security concerns and potential vulnerabilities.</p></li><li><p>(26:58) - Relays and group management.</p></li><li><p>(30:50) - Importance of secure client implementations.</p></li><li><p>(35:25) - Handling bad actors in group chats.</p></li><li><p>(43:15) - Integration of payments in group chat dynamics pay-to-post model.</p></li><li><p>(50:25) - Exploring broadcast model for private groups.</p></li><li><p>(55:16) - Proof of concept for a secure group chat client.</p></li><li><p>(59:27) - Conclusion and final thoughts</p></li></ul><h3><strong>Episode submission ideas</strong></h3><ul><li><p>We&#8217;re looking for ideas for interesting panel conversations. To send Bitcoin related questions, just go to <a href="https://bitcoin.review/">bitcoin.review</a> and follow the contact links at the bottom of the page.</p></li></ul><h3><strong>Get in touch with the pod</strong></h3><ul><li><p><a href="https://twitter.com/bitcoinreviewhq">Podcast Twitter</a></p></li><li><p><a href="https://twitter.com/nvk">NVK Twitter</a></p></li><li><p><a href="https://t.me/BitcoinReviewPod">Telegram</a></p></li><li><p><a href="mailto:producer@coinkite.com">Email</a></p></li><li><p>Nostr &amp; LN &#9889;nvk@nvk.org (not an email!)</p></li></ul>]]></content:encoded></item><item><title><![CDATA[BR080: Nostr Rising 03 - Relays & Scaling ft. Fiatjaf, Mike Dilger & Pablo]]></title><description><![CDATA[I&#8217;m joined by guests Fiatjaf, Mike Dilger & Pablo to discuss relays and scaling nostr.]]></description><link>https://substack.bitcoin.review/p/br080-nostr-rising-03-relays-and</link><guid isPermaLink="false">https://substack.bitcoin.review/p/br080-nostr-rising-03-relays-and</guid><dc:creator><![CDATA[STACK TO THE FUTURE]]></dc:creator><pubDate>Fri, 18 Oct 2024 13:27:27 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/c25f41c6-c7dd-4882-9cdf-d8c3775a93bd_1920x1080.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I&#8217;m joined by guests <a href="https://njump.me/npub180cvv07tjdrrgpa0j7j7tmnyl2yr6yr7l8j4s3evf6u64th6gkwsyjh6w6">Fiatjaf</a>, <a href="https://njump.me/npub1acg6thl5psv62405rljzkj8spesceyfz2c32udakc2ak0dmvfeyse9p35c">Mike Dilger</a> &amp; <a href="https://primal.net/p/npub1l2vyh47mk2p0qlsku7hg0vn29faehy9hy34ygaclpn66ukqp3afqutajft">Pablo</a> to discuss relays and scaling nostr.</p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://bitcoin.review/podcast/episode-56/&quot;,&quot;text&quot;:&quot;Listen on your favorite podcast app&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://bitcoin.review/podcast/episode-56/"><span>Listen on your favorite podcast app</span></a></p><div><hr></div><h3><strong>Chapters</strong></h3><ul><li><p>(00:00) &#8211; Introduction to Nostr protocol and event signing</p></li><li><p>(02:15) &#8211; Relay management and costs in Nostr ecosystem</p></li><li><p>(05:30) &#8211; Scaling concerns and misconceptions about relay overload</p></li><li><p>(09:11) &#8211; Importance of public key identity management</p></li><li><p>(12:18) &#8211; Challenges in moderation and decentralized governance</p></li><li><p>(15:40) &#8211; Defining the roles of clients and relays</p></li><li><p>(20:19) &#8211; Lightning integration for payments in Nostr</p></li><li><p>(25:00) &#8211; Need for better developer tools for relay management</p></li><li><p>(29:45) &#8211; Cross-platform interoperability between Nostr and Mastodon</p></li><li><p>(35:20) &#8211; Censorship on Mastodon and the Fediverse</p></li><li><p>(40:05) &#8211; Scalability and reliability improvements during user influxes</p></li><li><p>(44:10) &#8211; The idea of creating more experimental and niche relays</p></li><li><p>(47:25) &#8211; Vision for integrating specialized relay functionality into clients</p></li><li><p>(49:31) &#8211; Concept of Yahoo Pipes for Nostr relays data aggregation tools</p></li><li><p>(50:09) &#8211; DVMs and the evolution of decentralized systems</p></li><li><p>(51:00) &#8211; Closing remarks</p></li></ul><h3><strong>Episode submission ideas</strong></h3><ul><li><p>We&#8217;re looking for ideas for interesting panel conversations. To send Bitcoin related questions, just go to <a href="https://bitcoin.review/">bitcoin.review</a> and follow the contact links at the bottom of the page.