<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[bitcoin++'s Insider Edition]]></title><description><![CDATA[bitcoin++ is an international bitcoin dev conference series. "Insider Edition" is our newsroom covering what's happening in and across the bitcoin++ universe and beyond.]]></description><link>https://insider.btcpp.dev</link><image><url>https://substackcdn.com/image/fetch/$s_!Y_ng!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30eeeceb-d343-4c5d-93d2-4da0d7357725_650x650.png</url><title>bitcoin++&apos;s Insider Edition</title><link>https://insider.btcpp.dev</link></image><generator>Substack</generator><lastBuildDate>Sat, 19 Sep 2026 07:54:47 GMT</lastBuildDate><atom:link href="https://insider.btcpp.dev/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[btcplusplus LLC]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[hello@btcpp.dev]]></webMaster><itunes:owner><itunes:email><![CDATA[hello@btcpp.dev]]></itunes:email><itunes:name><![CDATA[~nifty~]]></itunes:name></itunes:owner><itunes:author><![CDATA[~nifty~]]></itunes:author><googleplay:owner><![CDATA[hello@btcpp.dev]]></googleplay:owner><googleplay:email><![CDATA[hello@btcpp.dev]]></googleplay:email><googleplay:author><![CDATA[~nifty~]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[The GUI doesn't speak RPC - This Week in Bitcoin Core #58]]></title><description><![CDATA[This week the GUI doesn't speak RPC...]]></description><link>https://insider.btcpp.dev/p/the-gui-doesnt-speak-rpc-this-week</link><guid isPermaLink="false">https://insider.btcpp.dev/p/the-gui-doesnt-speak-rpc-this-week</guid><dc:creator><![CDATA[kevkevin]]></dc:creator><pubDate>Fri, 18 Sep 2026 15:20:19 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!MJw8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cee73e5-1dd4-4081-a559-6f40592a5154_1456x816.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Hello &#128075; folks, I&#8217;m Kevkevin. I&#8217;m an open-source developer and reporter for Insider Edition. <br><br>Last week I reviewed several pull requests from the Bitcoin Core repo. This week there were multiple PR&#8217;s that dealt with a constraint that keeps showing up in wallet work: Bitcoin Core GUI does not speak RPC. <br><br>Descriptor import and <code>addhdkey</code> lived in the RPC layer, which is fine if you&#8217;re the <code>bitcoin-cli</code>, and a dead end if you&#8217;re the GUI trying to do multisig. This week both of those grew a real wallet interface.</p><p>Also: last week branch-off missed the calendar. This week, sedited tagged <code>v32.0rc1</code>. The <a href="https://github.com/bitcoin-core/bitcoin-devwiki/wiki/32.0-Release-Candidate-Testing-Guide">testing guide</a> is up. I do not see binaries on bitcoincore.org yet, and Thursday&#8217;s meeting was ten minutes of working groups plus a nudge to still review things for v32.<br></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!MJw8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cee73e5-1dd4-4081-a559-6f40592a5154_1456x816.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!MJw8!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cee73e5-1dd4-4081-a559-6f40592a5154_1456x816.png 424w, https://substackcdn.com/image/fetch/$s_!MJw8!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cee73e5-1dd4-4081-a559-6f40592a5154_1456x816.png 848w, https://substackcdn.com/image/fetch/$s_!MJw8!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cee73e5-1dd4-4081-a559-6f40592a5154_1456x816.png 1272w, https://substackcdn.com/image/fetch/$s_!MJw8!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cee73e5-1dd4-4081-a559-6f40592a5154_1456x816.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!MJw8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cee73e5-1dd4-4081-a559-6f40592a5154_1456x816.png" width="1456" height="816" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1cee73e5-1dd4-4081-a559-6f40592a5154_1456x816.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:816,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!MJw8!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cee73e5-1dd4-4081-a559-6f40592a5154_1456x816.png 424w, https://substackcdn.com/image/fetch/$s_!MJw8!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cee73e5-1dd4-4081-a559-6f40592a5154_1456x816.png 848w, https://substackcdn.com/image/fetch/$s_!MJw8!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cee73e5-1dd4-4081-a559-6f40592a5154_1456x816.png 1272w, https://substackcdn.com/image/fetch/$s_!MJw8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cee73e5-1dd4-4081-a559-6f40592a5154_1456x816.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h4><strong>Merged PR&#8217;s</strong></h4><h5><strong>Every week, several changes are officially added to Bitcoin Core. This week, </strong>multiple <strong>changes were merged. Here are some I found interesting this week.</strong></h5><ul><li><p><strong><a href="https://github.com/bitcoin/bitcoin/pull/34861">wallet: Add importdescriptors interface</a></strong> by <strong><a href="https://github.com/polespinasa">polespinasa</a></strong></p><p>This week, Pol Espinasa had his change merged, which tackled the fact that importing descriptors was RPC-only and the <strong>Bi</strong>tcoin Core GUI does not use that interface, so it could not offer descriptor import. This is what you need for more complex wallet setups like multisig. <br><br>The PR moves the core logic out of <code>ProcessDescriptorImport</code> and into <code>CWallet::ImportDescriptor</code>, then adds <code>interfaces::Wallet::importDescriptors()</code> so the GUI can call it directly. Results come back as <code>wallet::ImportDescriptorResult</code> with a <code>FailureReason</code> enum, and the RPC layer maps those back to JSON-RPC error codes. Pol already has a GUI menu on his fork to try it, and said he&#8217;ll open that against the GUI repo now that this is in.</p></li><li><p><strong><a href="https://github.com/bitcoin/bitcoin/pull/35436">wallet: Add addHDkey interface</a></strong> by <strong><a href="https://github.com/pseudoramdom">pseudoramdom</a></strong><br>Same story, different RPC. <code>addhdkey</code> existed. The GUI still could not call it. Ram (pseudoramdom) moved the wallet logic into <code>CWallet::AddHDKey()</code>, introduced a generic <code>WalletError</code> with a machine-readable code plus a translated message, and added <code>interfaces::Wallet::addHDKey()</code> which generates a new HD key and returns the master xpub. The RPC still does argument parsing, and now also exposes the master fingerprint in hex. Pair this with <code>derivehdkey</code> and the GUI can produce a shareable xpub during multisig setup without going through RPC.</p></li></ul><h5><strong>There are always changes being updated and reviewed in real-time. Here are some notable PR&#8217;s that are still up and looking for reviews.</strong></h5><ul><li><p><strong><a href="https://github.com/bitcoin/bitcoin/pull/36284">wallet: don't double discard output groups with avoidpartialspends</a></strong> by <strong><a href="https://github.com/fjahr">fjahr</a></strong></p><p>fjahr called this out in Thursday&#8217;s meeting as maybe still interesting for v32. Clean merge, not a draft. If you have review time this week, start here.</p><blockquote><p>With `-avoidpartialspends` or `avoid_reuse`, `GroupOutputs` puts every positive-value output into both the mixed and the positive-only map and runs `push_output_groups` on each, so a group rejected by the eligibility filters lands in `discarded_groups` twice. `AutomaticCoinSelection` then subtracts it twice and could fail with an insufficient funds error even when there would be enough confirmed coins to cover the payment.</p><p>Not a problem in a default wallet but it can happen with `sendtoaddress` from an `avoid_reuse` wallet, or with `-avoidpartialspends=1`.</p></blockquote></li></ul><div><hr></div><h4><strong>IRC meeting notes</strong></h4><h5><strong>Every week on Thursday, there is an IRC meeting. Here are some short notes from that meeting.</strong></h5><pre><code>&#120307;&#120311;&#120302;&#120309;&#120319;: There are no pre-proposed meeting topics this week. Any last minute ones to add?
&#120307;&#120311;&#120302;&#120309;&#120319;: Ok, let's do the WGs

--- Topic 1 ---
&#120307;&#120311;&#120302;&#120309;&#120319;: #topic QA WG Update (brunoerg)
&#120303;&#120319;&#120322;&#120315;&#120316;&#120306;&#120319;&#120308;: no update this week, will have a big one next week.

--- Topic 2 ---
&#120307;&#120311;&#120302;&#120309;&#120319;: #topic QML GUI WG Update (johnny9dev)
&#120311;&#120316;&#120309;&#120315;&#120315;&#120326;&#120821;&#120305;&#120306;&#120323;: Opened issue #36289 to track the QML staging branch
&#120311;&#120316;&#120309;&#120315;&#120315;&#120326;&#120821;&#120305;&#120306;&#120323;: Will use this issue to share my plan for merging gui-qml and help with organizing and prioritizing current issues that remain
&#120311;&#120316;&#120309;&#120315;&#120315;&#120326;&#120821;&#120305;&#120306;&#120323;: We got another new contributor to the project this week, Andrea, and she has already fix a high priority issue for us
&#120311;&#120316;&#120309;&#120315;&#120315;&#120326;&#120821;&#120305;&#120306;&#120323;: thats all for this week

--- Topic 3 ---
&#120307;&#120311;&#120302;&#120309;&#120319;: #topic Benchmarking WG Update (l0rinc, andrewtoth)
&#120302;&#120315;&#120305;&#120319;&#120306;&#120324;&#120321;&#120316;&#120321;&#120309;_: no update
&#120307;&#120311;&#120302;&#120309;&#120319;: That's it for the WGs afaict, anything else to discuss?
&#120307;&#120311;&#120302;&#120309;&#120319;: Anything of note from release testing?
&#120307;&#120311;&#120302;&#120309;&#120319;: There is still some stuff to review here: https://github.com/bitcoin/bitcoin/milestone/84
&#120307;&#120311;&#120302;&#120309;&#120319;: And maybe #36284 is interesting to still make into v32</code></pre><p>Read here for the <a href="https://achow101.com/ircmeetings/2026/bitcoin-core-dev.2026-09-17_16_00.html">full meeting</a></p><div><hr></div><h4><strong>Releases</strong></h4><ul><li><p><code>v32.0rc1</code> was tagged 2026-09-14 by sedited. Signed git tag exists.</p></li></ul><div><hr></div><blockquote><p>Thank you for reading. Be sure to tune in again next week for your updates on Bitcoin Core!</p></blockquote><p><em>If there are any comments, suggestions, or errors, do not hesitate to reach out or comment</em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://insider.btcpp.dev/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">bitcoin++'s Insider Edition is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Nayoma | Node Fingerprinting - BTC++ Inisder Interviews]]></title><description><![CDATA[Naiyoma tells us how fingerprinting attacks can link a Bitcoin node&#8217;s clearnet and Tor identities, weakening privacy.]]></description><link>https://insider.btcpp.dev/p/nayoma-node-fingerprinting-btc-inisder</link><guid isPermaLink="false">https://insider.btcpp.dev/p/nayoma-node-fingerprinting-btc-inisder</guid><dc:creator><![CDATA[Matthew]]></dc:creator><pubDate>Tue, 15 Sep 2026 18:00:52 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/215855036/24e1a897fb245e7a3d60d12726c8484c.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p><span>Naiyoma tells us how fingerprinting attacks can link a Bitcoin node&#8217;s clearnet and Tor identities, weakening  privacy.<br><br>Read the thread by @danielabrozzoni on her research with Naiyoma </span><a href="https://delvingbitcoin.org/t/fingerprinting-nodes-via-addr-requests/1786"><span>here</span></a><span>.</span></p>]]></content:encoded></item><item><title><![CDATA[Naiyoma - BTC++ Insider Interviews]]></title><description><![CDATA[Naiyoma tells us about Private Broadcast, which she reviewed in Bitcoin Core.]]></description><link>https://insider.btcpp.dev/p/naiyoma-btc-insider-interviews</link><guid isPermaLink="false">https://insider.btcpp.dev/p/naiyoma-btc-insider-interviews</guid><dc:creator><![CDATA[Matthew]]></dc:creator><pubDate>Mon, 14 Sep 2026 16:22:14 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/215687966/eda4e119109cf49d8e08853ff5cee156.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>Naiyoma tells us about Private Broadcast,  which she reviewed in Bitcoin Core. It sends transactions over short-lived Tor or I2P connections to hide the origin IP.</p><p>She talks about the Private Transactions June bugfix, and encourages you to run your own Tor node.</p>]]></content:encoded></item><item><title><![CDATA[New Bindings — Last Week in Bitcoin (Sep 07 - 13)]]></title><description><![CDATA[Hi Insiders.]]></description><link>https://insider.btcpp.dev/p/new-bindings-last-week-in-bitcoin</link><guid isPermaLink="false">https://insider.btcpp.dev/p/new-bindings-last-week-in-bitcoin</guid><dc:creator><![CDATA[Tuma (I WILL NEVER DM YOU)]]></dc:creator><pubDate>Mon, 14 Sep 2026 14:01:24 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!0-ek!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96dddae3-091a-47fb-8d36-4a3ac2b5c627_1600x900.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Hi Insiders. This is Tuma, open-source reporter from the Insider Edition.</em></p><p><em>In this week&#8217;s update we feature the latest release, v3.1.0, of the bindings library for BDK, exposing the latest development to several programming languages.</em></p><p><em>We also cover the publication of BIP332, defining a new, opt-in P2P message, a a new BIP that has been assigned a number, BIP394, which defines a new output script descriptor, called </em><code>rawtr()</code><em> .</em></p><p><em>We finally discuss some other news from the Bitcoin developer ecosystem. In particular, we talk about a bug in the legacy gateway module in Fedimint, a blog post from Second on how to board an Ark using Payjoin, and a research from BlueWallet CTO on the security of non-custodial wallets on the App Store.</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0-ek!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96dddae3-091a-47fb-8d36-4a3ac2b5c627_1600x900.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0-ek!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96dddae3-091a-47fb-8d36-4a3ac2b5c627_1600x900.jpeg 424w, https://substackcdn.com/image/fetch/$s_!0-ek!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96dddae3-091a-47fb-8d36-4a3ac2b5c627_1600x900.jpeg 848w, https://substackcdn.com/image/fetch/$s_!0-ek!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96dddae3-091a-47fb-8d36-4a3ac2b5c627_1600x900.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!0-ek!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96dddae3-091a-47fb-8d36-4a3ac2b5c627_1600x900.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0-ek!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96dddae3-091a-47fb-8d36-4a3ac2b5c627_1600x900.jpeg" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/96dddae3-091a-47fb-8d36-4a3ac2b5c627_1600x900.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:347184,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://insider.btcpp.dev/i/215631859?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96dddae3-091a-47fb-8d36-4a3ac2b5c627_1600x900.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!0-ek!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96dddae3-091a-47fb-8d36-4a3ac2b5c627_1600x900.jpeg 424w, https://substackcdn.com/image/fetch/$s_!0-ek!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96dddae3-091a-47fb-8d36-4a3ac2b5c627_1600x900.jpeg 848w, https://substackcdn.com/image/fetch/$s_!0-ek!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96dddae3-091a-47fb-8d36-4a3ac2b5c627_1600x900.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!0-ek!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96dddae3-091a-47fb-8d36-4a3ac2b5c627_1600x900.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h1><strong>Highlights from the Bitcoin developer ecosystem</strong></h1><p><em>I spent 10+ hours in open-source developer calls in the Bitcoin ecosystem last week. Here is what caught my eye</em>:</p><ul><li><p>The BDK team released the latest version of their bindings, <a href="https://github.com/bitcoindevkit/bdk-ffi/releases/tag/v3.1.0">v3.1.0</a>, bringing the whole library to several programming languages</p><ul><li><p>During their weekly call, on Tuesday 8th, BDK contributors discussed the release of <code>bdk-ffi</code> v3.1.0, the library that allows to expose the Rust codebase to several other programming languages, such as Dart, Swift, Kotlin, Python, and react-native.</p></li><li><p>This release upgrades UniFFI &#8212; the bindings generator &#8212; to <a href="https://github.com/mozilla/uniffi-rs/releases/tag/v0.31.2">v0.31.2</a> and brings the bindings up-to-date with the <a href="https://github.com/bitcoindevkit/bdk_wallet/releases/tag/v3.1.0">latest release of the BDK Wallet libraries</a>, exposing several new methods, such as those to choose the coin selection algorithm, wallet signers, APIs to load wallet parameters, and more.</p></li><li><p><code>bdk-dart</code> &#8212; the library exposing BDK to Dart &#8212; has been upgraded to use the latests <code>bdk-ffi</code> library, and a new release candidate, <a href="https://github.com/bitcoindevkit/bdk-dart/releases/tag/v1.0.0-rc.4">v1.0.0-rc.4</a> has been published. This update brings the Dart bindings closer to a first stable release.</p></li></ul></li></ul><div><hr></div><h1>A BIPs Update</h1><p><em>In the last days there was some movement in the <a href="https://github.com/bitcoin/bips">BIP repository</a>. Specifically, one new BIP has been published and one has been assigned a number by BIP maintainer <a href="https://github.com/murchandamus">Murchandamus</a>.</em></p><h2>Published BIPs</h2><p><em>A list of recently published BIPs</em></p><h3>BIP332: Stale Tip Relay</h3><p><strong>Authors</strong>: <a href="https://github.com/ajtowns">Anthony Towns</a>, <a href="https://github.com/w0xlt">w0xlt</a>, <a href="https://github.com/pseudoramdom">Ram</a></p><p><strong>Published On</strong>: Sep 9th, 2026</p><p><strong>Layer</strong>: Peer Services</p><p><a href="https://github.com/bitcoin/bips/blob/master/bip-0332.md">BIP 332</a> defines a new, opt-in P2P message called <code>staletip</code> whose goal is to announce recent stale chain tips to peers. The message contains the block height at which a stale branch diverges (the fork point), a vector containing the block headers belonging to the stale branch, and a flag signaling willingness to serve that block data. This may be useful for monitoring the network health, since increases in the stale block rate may expose validation or relay bottlenecks, network partitions, or <a href="https://bitcoinops.org/en/topics/selfish-mining/">selfish mining</a> behavior.</p><h2>Numbered BIPs</h2><p><em>A list of BIPs that recently got assigned a number</em></p><h3><strong>BIP394: rawtr() Output Script Descriptors</strong></h3><p><strong>Authors</strong>: <a href="https://github.com/jeanpablojp">jeanpablojp</a></p><p><strong>Assigned On</strong>: Sep 9th, 2026</p><p><strong>Layer</strong>: Applications</p><p><a href="https://github.com/bitcoin/bips/pull/2251">PR2251</a> introduces BIP394, which defines a new output script descriptor, called <code>rawtr()</code> . The descriptor &#8212; that has been available in Bitcoin Core since <a href="https://github.com/bitcoin/bitcoin/releases/tag/v24.0.1">v24.0</a> but was never specified in a BIP &#8212; can be used to express a P2TR output directly by its output key. The key is used as the taproot output key without applying the <a href="https://github.com/bitcoin/bips/blob/master/bip-0341.mediawiki">BIP341</a> tweak. This is useful, for example, when the internal structure isn&#8217;t known, or the script tree hasn&#8217;t been revealed by the owner.