</p></li></ul><h3><strong>Get in touch with the pod</strong></h3><ul><li><p><a href="https://twitter.com/bitcoinreviewhq">Podcast Twitter</a></p></li><li><p><a href="https://twitter.com/nvk">NVK Twitter</a></p></li><li><p><a href="https://t.me/BitcoinReviewPod">Telegram</a></p></li><li><p><a href="mailto:producer@coinkite.com">Email</a></p></li><li><p>Nostr &amp; LN &#9889;nvk@nvk.org (not an email!)</p></li></ul>]]></content:encoded></item><item><title><![CDATA[BR079: Nostr Rising 02 - Communities ft. Rabble, Alex Gleason, Hodlbod & Pablo]]></title><description><![CDATA[I&#8217;m joined by guests Rabble, Hodlbod, Alex Gleason & Pablo to discuss nostr communities.]]></description><link>https://substack.bitcoin.review/p/br079-nostr-rising-02-communities</link><guid isPermaLink="false">https://substack.bitcoin.review/p/br079-nostr-rising-02-communities</guid><dc:creator><![CDATA[STACK TO THE FUTURE]]></dc:creator><pubDate>Wed, 16 Oct 2024 14:31:43 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/38757f9e-0666-4922-bee1-e3d9c01bba0d_1920x1080.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I&#8217;m joined by guests <a href="https://primal.net/p/npub1wmr34t36fy03m8hvgl96zl3znndyzyaqhwmwdtshwmtkg03fetaqhjg240">Rabble</a>, <a href="https://primal.net/p/npub1jlrs53pkdfjnts29kveljul2sm0actt6n8dxrrzqcersttvcuv3qdjynqn">Hodlbod</a>, <a href="https://primal.net/p/npub1q3sle0kvfsehgsuexttt3ugjd8xdklxfwwkh559wxckmzddywnws6cd26p">Alex Gleason</a> &amp; <a href="https://primal.net/p/npub1l2vyh47mk2p0qlsku7hg0vn29faehy9hy34ygaclpn66ukqp3afqutajft">Pablo</a> to discuss nostr communities.</p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://bitcoin.review/podcast/episode-56/&quot;,&quot;text&quot;:&quot;Listen on your favorite podcast app&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://bitcoin.review/podcast/episode-56/"><span>Listen on your favorite podcast app</span></a></p><div><hr></div><h3><strong>Discussion Topics</strong></h3><ul><li><p>00:00:00 &#8211; Introduction to Nostr and its evolving landscape</p></li><li><p>00:01:35 &#8211; Comparison between TCP/IP and Nostr as flexible protocols</p></li><li><p>00:05:45 &#8211; Nostr&#8217;s decentralized development and innovation without permission</p></li><li><p>00:12:20 &#8211; User experience challenges in decentralized systems</p></li><li><p>00:18:10 &#8211; Importance of experimentation and building tools for Nostr</p></li><li><p>00:21:55 &#8211; Differences between digital and physical communities</p></li><li><p>00:25:10 &#8211; Discussion on the long tail of communities in Nostr</p></li><li><p>00:29:00 &#8211; How Nostr helps niche groups and the growth of communities</p></li><li><p>00:32:50 &#8211; Balancing decentralization and user experience</p></li><li><p>00:38:10 &#8211; Ham radio community&#8217;s adoption of Nostr</p></li><li><p>00:42:55 &#8211; Importance of building discoverable and easy-to-join communities</p></li><li><p>00:47:30 &#8211; Nostr as an open, super-app platform similar to early Facebook</p></li><li><p>00:52:00 &#8211; Final thoughts on Nostr&#8217;s role in fostering decentralized communities</p></li><li><p>00:57:55 &#8211; Nostr&#8217;s network effect and social graph integration</p></li><li><p>01:00:04 &#8211; Future potential and excitement about Nostr communities expanding</p></li><li><p>01:01:28 &#8211; Nostr&#8217;s organic growth and fostering more community engagement</p></li><li><p>01:02:07 &#8211; Closing remarks and thanks to the guests</p></li></ul><h3><strong>Episode submission ideas</strong></h3><ul><li><p>We&#8217;re looking for ideas for interesting panel conversations. To send Bitcoin related questions, just go to <a href="https://bitcoin.review/">bitcoin.review</a> and follow the contact links at the bottom of the page.