</p><div><hr></div><h1>Other News from the Bitcoin World</h1><ul><li><p><strong>Fedimint Bug</strong>: The Fedimint team <a href="https://x.com/fedimint/status/2098803741298200618">announced</a> that they had found a bug in the legacy gateway module, the one responsible for integrating the federated ecash ecosystem with the Lightning Network.</p><ul><li><p>The team released <a href="https://github.com/fedimint/fedimint/releases/tag/v0.12.1">v0.12.1</a> to fix the issue and contacted all the reachable gateway operators to invite them to update their modules as soon as possible.</p></li><li><p>The issue only affects legacy gateway modules, those running the so-called LNv1, while those that had previously upgraded to LNv2 or those running an LDK backend can run safely. The team also point out that users&#8217; funds, federations, and ecash are not affected by the bug.</p></li></ul></li><li><p><strong>Boarding an Ark with Payjoin</strong>: Second, the company behind Bark, <a href="https://x.com/secondhq/status/2098054721210843167">posted</a> a thread explaining how to board and Ark using Payjoin, a feature that has been available for some time now. The same flow is also available to enter a Cashu mint. Second also provided a <a href="https://second.tech/blog/payjoin-boards-board-psbt/">full write-up</a> on the topic.</p></li><li><p><strong>App Store Research</strong>: BlueWallet CTO @overtorment <a href="https://kek.lol/research/appstore-wallets/">pubished</a> a report on the security of non-custodial wallets on the App Store.</p><ul><li><p>The research focused on finding traces of weak entropy and private key exfiltration by decompiling and analyzing code from different wallets.</p></li><li><p>@overtorment was able to decompile 494 wallets, 45 of which raised red flags. He identified 23 apps with critical vulnerabilites and 22 with high-severity one. The complete list can be found at the end of the report.</p></li></ul></li><li><p><strong>Bitcoin++ Insider Edition &#8212; News Hour</strong>: On Friday, the Insider team held its <a href="https://x.com/btcinsider__/status/2098455841565442528">first News Hour</a>, a livestream where we discussed the most important news of the week, interesting articles, and the latest insides from the developer ecosystem. This will become a weekly appointment, so don&#8217;t forget to tune in on Friday @ 5p UTC!</p></li></ul><div><hr></div><h1>More from BTC++ Insider Edition</h1><h3>Articles</h3><ul><li><p><strong><a href="https://insider.btcpp.dev/p/egge-wants-you-to-pay-with-bitcoin">Egge Wants You to Pay with Bitcoin</a></strong></p></li><li><p><strong><a href="https://insider.btcpp.dev/p/how-cache-optimization-not-broken">How cache optimization, not broken crypto, caused inflation on Liquid</a></strong></p></li><li><p><strong><a href="https://insider.btcpp.dev/p/temudandelion-this-week-in-bitcoin">temudandelion - This Week in Bitcoin Core #57</a></strong></p></li></ul><h3>Videos</h3><ul><li><p><strong><a href="https://insider.btcpp.dev/p/connor-aherne-btc-insider-interviews">Connor Aherne - BTC++ Insider Interviews</a></strong></p></li><li><p><strong><a href="https://insider.btcpp.dev/p/antoine-poinsot-btc-insider-interviews">Antoine Poinsot - BTC++ Insider Interviews</a></strong></p></li></ul><div><hr></div><p><em>Looking for an opportunity to join up with some bitcoin devs in person? Join us in <a href="https://btcpp.dev/berlin26?code=TUMA20">Berlin</a> this October 1- 3 to talk about payments in Bitcoin!</em></p>]]></content:encoded></item><item><title><![CDATA[How cache optimization, not broken crypto, caused inflation on Liquid]]></title><description><![CDATA[Steven Roose, the CEO of Second and an ex-Liquid team engineer at Blockstream, deep dives on what, exactly, happened that lead to the Liquid Network hack of almost 4,000 on Sept 6, 2026.]]></description><link>https://insider.btcpp.dev/p/how-cache-optimization-not-broken</link><guid isPermaLink="false">https://insider.btcpp.dev/p/how-cache-optimization-not-broken</guid><pubDate>Sat, 12 Sep 2026 13:55:39 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!yqTv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bd5e3ef-ddab-4017-b2a3-f289806cc0f2_2400x1042.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em><a href="https://btcpp.dev/whois/stevenroose">Steven Roose</a>, the CEO of <a href="https://second.tech/">Second </a>and an ex-Liquid team engineer at Blockstream, deep dives on what, exactly, happened that lead to the Liquid Network hack of almost 4,000 on Sept 6, 2026.</em><span><br><br>I worked for Blockstream as part of the Liquid team for about five years. I am quite certain that I speak for all my former colleagues that an inflation bug as we witnessed over the last few days was our greatest fear whenever we had to touch the complex section of code that implements Liquid&#8217;s Confidential Transactions.</span></p><p><span>This is a walk through what actually happened, at the level of the code. Which bugs existed, how they were exploited, and how an attacker managed to run away with 4000 Bitcoin.</span></p><h3><span>What Liquid is, and how the peg works</span></h3><p><span>Liquid is a federated sidechain to bitcoin. Instead of proof-of-work, eleven signatures are required to produce a valid block. These signatures are placed by the Liquid functionaries: around fifteen independent businesses running a specialized server, or HSM. The functionaries take turns to propose a block roughly every minute. As long as five functionaries remain honest, no invalid blocks can be produced.</span></p><p><span>The principal asset that circulates on Liquid is L-BTC, and it is meant to be backed one-to-one by bitcoin held in reserve. The reserve is held in a wallet managed by the same federation of 15 functionaries. Converting Bitcoin to L-BTC is a </span><em><span>peg-in</span></em><span>: you send Bitcoin to a federation-controlled address on the bitcoin mainchain, and, after enough confirmations, the same amount of L-BTC is credited to you in Liquid. Getting out is a </span><em><span>peg-out</span></em><span>: you destroy L-BTC on Liquid, and the federation releases the corresponding Bitcoin to you from reserve on the mainchain. Similarly, as long as five functionaries are honest, no one can take more money out of the system than they deserve. Or that was the idea.</span></p><h3><span>Confidential transactions, confidential assets, and range proofs</span></h3><p><span>On bitcoin, every output amount is public. On Liquid, amounts can be hidden. This feature is called </span><em><span>Confidential Transactions</span></em><span>. In a confidential transaction, the output amount field doesn&#8217;t hold a plain number. Instead, it carries a Pedersen commitment, or a curve point that binds the amount behind a blinding factor.  The Pedersen commitment hides the amount while still supporting arithmetic. A verifier who cannot see any individual amount can still add up the input commitments, add up the output commitments, and check that the two sides balance. That is the </span><em><span>balance proof</span></em><span>, and it ensures transactions always have balanced inputs and outputs. In other words, the balance proof confirms that no new Bitcoin were created in the confidential transaction.</span></p><p><em><span>Confidential Assets</span></em><span> extends the same idea to which asset an output holds, not just the amount. L-BTC, Tether USDt, and every other Liquid asset look alike in the blockchain; a per-output surjection proof ties each output&#8217;s asset back to the inputs.</span></p><p><span>Balance alone is not enough, and this is the crux of the whole incident. Pedersen commitments live in a finite group, so arithmetic wraps around in modulo. A commitment can encode a value so large it behaves like a negative number. If I am allowed to do that, I can build a transaction that balances on paper while minting money:</span></p><div class="callout-block" data-callout="true"><p><span>Imagine a transaction with an input of 1 L-BTC and two outputs: one of 100 L-BTC and one of &#8220;minus 99&#8221; L-BTC. The sums on both sides match up: </span><code>1 == 100-99</code><span>. You can discard the -99 L-BTC output but keep the 100 L-BTC one.</span></p></div><p><span>The thing that forbids this is the </span><em><span>range proof</span></em><span>. Every confidential output must carry a zero-knowledge proof that proves the hidden amounts lie in a sane, positive range and not in the wrap-around zone. Range proofs are what make hidden inflation impossible.</span></p><h3><span>The cache</span></h3><p><span>Range proofs are big &#8212; a few kilobytes each &#8212; and expensive to verify. Liquid nodes see the same proof more than once: once when a transaction arrives in the mempool, again when it appears in a block. Re-running the elliptic-curve verification every time is wasteful, so Elements remembers successful verifications in a cache. The idea is simple and, in bitcoin, entirely standard: verify a proof once, remember that this exact proof passed, and skip the math if you see it again.</span></p><p><span>A cache needs a key. For a signature or a proof, the key is a hash of everything the verification depended on. Get everything into the key and the cache is safe: two verifications collide only when they truly are the same check. Leave something out and you have a problem, because now two different checks can share a key and the cache will happily answer &#8220;already valid&#8221; for a check it never ran.</span></p><p><span>That single sentence is the entire vulnerability that got Liquid hacked. The details is which fields went missing, and when.</span></p><h3><span>The 2018 cache key change</span></h3><p><span>The original cache implementation was using an existing function that Bitcoin Core uses to cache transaction signatures. Due to an upstream change to that function, in commit </span><a href="https://github.com/ElementsProject/elements/commit/957216523881768d9bcd6c5092dd5d50495dcd4e"><span>9572165</span></a><span>, a custom cache key function is introduced for range proofs specifically. Here&#8217;s the relevant changes:</span></p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;cpp&quot;,&quot;nodeId&quot;:&quot;8a9f1a0d-78f8-4b4a-824f-311161c4e53a&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-cpp">+    void ComputeEntry(uint256&amp; entry, const std::vector&lt;unsigned char&gt;&amp; proof, const std::vector&lt;unsigned char&gt;&amp; commitment)

+    {

+        CSHA256().Write(nonce.begin(), nonce.size()).Write(proof.data(), proof.size()).Write(commitment.data(), commitment.size()).Finalize(entry.begin());

+    }</code></pre></div><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;cpp&quot;,&quot;nodeId&quot;:&quot;b0a85fc7-890c-4c4b-bbce-c977b5a739ed&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-cpp">-    rangeProofCache.ComputeEntry(entry, uint256(), vchRangeProof, pubkey, vchAssetCommitment, scriptPubKey);

+    rangeProofCache.ComputeEntry(entry, vchRangeProof, vchValueCommitment);</code></pre></div><p><span>The new cache key is </span><code>SHA256(nonce || rangeproof || value-commitment)</code><span>. The asset commitment and the </span><code>scriptPubKey</code><span>, which were previously there, are gone. The verification function still received them and still verified against them, but the cache no longer remembered that it had. Two range proof checks with the same proof and the same value commitment, but a different asset or a different output script, now would hash to the same cache entry.</span></p><p><span>This design violates the requirement that all relevant fields for validation must be part of the cache key, so it&#8217;s definitely a bug. Let&#8217;s look at how it could be exploited.</span></p><p><span>If the value commitment was a Pedersen commitment to the value alone, it would require breaking the elliptic curve logarithm problem to create an identical commitment to a different value. That means that it is as hard as forging a bitcoin signature. However, because of how Confidential Transactions and Confidential Assets work, the value commitment that is used here, is actually made up of two parts: it contains a commitment to the value, but it&#8217;s also mixing in a asset-specific factor so that you can&#8217;t blend different assets.</span></p><p><span>The commitment contains an additional generator </span><code>H</code><span> that is calculated from the asset. Now, if we could invent a different asset with generator </span><code>-H</code><span>, we can create an identical value commitment for the same amount, but negative.</span></p><p><span>Choosing our own asset generator would also require breaking our crypto, but we don&#8217;t really have to. The validity of the asset generators is checked in what is called the asset &#8220;surjection proof&#8221;. But, this check only happens </span><em><span>after</span></em><span> the range proofs are checked. This means that I can just claim to have an output for asset generator </span><code>-H</code><span> and a value of 1 BTC. The rangeproof will pass and be stored in the cache. Afterwards, the surjection proof will fail and the transaction will be invalid.</span></p><p><span>But any node that actually validated this transaction, will have made an entry in its rangeproof cache and will now accept a rangeproof for -1 BTC under asset generator </span><code>H</code><span> which allows the same transaction to add an extra output for 1 BTC without having sufficient input value.</span></p><p><span>What this means in practice is that an attacker could cause inflation if he could make enough functionary nodes first validate (and reject!) an invalid transaction and then propose a block that has an inflationary transaction in it.</span></p><p><span>The Liquid network has some protections against this sort of behavior: users cannot send transactions directly to the functionaries. All transactions pass through &#8220;bridge nodes&#8221; that then relay them to the functionaries. While this protects the functionaries somewhat against outside attackers, it still means that anyone with privileged access to the inner network could have exploited this bug and confirmed an inflationary transaction.</span></p><p><span>Also, if for example a malicious functionary would perform this attack, the entire rest of the network would reject this block because they hadn&#8217;t seen the invalid tx preceding it. So while an inflationary exploit was possible, it was pretty hard to execute, would be noticed way faster and could only be performed by Liquid&#8217;s inner circle.</span></p><h3><span>Why variable sized fields should always have a prefix</span></h3><p><span>On 1 September 2026, five days before the attack, commit </span><a href="https://github.com/ElementsProject/elements/commit/c26d719c29a40da280a825b25657e9c3d8bc7d99"><span>c26d719</span></a><span> fixes the 2018 bug by putting the missing fields like the asset commitment back into the cache key:</span></p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;cpp&quot;,&quot;nodeId&quot;:&quot;3b4aaa03-ed54-4166-a4a4-5bb7b5135e30&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-cpp">-void SignatureCache::ComputeEntryRangeProof(uint256&amp; entry, const std::vector&lt;unsigned char&gt;&amp; proof, const std::vector&lt;unsigned char&gt;&amp; commitment) const {

+void SignatureCache::ComputeEntryRangeProof(uint256&amp; entry, const std::vector&lt;unsigned char&gt;&amp; proof, const std::vector&lt;unsigned char&gt;&amp; commitment, const std::vector&lt;unsigned char&gt;&amp; asset_commitment, const CScript&amp; scriptPubKey) const {

     CSHA256 hasher = m_salted_hasher_range_proof;

-    hasher.Write(proof.data(), proof.size()).Write(commitment.data(), commitment.size()).Finalize(entry.begin());

+    hasher.Write(proof.data(), proof.size()).Write(commitment.data(), commitment.size()).Write(asset_commitment.data(), asset_commitment.size()).Write(scriptPubKey.data(), scriptPubKey.size()).Finalize(entry.begin());

 }</code></pre></div><p><span>Read that </span><code>Write</code><span> chain carefully. The key is now:</span></p><p><code>SHA256( nonce || proof || commitment || asset_commitment || scriptPubKey )</code></p><p><span>All four fields are present, which looks like exactly what you want. I wrote above that in the old key, only the range proof field was of variable length, and that&#8217;s why a collision could only happen for exactly the same range proof and value commitment. In this new cache key, two fields are of variable length and they are hashed without having a length prefix.</span></p><p><span>When you glue variable-length fields together without length prefixes, the boundaries between them stop being meaningful. Only the total byte string matters. If I can make the proof longer by the same number of bytes that I make the script shorter, and arrange the bytes in between them to line up, I can produce an identical concatenation for a completely different </span><code>(proof, commitment, asset, script)</code><span> tuple.</span></p><p><span>This implementation lets you create two </span><strong><span>identical</span></strong><span> cache keys for a </span><em><span>different</span></em><span> amount, asset, and script. If you can get a Liquid node to first parse a valid transaction and then an invalid one with a junk proof and a forged amount, but that is carefully crafted so that the cache key for this transaction matches exactly with the cache key of the first one, it won&#8217;t even validate the range proof because you convinced it that it has already done that before.</span></p><p><span>This is a commonly known pitfall in cryptography. Hashing structured data by raw concatenation is unsafe precisely because distinct structures can share a byte encoding. The 2016 signature cache in bitcoin gets away with concatenation because its fields are all fixed length. The moment two variable-length fields sit next to each other, concatenation is a trap.</span></p><p><span>I remember from my time at Blockstream that whenever we would introduce any new consensus-critical serialization, we would ask Russell O&#8217;Connor to review it. Russell has the reputation as the expert in spotting this kind of byte-shifting vulnerabilities.</span></p><p><span>Here is the field layout, from a diagram </span><a href="https://x.com/mononautical"><span>mononautical</span></a><span>, an engineer at Mempool.space, made </span>while going through the same rabbit hole. The cache key is <code>proof | amount | asset | script</code>. Feed it a genuine &#8220;primer&#8221; and a crafted &#8220;exploit&#8221; and the two produce the same 4,301 bytes with the field boundaries in different places:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!yqTv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bd5e3ef-ddab-4017-b2a3-f289806cc0f2_2400x1042.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!yqTv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bd5e3ef-ddab-4017-b2a3-f289806cc0f2_2400x1042.jpeg 424w, https://substackcdn.com/image/fetch/$s_!yqTv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bd5e3ef-ddab-4017-b2a3-f289806cc0f2_2400x1042.jpeg 848w, https://substackcdn.com/image/fetch/$s_!yqTv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bd5e3ef-ddab-4017-b2a3-f289806cc0f2_2400x1042.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!yqTv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bd5e3ef-ddab-4017-b2a3-f289806cc0f2_2400x1042.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!yqTv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bd5e3ef-ddab-4017-b2a3-f289806cc0f2_2400x1042.jpeg" width="1456" height="632" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1bd5e3ef-ddab-4017-b2a3-f289806cc0f2_2400x1042.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:632,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Image&quot;,&quot;title&quot;:&quot;Image&quot;,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Image" title="Image" srcset="https://substackcdn.com/image/fetch/$s_!yqTv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bd5e3ef-ddab-4017-b2a3-f289806cc0f2_2400x1042.jpeg 424w, https://substackcdn.com/image/fetch/$s_!yqTv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bd5e3ef-ddab-4017-b2a3-f289806cc0f2_2400x1042.jpeg 848w, https://substackcdn.com/image/fetch/$s_!yqTv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bd5e3ef-ddab-4017-b2a3-f289806cc0f2_2400x1042.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!yqTv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bd5e3ef-ddab-4017-b2a3-f289806cc0f2_2400x1042.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Cache key format: the primer and the exploit serialise to the same 4301 bytes with different field boundaries</figcaption></figure></div><h3><span>How to print 4000 L-BTC</span></h3><p><span>The exploit ran in two steps, exactly as the layout predicts. I pulled the raw transactions from the explorer and reconstructed the cache keys byte for byte.</span></p><p><strong><span>Step one, the primer.</span></strong><span> In Liquid block 4,050,335 the attacker published two nearly identical transactions: </span><a href="https://blockstream.info/liquid/tx/271147100a94f6337b6c3db39b30c92d5b97ed91597307b6f721f73a15187ec5"><span>2711</span></a><code>7&#8230; </code>and <a href="https://blockstream.info/liquid/tx/71c93d4339fe8328981a2ec0dd23808d1ff104dc4c4cbcfc5c06fb2bb622f411"><span>71c93d</span></a><span>. Note that just one transaction would have sufficed. The second is presumably insurance.</span></p><p><span>Each has an output that is an </span><code>OP_RETURN</code><span> carrying a </span><em><span>genuine, valid range proof</span></em><span>, 4,166 bytes, verifiable in its own right. The clever part is the script on that output. It is a 69-byte </span><code>OP_RETURN</code><span> whose pushed data is not random: it embeds, byte for byte, the value commitment, asset generator and script head that the </span><strong><span>second</span></strong><span> transaction will need. When a node verifies this proof, it computes the cache key over </span><code>proof || commitment || asset || script</code><span> and stores a success. The primer&#8217;s only job is to plant that entry.</span></p><p><strong><span>Step two, the exploit.</span></strong><span> One block later, in 4,050,336, transaction </span><a href="https://blockstream.info/liquid/tx/f24a4b179b5cc7e88b25a763911f7cbdf2bf45d1d1b5ab611e94461cef0a183f"><span>f24a4b&#8230; </span></a><span>creates an output whose &#8220;range proof&#8221; is 4,234 bytes that would never pass as a valid range proof. But those 4,234 bytes are not random either: they are the primer&#8217;s 4,166-byte proof, followed by the primer&#8217;s 33-byte commitment, followed by the 33-byte asset generator, followed by the two script-header bytes </span><code>6a 43</code><span>. In other words, the exploit&#8217;s </span><em><span>proof field</span></em><span> has swallowed the primer&#8217;s proof, commitment, asset and script-head. The exploit&#8217;s own commitment, asset and a one-byte </span><code>6a</code><span> (</span><code>OP_RETURN</code><span>) script then follow in their proper places, as they were encoded in the primer&#8217;s </span><code>OP_RETURN</code><span> data.</span></p><p><span>Line up the two cache-key preimages and they are the same string:</span></p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:&quot;26532d33-155a-4cbb-9c7a-17a9bbf9df28&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">primer:   &lt;4166B proof&gt; | &lt;33B comm&gt; | &lt;33B asset&gt; | &lt; 2B head&gt; | &lt;33B comm&gt; | &lt;33B asset&gt; | &lt;1B script&gt;