</p></li></ul><h3><strong>Get in touch with the pod</strong></h3><ul><li><p><a href="https://twitter.com/bitcoinreviewhq">Podcast Twitter</a></p></li><li><p><a href="https://twitter.com/nvk">NVK Twitter</a></p></li><li><p><a href="https://t.me/BitcoinReviewPod">Telegram</a></p></li><li><p><a href="mailto:producer@coinkite.com">Email</a></p></li><li><p>Nostr &amp; LN &#9889;nvk@nvk.org (not an email!)</p></li></ul>]]></content:encoded></item><item><title><![CDATA[BR078: Nostr Rising 01 - Permissionless Algos ft. JB55, Hodlbod & Miljan]]></title><description><![CDATA[I&#8217;m joined by guests JB55, Hodlbod & Miljan to discuss Permissionless Algos in the first episode of Nostr Rising.]]></description><link>https://substack.bitcoin.review/p/br078-nostr-rising-01-permissionless</link><guid isPermaLink="false">https://substack.bitcoin.review/p/br078-nostr-rising-01-permissionless</guid><dc:creator><![CDATA[STACK TO THE FUTURE]]></dc:creator><pubDate>Mon, 14 Oct 2024 20:30:38 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/008013b2-9821-471c-aa6b-24a0dd8ed2f6_1920x1080.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I&#8217;m joined by guests <a href="https://primal.net/p/npub1xtscya34g58tk0z605fvr788k263gsu6cy9x0mhnm87echrgufzsevkk5s">JB55</a>, <a href="https://primal.net/p/npub1jlrs53pkdfjnts29kveljul2sm0actt6n8dxrrzqcersttvcuv3qdjynqn">Hodlbod</a> &amp; <a href="https://primal.net/p/npub16c0nh3dnadzqpm76uctf5hqhe2lny344zsmpm6feee9p5rdxaa9q586nvr">Miljan</a> to discuss Permissionless Algos in the first episode of Nostr Rising.</p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://bitcoin.review/podcast/episode-56/&quot;,&quot;text&quot;:&quot;Listen on your favorite podcast app&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://bitcoin.review/podcast/episode-56/"><span>Listen on your favorite podcast app</span></a></p><div><hr></div><h3><strong>Discussion Topics</strong></h3><ul><li><p>00:00:00 &#8211; Introduction to decentralized algorithms and Nostr&#8217;s open network</p></li><li><p>00:01:01 &#8211; Users&#8217; control over algorithms and content feeds</p></li><li><p>00:03:01 &#8211; Challenges of building permissionless systems without tracking users</p></li><li><p>00:05:01 &#8211; Feed marketplace concept and its impact on content discovery</p></li><li><p>00:08:01 &#8211; Importance of user feedback in developing decentralized platforms</p></li><li><p>00:12:01 &#8211; AI agents and bots assisting with content curation</p></li><li><p>00:15:01 &#8211; The value of human-created content versus bot-generated content</p></li><li><p>00:17:31 &#8211; AI&#8217;s role in building decentralized apps on Nostr</p></li><li><p>00:20:01 &#8211; Future of algorithms and personalized content on decentralized networks</p></li><li><p>00:24:01 &#8211; Curation and community-driven feeds as an alternative to centralized platforms</p></li><li><p>00:28:01 &#8211; Nostr&#8217;s potential to disrupt big tech and centralized institutions</p></li><li><p>00:30:01 &#8211; Open network and emergent properties of user-driven content</p></li><li><p>00:33:01 &#8211; Role of lists and curated social clusters in enhancing user experience</p></li><li><p>00:36:01 &#8211; Encouragement for users and developers to participate in Nostr</p></li><li><p>00:40:01 &#8211; Final thoughts: the power of decentralized networks and AI collaboration</p></li><li><p>00:42:31 &#8211; Closing remarks and a call to action for Nostr&#8217;s growth and adoption</p></li></ul><h3><strong>Episode submission ideas</strong></h3><ul><li><p>We&#8217;re looking for ideas for interesting panel conversations. To send Bitcoin related questions, just go to <a href="https://bitcoin.review/">bitcoin.review</a> and follow the contact links at the bottom of the page.</p></li></ul><h3><strong>Get in touch with the pod</strong></h3><ul><li><p><a href="https://twitter.com/bitcoinreviewhq">Podcast Twitter</a></p></li><li><p><a href="https://twitter.com/nvk">NVK Twitter</a></p></li><li><p><a href="https://t.me/BitcoinReviewPod">Telegram</a></p></li><li><p><a href="mailto:producer@coinkite.com">Email</a></p></li><li><p>Nostr &amp; LN &#9889;nvk@nvk.org (not an email!)</p></li></ul>]]></content:encoded></item></channel></rss>