                                                     &#9492;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472; 69B script &#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9496;

exploit:  &lt;4166B proof&gt; | &lt;33B comm&gt; | &lt;33B asset&gt; | &lt; 2B head&gt; | &lt;33B comm&gt; | &lt;33B asset&gt; | &lt;1B script&gt;

          &#9492;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472; 4234B &#8220;proof&#8221; &#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9496;</code></pre></div><p><span>The exploit&#8217;s forged output collides with the primer&#8217;s cache entry, so the range proof checker short-circuits to &#8220;valid&#8221; and never looks at the invalid proof. That output hides a massive overflowing amount (the &#8220;negative&#8221; output from the balance-attack sketch earlier) and a sibling output credits the attacker with a large positive amount. The balance proof, which is real and which the attacker cannot fake, sums to zero. The range proof, </span><em><span>which should have stopped it</span></em><span>, was answered from cache.</span></p><h3><span>The chain split</span></h3><p><span>Interestingly, the attack did not fool most of the Liquid network. It only fooled nodes whose cache had been poisoned, and because the commit that introduced the buggy fix had not been included in an official Elements release yet, most of the network was not running this version of the Liquid node software. It looks like the Liquid federation decided to first deploy this bugfix release to the internal Liquid infrastructure. This is a common thing to do when deploying security fixes.</span></p><p><span>But it meant that most of the network actually rejected the attacker&#8217;s transaction. They didn&#8217;t have the cache key change, so no cache hit and they actually validated the range proof and rejected the transaction, as well as the block that the transaction was relayed in.</span></p><p><span>These nodes stalled at height 4,050,335: the last block before the exploit. The nodes running the vulnerable build, including the federation&#8217;s bridge nodes, accepted 4,050,336 and kept going.</span></p><p><span>You can still watch this split today. Blockstream&#8217;s explorer, </span><a href="https://blockstream.info/liquid/"><span>blockstream.info</span></a><span>, sits above height 4,051,000. mempool.space&#8217;s Liquid node, </span><a href="https://liquid.network/"><span>liquid.network</span></a><span>, is frozen at exactly </span><strong><span>4,050,335</span></strong><span>.</span></p><p><span>OrangeSurf </span><a href="https://github.com/orangesurf/liquid-transaction-replay-monitor"><span>published</span></a><span> the reproduction recipe: run a build that includes the vulnerable commit, </span><code>invalidateblock 4050335</code><span> to push the primer back into the mempool so the poisoned key gets re-inserted, then </span><code>reconsiderblock</code><span> and your node reorgs onto the federation&#8217;s inflated chain.</span></p><h2><span>Out the front door: PAK and SideSwap</span></h2><p><span>Inflating L-BTC is only half a heist. The attacker still had to convert unbacked L-BTC into real BTC, and Liquid does not let just anyone pull from the reserve. Peg-outs are gated by </span><em><span>PAK</span></em><span>, the Pegout Authorization Key system. Each peg-out output must carry a whitelist proof tying the destination to a registered key belonging to a trusted federation member. A peg-out to an unauthorized key is simply invalid as per Liquid&#8217;s consensus rules.</span></p><p><span>So the attacker needed a PAK holder to peg the coins out for them. Enter </span><em><span>SideSwap</span></em><span>, a Liquid member that runs a peg-out pass-through service: you send it L-BTC, it peg-outs under its own PAK key, and it forwards the resulting BTC to whatever mainchain address you give it. This is a useful product. It is also a good way to render the entire PAK system pointless.</span></p><p><span>In Liquid block 4,050,349, thirteen blocks after the exploit, the coins were pegged out. On the bitcoin side the federation released the reserve as designed: roughly 3,996 BTC landed at SideSwap&#8217;s whitelisted address </span><a href="https://mempool.space/address/bc1qgslsydz56d0ed6827hdemfmk5w2f6ldyc6wt7p"><span>bc1qgslsydz56d0ed6827hdemfmk5w2f6ldyc6wt7p</span></a><span>, which forwarded it on to the attacker&#8217;s address </span><a href="https://mempool.space/address/bc1ql4mfu6aundtkksxklfajs2h3t9nzcd6gyqjlte"><span>bc1ql4mfu6aundtkksxklfajs2h3t9nzcd6gyqjlte</span></a><span>.</span></p><p><span>Because the balance and PAK checks all passed, SideSwap&#8217;s node and every functionary treated it as an ordinary authorized withdrawal. Liquid&#8217;s own incident report confirms the shape: the validation failure was at the transaction level, before the peg-out, so nothing downstream had reason to object.</span></p><p><span>The part that should give every system designer pause: </span><strong><span>neither the peg-out mechanism nor SideSwap had either a built-in time delay or an upper limit on amounts.</span></strong><span> A single transaction that moved on the order of 4,000 BTC, roughly 400M USD at the time, went straight through: no waiting, no manual review, no velocity check. Before the incident the reserve held about 4,205 BTC. Nothing was in place to prevent 95% of that from leaving the system in about half an hour.</span></p><h3><span>The white hat and the negotiation</span></h3><p><span>Then the story takes a very unexpected turn. Bitcoin heists like this usually are followed by total silence in which the funds stay put, or by transactions showing the attacker is trying to obfuscate his trails and white-wash the coins.</span></p><p><span>Instead, a few hours after the drain, with a </span><a href="https://mempool.space/tx/c103de95817b43f2df635ec6f35ff126ca26a7c6d20570c4b01866b2b3e69a19"><span>transaction</span></a><span> paying 1,000 sats to the federation wallet, the attacker left a note in an </span><code>OP_RETURN</code><span>:</span></p><blockquote><p>&gt; we are whitehats. contact us on chain</p></blockquote><p><span>Blockstream replied from a known address: </span><code>&#8220;Please contact security@blockstream.com&#8221;,</code><span> then an encrypted message signed with their security key. The attacker agrees to send the funds back to the federation address but demands the bug be fixed first:</span></p><blockquote><p><span>&gt; Please fix the bug first. The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix.</span></p></blockquote><p><span>Blockstream clear-signed </span><strong><span>&#8221;Yes, thank you,&#8221;</span></strong><span> and later &#8221;</span><strong><span>Bridge nodes are patched, safe to return the funds.&#8221;</span></strong><span> </span></p><p><span>On 7 September at 16:09 UTC, the attacker </span><a href="https://mempool.space/tx/a6d697a25266ce3c78774fd1d75f896b7af522ada209b0f6228ea497bc49a46d"><span>returned</span></a><span> exactly </span><strong><span>3,400 BTC</span></strong><span> to the federation&#8217;s wallet and kept about </span><strong><span>598.5 Bitcoin</span></strong><span> (roughly 15%) in his own wallet.</span></p><p><span>That 15% was not an accident, and the tone did not stay collegial. In a later message the attacker dropped his white-hat pose entirely:</span></p><blockquote><p><span>Your dereliction of duty is obvious that you allocated only $1.5M (maybe even 0) to secure $5B assets. [&#8230;] You SHALL pay 10% using your own money as bug bounty or you will cause all your holders a 15% loss for your irresponsibility and stinginess. [&#8230;] Anyway we are going to publish the private key to decrypt our conversations afterwards.</span></p></blockquote><p><span>Whatever you call someone who drains a chain, pegs it out through an unwitting third party, and then negotiates a bounty under threat, &#8220;white hat&#8221; is not a term I would use. As of writing, Liquid is still paused, the 3,400 BTC is back, and roughly 598 BTC is outstanding while the two sides argue over the difference.</span></p><p><span>The whole exchange is visible on the bitcoin mainchain, signed and verifiable; </span><a href="https://btcpp.dev/whois/sjors"><span>Sjors</span></a><span> published a </span><a href="https://gist.github.com/Sjors/9d24363e67529079cc2ae4305ff90fcd"><span>script and transcript</span></a><span>, that checks the PGP signatures against Blockstream&#8217;s published key, and there is a </span><a href="https://opreturn-chat.arvin.dev/"><span>readable viewer</span></a><span> where you can follow the entire conversation live.</span></p><h2><span>The real fix, and what it teaches</span></h2><p><span>The actual repair got </span><a href="https://github.com/ElementsProject/elements/commit/94000967f6dc05b1afd435e79b1bbc597e29f816"><span>shipped</span></a><span>, as part of Elements release v23.3.4. It stops hashing the cache-key fields by raw concatenation and serializes them through </span><code>CHashWriter</code><span> instead, which length-prefixes every field. Once each variable-length field is preceded by its length, the byte-shift trick is dead: a longer proof and a shorter script no longer produce the same encoding, because the lengths themselves are part of the hash. The release also adds a </span><code>-norangeproofcache</code><span> switch to turn the cache off entirely.</span></p><p><span>There are a few lessons here, and none of them are exotic.</span></p><p><strong><span>A cache key is a security boundary.</span></strong><span> The instant a verification result is memoized, the key that identifies it inherits the full weight of the check it replaces. Leave a field out and you have silently widened what counts as &#8220;the same&#8221;.</span></p><p><strong><span>Simple concatenation is not safe serialization</span></strong><span>. Gluing variable-length fields together without lengths or safe delimiters is a canonicalization bug waiting for someone with creativity to find a way to abuse it.</span></p><p><strong><span>Fixes deserve the same fear as features,</span></strong><span> especially security fixes under time pressure. The recent change was trying to make the key correct and ended up breaking it instead. The dangerous edit was the one that looked like a patch.</span></p><p><span>And, finally, </span><strong><span>defense in depth is not optional</span></strong><span> at the money layer. Bugs happen to all of us, but the loss was 4,000 BTC because a single peg-out with no limit could carry the entire reserve out in half an hour. The consensus bug is fixed. The question of why the pegouts have no delay and no ceiling is the one Blockstream and SideSwap still have to answer.</span></p><p></p><p><em><span>bitcoin++ Insiders Edition will be in Berlin, this coming October 1 &#8212; 3 at the upcoming payments edition bitcoin++ conference. Join us for three days of hacking, talks, and hands-on workshops. </span><a href="https://btcpp.dev/berlin26#tickets?code=insider"><span>Use code INSIDER for 20% off a ticket.</span></a></em></p>]]></content:encoded></item><item><title><![CDATA[temudandelion - This Week in Bitcoin Core #57]]></title><description><![CDATA[This week we change private broadcast to temudandelion...]]></description><link>https://insider.btcpp.dev/p/temudandelion-this-week-in-bitcoin</link><guid isPermaLink="false">https://insider.btcpp.dev/p/temudandelion-this-week-in-bitcoin</guid><dc:creator><![CDATA[kevkevin]]></dc:creator><pubDate>Fri, 11 Sep 2026 14:02:12 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!MJw8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cee73e5-1dd4-4081-a559-6f40592a5154_1456x816.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Hello &#128075; folks, I&#8217;m Kevkevin. I&#8217;m an open-source developer and reporter for Insider Edition. Last week, I reviewed several pull requests from the <a href="https://github.com/bitcoin/bitcoin/pulls">Bitcoin Core</a> repo.<br><br>In the Bitcoin Core 31.0 release notes, the private broadcast feature promised that your IP would <strong>never be known</strong> to the recipients and that unrelated transactions would <strong>not be linked</strong>. In the weekly IRC meeting, there was discussion on whether Bitcoin Core can still back that.<br><br>Fankquake mentioned that privacy leaks had been reported to the security team, and they wanted broader threat model discussion before releasing v32.0. There was also discussion on renaming the flag; here are some of the options. (<code>-cloakedbroadcast</code>, <code>-oneshottorbroadcast</code>, <code>-notsoprivatebroadcast</code>, -<code>temudandelion)<br><br></code>Branch-off for v32.0 was supposed to be yesterday. But there is still no <code>32.x</code> branch and no v32 tag yet. Five items are still open on the <a href="https://github.com/bitcoin/bitcoin/milestone/84">32.0 milestone</a>.<br><br></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!MJw8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cee73e5-1dd4-4081-a559-6f40592a5154_1456x816.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!MJw8!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cee73e5-1dd4-4081-a559-6f40592a5154_1456x816.png 424w, https://substackcdn.com/image/fetch/$s_!MJw8!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cee73e5-1dd4-4081-a559-6f40592a5154_1456x816.png 848w, https://substackcdn.com/image/fetch/$s_!MJw8!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cee73e5-1dd4-4081-a559-6f40592a5154_1456x816.png 1272w, https://substackcdn.com/image/fetch/$s_!MJw8!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cee73e5-1dd4-4081-a559-6f40592a5154_1456x816.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!MJw8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cee73e5-1dd4-4081-a559-6f40592a5154_1456x816.png" width="1456" height="816" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1cee73e5-1dd4-4081-a559-6f40592a5154_1456x816.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:816,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!MJw8!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cee73e5-1dd4-4081-a559-6f40592a5154_1456x816.png 424w, https://substackcdn.com/image/fetch/$s_!MJw8!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cee73e5-1dd4-4081-a559-6f40592a5154_1456x816.png 848w, https://substackcdn.com/image/fetch/$s_!MJw8!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cee73e5-1dd4-4081-a559-6f40592a5154_1456x816.png 1272w, https://substackcdn.com/image/fetch/$s_!MJw8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cee73e5-1dd4-4081-a559-6f40592a5154_1456x816.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h4><strong>Merged PR&#8217;s</strong></h4><h5><strong>Every week, several changes are officially added to Bitcoin Core. This week, </strong>multiple <strong>changes were merged. Here are some I found interesting this week.</strong></h5><ul><li><p><strong><a href="https://github.com/bitcoin/bitcoin/pull/35445">wallet, descriptor: Revert </a></strong><code>StringType::COMPAT</code><strong><a href="https://github.com/bitcoin/bitcoin/pull/35445"> for Miniscript expressions and drop the concept of a Descriptor ID that can be validated</a></strong> by <strong><a href="https://github.com/achow101">achow101</a></strong></p><p>achow101 closed a wallet compatibility hole that had already bitten once.<br></p><p>Miniscript keys were not handled <code>StringType::COMPAT</code> correctly when computing a Descriptor ID. To keep old wallets loading, Core had to keep hashing that ID the wrong way. This is the second time that happened, so this PR stops pretending the ID is something you can validate at all.<br></p><p>The value read from the database is now an opaque blob that only ties records to a ScriptPubKeyMan. <code>DescriptorID</code> is renamed to <code>CompatDescriptorHash</code> &#8212; still written, no longer checked against a recomputed hash. <code>importdescriptors</code> and <code>createwalletdescriptor</code> compare descriptor strings instead of hashes. Lookup in <code>m_spk_managers</code> goes from a map to <code>std::find_if</code> (log to linear). achow101&#8217;s take: those RPCs are not the hot path, and <code>importdescriptors</code> might rescan anyway.<br></p><p>The wallet backwards-compat test now includes 30.2 and 31.0 nodes plus a Miniscript wallet, so both directions get exercised. Fixes #35432. If you have a wallet with Miniscript in it from a previous release, this is the PR that is supposed to keep it loading.</p><p></p></li><li><p><strong><a href="https://github.com/bitcoin/bitcoin/pull/36174">http: throttle send buffer when client stops draining</a></strong> by <strong><a href="https://github.com/pinheadmz">pinheadmz</a></strong></p><p>If a client stops reading the socket, Core used to keep dispatching requests and packing responses into <code>m_send_buffer</code> with no cap. After a complete request is parsed, before it goes to a worker, the server now checks that buffer. Already 32MiB sitting there (<code>MAX_BODY_SIZE</code>, open for bikeshedding) and the request stays as <code>m_req</code> instead of getting another worker. The misbehaving client does not get an unbounded send queue for free.<br></p><p>This was found and disclosed by the Red Team &#128997;. Same HTTP rewrite pinheadmz has been triaging agent findings on &#8212; last week he asked people to keep them coming before branch-off.</p></li></ul><h5><strong>There are always changes being updated and reviewed in real-time. Here are some notable PR&#8217;s that are still up and looking for reviews.</strong></h5><ul><li><p><strong><a href="https://github.com/bitcoin/bitcoin/pull/34374">kernel: use struct-based logging and simplify logging interface</a></strong> by <strong><a href="https://github.com/stickies-v">stickies-v</a></strong></p><p><a href="https://github.com/sedited">sedited</a> asked for comments in Thursday&#8217;s meeting. stickies-v just pushed after months of architecture thrash. It is open, not a draft, not Needs rebase. Last week&#8217;s prefetch PR (<a href="https://github.com/bitcoin/bitcoin/pull/36000">#36000</a>) is still open too if you have a second tab.</p><blockquote><p>tl;dr: kernel logging is cumbersome. This PR delivers log entries as a struct instead of a formatted string, and simplifies the kernel logging interface. Closes #34062.</p><p>Kernel logging has a few problems:</p><ul><li><p>callbacks operate on formatted strings, so users need to parse the string to get the timestamp, category, level, ... based on which options are set. This is cumbersome, brittle, and inefficient.</p></li><li><p>the filtering interface is not really intuitive, requiring users to call combinations of <code>btck_logging_set_level_category</code> and <code>btck_logging_enable_category</code> when they want to produce <code>debug</code> or <code>trace</code> logs.</p></li><li><p>the node logging infrastructure has quite a bit more functionality than is necessary for a library.</p></li></ul><p>This PR gives <code>bitcoinkernel</code> its own implementation of those hooks, so it no longer depends on <code>logging.cpp</code>, and upgrades the C API to deliver struct-based entries. Node logging is not changed.</p></blockquote></li></ul><div><hr></div><h4><strong>IRC meeting notes</strong></h4><h5><strong>Every week on Thursday, there is an IRC meeting. Here are some short notes from that meeting.</strong></h5><pre><code>&#120307;&#120311;&#120302;&#120309;&#120319;: There are no pre-proposed meeting topics this week. Any last minute ones to add?
&#120307;&#120311;&#120302;&#120309;&#120319;: Let's start with the WGs

--- Topic 1 ---
&#120307;&#120311;&#120302;&#120309;&#120319;: #topic QA WG Update (brunoerg)
&#120303;&#120319;&#120322;&#120315;&#120316;&#120306;&#120319;&#120308;: no update this week

--- Topic 2 ---
&#120307;&#120311;&#120302;&#120309;&#120319;: #topic QML GUI WG Update (johnny9dev)
&#120311;&#120316;&#120309;&#120315;&#120315;&#120326;&#120821;&#120305;&#120306;&#120323;: First chunk of the staging branch was merged in
&#120311;&#120316;&#120309;&#120315;&#120315;&#120326;&#120821;&#120305;&#120306;&#120323;: Establishes the qml foundational pieces
&#120311;&#120316;&#120309;&#120315;&#120315;&#120326;&#120821;&#120305;&#120306;&#120323;: hebasto helped a ton with the final review
&#120311;&#120316;&#120309;&#120315;&#120315;&#120326;&#120821;&#120305;&#120306;&#120323;: I have drafts for the next two chunks. Both will setup the wallet disabled version of the gui.
&#120309;&#120306;&#120303;&#120302;&#120320;&#120321;&#120316;: post-merge review is always welcome; especially from python people
&#120311;&#120316;&#120309;&#120315;&#120315;&#120326;&#120821;&#120305;&#120306;&#120323;: Yeah everything can be updated. Nothing has to be finalized
&#120311;&#120316;&#120309;&#120315;&#120315;&#120326;&#120821;&#120305;&#120306;&#120323;: I have a rough list of all of the chunks now and the order they should go in and I will create the tracking issue to "Upgrading Gui to Qml" with it.
&#120311;&#120316;&#120309;&#120315;&#120315;&#120326;&#120821;&#120305;&#120306;&#120323;: Pseudoramdom is updating the designs to make them more desktop friendly and consistent in parallel and epicleafies is taking care of transaction and activity issues
&#120311;&#120316;&#120309;&#120315;&#120315;&#120326;&#120821;&#120305;&#120306;&#120323;: That's all for now

--- Topic 3 ---
&#120307;&#120311;&#120302;&#120309;&#120319;: #topic Benchmarking WG Update (l0rinc, andrewtoth)
&#120302;&#120315;&#120305;&#120319;&#120306;&#120324;&#120321;&#120316;&#120321;&#120309;: no update

--- Topic 4 ---
&#120307;&#120311;&#120302;&#120309;&#120319;: #topic Kernel WG Update (sedited)
&#120320;&#120306;&#120305;&#120310;&#120321;&#120306;&#120305;: don't have anything from my side, but stickies-v recently pushed to #34374 again and left a comment: https://github.com/bitcoin/bitcoin/pull/34374#issuecomment-5605856730
&#120320;&#120306;&#120305;&#120310;&#120321;&#120306;&#120305;: would be good to get some comments there.
&#120320;&#120306;&#120305;&#120310;&#120321;&#120306;&#120305;: that's all.

--- Topic 5 ---
&#120307;&#120311;&#120302;&#120309;&#120319;: That's it for the WGs afaict, anything to say about the release?
&#120307;&#120302;&#120315;&#120318;&#120322;&#120302;&#120312;&#120306;: I think we are looking pretty decent for branch off
&#120320;&#120306;&#120305;&#120310;&#120321;&#120306;&#120305;: branch-off should be today, but there are still a few things in the milestone https://github.com/bitcoin/bitcoin/milestone/84
&#120307;&#120302;&#120315;&#120318;&#120322;&#120302;&#120312;&#120306;: There does seem to be an outstanding thread in regards to private broadcast, which could be worth discussing now
&#120307;&#120302;&#120315;&#120318;&#120322;&#120302;&#120312;&#120306;: Re what's left on the milestone, if any of those miss, they should also all be fine to backport into 32.x
&#120320;&#120306;&#120305;&#120310;&#120321;&#120306;&#120305;: yes
&#120307;&#120311;&#120302;&#120309;&#120319;: What's the private broadcast thread?
&#120305;&#120302;&#120319;&#120316;&#120320;&#120310;&#120316;&#120319;: Should we do privatebroadcast now or milestone?
&#120307;&#120302;&#120315;&#120318;&#120322;&#120302;&#120312;&#120306;: re private broadcast. Some privacy leaks have reported to the security team, and we'd like to facilitate a broader discussion about the threat model to know how to handle those
&#120307;&#120302;&#120315;&#120318;&#120322;&#120302;&#120312;&#120306;: I don't think there's too much to discuss on the milestone, other than, everything is looking for review
&#120307;&#120302;&#120315;&#120318;&#120322;&#120302;&#120312;&#120306;: (or if someone thinks something is missing)
&#120307;&#120311;&#120302;&#120309;&#120319;: fanquake: but is that something still relevant for the release, e.g. putting some warning in there, or is this a discussion unrelated to the release
&#120307;&#120302;&#120315;&#120318;&#120322;&#120302;&#120312;&#120306;: fjahr: I think it's both
&#120320;&#120306;&#120305;&#120310;&#120321;&#120306;&#120305;: my impression is the base assumption of the feature is "no worse privacy than only connecting through tor"
&#120302;&#120315;&#120305;&#120319;&#120306;&#120324;&#120321;&#120316;&#120321;&#120309;: there's one issue i think we should patch
&#120302;&#120315;&#120305;&#120319;&#120306;&#120324;&#120321;&#120316;&#120321;&#120309;: not sure what we are discussing here exactly though
&#120310;&#120315;&#120320;&#120321;&#120302;&#120308;&#120310;&#120303;&#120303;&#120320;: so for release, we could suggest remediations such as preferred configurations, or soft enforce them in releases. as an example
&#120320;&#120306;&#120305;&#120310;&#120321;&#120306;&#120305;: what do you mean with preferred configurations instagibbs?
&#120302;&#120315;&#120305;&#120319;&#120306;&#120324;&#120321;&#120316;&#120321;&#120309;: I'm not sure having to speak cryptically in a public conversation is helpful. Otherwise we should have a private conversation somewhere else where we can discuss everything openly.
&#120305;&#120302;&#120319;&#120316;&#120320;&#120310;&#120316;&#120319;: My understanding is there is more than one issue, and that it's not clear how far we want to go in patching them, and how to think about it consistently.
&#120305;&#120302;&#120319;&#120316;&#120320;&#120310;&#120316;&#120319;: andrewtoth: i think we can discuss openly what privacy guarantees we want to provide users. Then the specific instances in which they are breached can be kept momentarily private like we do for security breaches.
&#120307;&#120302;&#120315;&#120318;&#120322;&#120302;&#120312;&#120306;: I think a situation where we need to ship a feature with a caveat of *maybe don't use it unless you configure it a certain way*, but we don't make that the default, is not great
&#120310;&#120315;&#120320;&#120321;&#120302;&#120308;&#120310;&#120303;&#120303;&#120320;: sedited f.e. we could encourage people who want higher assurance that they run onlynet=onion, or similar. Or maybe this is again just pure communication about privacy model
&#120313;&#120310;&#120308;&#120309;&#120321;&#120313;&#120310;&#120312;&#120306;: yes, we could mention that private broadcast is still somewhat new/experimental and recommend to combine it with -onlynet=onion and -listen=0 if privacy is really needed instead of fully trusting it.
&#120310;&#120315;&#120320;&#120321;&#120302;&#120308;&#120310;&#120303;&#120303;&#120320;: ^ less inbound influence, that sort of thing yes
&#120320;&#120310;&#120317;&#120302;: (I haven't followed the issues) is there much of a point to privatebroadcast if you're in -onlynet=onion -listen=0 ?
&#120310;&#120315;&#120320;&#120321;&#120302;&#120308;&#120310;&#120303;&#120303;&#120320;: I think the idea was logical OR?
&#120320;&#120306;&#120305;&#120310;&#120321;&#120306;&#120305;: agree with sipa, there seems to be no point to the feature if that is the case.
&#120313;&#120310;&#120308;&#120309;&#120321;&#120313;&#120310;&#120312;&#120306;: sipa: correlating multiple connections originating from a node - any random outbound peer could do that.
&#120320;&#120310;&#120317;&#120302;: There is a small advantage still, namely that the receiver cannot correlate it with other traffic from you.
&#120320;&#120310;&#120317;&#120302;: Right.
&#120313;&#120310;&#120308;&#120309;&#120321;&#120313;&#120310;&#120312;&#120306;: *multiple transactions, not connections
&#120320;&#120306;&#120305;&#120310;&#120321;&#120306;&#120305;: I think this should be a binary choice. Either it works as advertised, or it doesn't and should be removed.
&#120310;&#120315;&#120320;&#120321;&#120302;&#120308;&#120310;&#120303;&#120303;&#120320;: "as advertised" doing all the work
&#120302;&#120315;&#120305;&#120319;&#120306;&#120324;&#120321;&#120316;&#120321;&#120309;: so what are we advertising?
&#120305;&#120302;&#120319;&#120316;&#120320;&#120310;&#120316;&#120319;: Yeah exactly, i agree with sedited but what guarantee are we aiming to provide
&#120307;&#120311;&#120302;&#120309;&#120319;: Depending on how easy to exploit the leak is, maybe documentation is not enough and we should enforce the settings until we have had the broader discussion. We should assume at least some users really need serious privacy if they use it and it seems risky no only use documentation.
&#120302;&#120315;&#120305;&#120319;&#120306;&#120324;&#120321;&#120316;&#120321;&#120309;: either we are talking about the guarantees we want to provide, or we are talking about some mitigation for something we can't disclose
&#120320;&#120310;&#120317;&#120302;: The 31.0 release notes make some promises.
&#120305;&#120302;&#120319;&#120316;&#120320;&#120310;&#120316;&#120319;: Are shooting for "If you are not a reachable node, operating only on Tor, then we guarantee the transactions you broadcast won't be easily correlated with each other"?
&#120310;&#120315;&#120320;&#120321;&#120302;&#120308;&#120310;&#120303;&#120303;&#120320;: If our privacy model is "honest but curious", then AFAIK we cover that. It's also about user expectations
&#120310;&#120315;&#120320;&#120321;&#120302;&#120308;&#120310;&#120303;&#120303;&#120320;: but that;s hard to to communicate, and weaker
&#120310;&#120315;&#120320;&#120321;&#120302;&#120308;&#120310;&#120303;&#120303;&#120320;: "what's honest but curious": they follow protocol, but write everything down, say
&#120307;&#120302;&#120315;&#120318;&#120322;&#120302;&#120312;&#120306;: The claims in https://bitcoincore.org/en/releases/31.0/ are "Their IP address (and thus geolocation) is never known to the recipients." &amp; "If the originator sends two otherwise unrelated transactions, they will not be linkable. This is because a separate connection is used for broadcasting each transaction. "
&#120305;&#120302;&#120319;&#120316;&#120320;&#120310;&#120316;&#120319;: instagibbs: so, passive observer?
&#120310;&#120315;&#120320;&#120321;&#120302;&#120308;&#120310;&#120303;&#120303;&#120320;: vs active probing, protcool violations
&#120320;&#120306;&#120305;&#120310;&#120321;&#120306;&#120305;: yeah, that seems very clear.
&#120310;&#120315;&#120320;&#120321;&#120302;&#120308;&#120310;&#120303;&#120303;&#120320;: darosior they follow the stated protocol
&#120310;&#120315;&#120320;&#120321;&#120302;&#120308;&#120310;&#120303;&#120303;&#120320;: whatever that means
&#120310;&#120315;&#120320;&#120321;&#120302;&#120308;&#120310;&#120303;&#120303;&#120320;: the prior issue we had and fixed violated this
&#120320;&#120310;&#120317;&#120302;: There isn't even a well-defined "honest" behavior for nodes.
&#120310;&#120315;&#120320;&#120321;&#120302;&#120308;&#120310;&#120303;&#120303;&#120320;: sipa handwaving here
&#120320;&#120306;&#120305;&#120310;&#120321;&#120306;&#120305;: if we can't guarantee what's in those release notes, then we should not ship the feature imo.
&#120305;&#120302;&#120319;&#120316;&#120320;&#120310;&#120316;&#120319;: Making a difference between passive and active attackers here make sense, but i'm concerned it would be hard to translate into an actionable information for users, and end up being a footgun.
&#120320;&#120310;&#120317;&#120302;: Right, but "honest but curious" is trivially false, if every behavior is "honest". That's a term that's used in cryptographic protocol with a well-defined prescription of how honest parties operate. Bitcoin doesn't have any of those.
&#120310;&#120315;&#120320;&#120321;&#120302;&#120308;&#120310;&#120303;&#120303;&#120320;: fanquake ok that note is wrong, two txs can be linked at the blockchain layer even with perfect impl
&#120310;&#120315;&#120320;&#120321;&#120302;&#120308;&#120310;&#120303;&#120303;&#120320;: "not be linkable at the networking layer" maybe
&#120302;&#120315;&#120305;&#120319;&#120306;&#120324;&#120321;&#120316;&#120321;&#120309;: instagibbs "otherwise unrelated" though
&#120302;&#120315;&#120305;&#120319;&#120306;&#120324;&#120321;&#120316;&#120321;&#120309;: maybe that can be better defined
&#120310;&#120315;&#120320;&#120321;&#120302;&#120308;&#120310;&#120303;&#120303;&#120320;: andrewtoth well, theyre all related :D but yes
&#120310;&#120315;&#120320;&#120321;&#120302;&#120308;&#120310;&#120303;&#120303;&#120320;: sipa ok, then that. dont worry about my misuse of labels too much
&#120320;&#120310;&#120317;&#120302;: instagibbs: no, i literally don't understand what you mean
&#120320;&#120310;&#120317;&#120302;: like you seem to have an implicit understanding of what "an honest node" means, but i think there is no such thing, and i don't know what it ought to entail
&#120305;&#120302;&#120319;&#120316;&#120320;&#120310;&#120316;&#120319;: What threshold are we aiming for to release this feature? That it prevents linkage at the network layer against a passive observer? Against an active one if you are not reachable? Against an active one if you are not reachable AND Tor-only? Against an active one no matter one?
&#120310;&#120315;&#120320;&#120321;&#120302;&#120308;&#120310;&#120303;&#120303;&#120320;: maybe the answer is "no we have no common definitions of what we're promising"
&#120302;&#120315;&#120305;&#120319;&#120306;&#120324;&#120321;&#120316;&#120321;&#120309;: ideally the strongest, but it's hard to say whether we can do it or not. Some issues preventing that can be patched easily, some I've seen are very theoretical and don't seem plausible.
&#120310;&#120315;&#120320;&#120321;&#120302;&#120308;&#120310;&#120303;&#120303;&#120320;: let's save the risk estimation for the security team, please
&#120310;&#120315;&#120320;&#120321;&#120302;&#120308;&#120310;&#120303;&#120303;&#120320;: at least for now
&#120302;&#120315;&#120305;&#120319;&#120306;&#120324;&#120321;&#120316;&#120321;&#120309;: well then we want to keep the guarantees from v31 release notes?
&#120307;&#120311;&#120302;&#120309;&#120319;: We need to have some clarifying information though, the feature is called privatebroadcast so people will expect something just based on that
&#120302;&#120315;&#120305;&#120319;&#120306;&#120324;&#120321;&#120316;&#120321;&#120309;: yeah, this conversation is too difficult if everything is not on the table
&#120305;&#120327;&#120325;&#120327;&#120308;: +1
&#120305;&#120302;&#120319;&#120316;&#120320;&#120310;&#120316;&#120319;: It's hard for me to see how we could give these guarantees completely as long as we have the mechanism embedded in net_processing, so plausibility may need to be discussed as part of the goal here. Are we happy to ship this feature if we give "reasonable" guarantees, i.e. kill the really low hanging fruits, on a "it's better than nothing" basis?
&#120305;&#120302;&#120319;&#120316;&#120320;&#120310;&#120316;&#120319;: fjahr: +1 for expectations
&#120320;&#120310;&#120317;&#120302;: Maybe this needs a discussion at coredev, and a focus right now about what we can reasonable address by documentation clarification for 32?
&#120310;&#120315;&#120320;&#120321;&#120302;&#120308;&#120310;&#120303;&#120303;&#120320;: ^ this
&#120321;&#120310;&#120308;&#120306;&#120319;&#120288;&#120302;&#120307;&#120310;&#120302;: fjahr: +1
&#120302;&#120315;&#120305;&#120319;&#120306;&#120324;&#120321;&#120316;&#120321;&#120309;: how can we focus on what we can reasonably address if we can't discuss the issues?
&#120305;&#120302;&#120319;&#120316;&#120320;&#120310;&#120316;&#120319;: Yeah i was really still on the binary question of what threshold are we setting for ourselves (which necessarily entail not shipping it at all until it meets that threshold, instead of trying to address it with documentation).
&#120305;&#120327;&#120325;&#120327;&#120308;: If the security model has changed substantially since when the feature was shipped it should be disabled or renamed, but I do think something should ship which is better than the default
&#120305;&#120302;&#120319;&#120316;&#120320;&#120310;&#120316;&#120319;: My favorite shed for the rename is -cloakedbroadcast /s
&#120302;&#120315;&#120305;&#120319;&#120306;&#120324;&#120321;&#120316;&#120321;&#120309;: i don't think we should disable it, it is better than the default way to broadcast.
&#120305;&#120302;&#120319;&#120316;&#120320;&#120310;&#120316;&#120319;: (But i do think rename makes more sense than documenting a feature called "private X" with caveats "actually not private in scenarii x, y and z")
&#120310;&#120315;&#120320;&#120321;&#120302;&#120308;&#120310;&#120303;&#120303;&#120320;: dzxzg issue is I'm not sure we agreed ahead of time
&#120320;&#120306;&#120305;&#120310;&#120321;&#120306;&#120305;: I'm confused, what's not clear about the release note there?
&#120310;&#120315;&#120320;&#120321;&#120302;&#120308;&#120310;&#120303;&#120303;&#120320;: I dont read the docs
&#120310;&#120315;&#120320;&#120321;&#120302;&#120308;&#120310;&#120303;&#120303;&#120320;: *ducks*
&#120320;&#120306;&#120305;&#120310;&#120321;&#120306;&#120305;: :D
&#120320;&#120310;&#120317;&#120302;: instagibbs: well, you or your agent
&#120305;&#120302;&#120319;&#120316;&#120320;&#120310;&#120316;&#120319;: sedited: fair
&#120310;&#120315;&#120320;&#120321;&#120302;&#120308;&#120310;&#120303;&#120303;&#120320;: the docs seem to match my expectation of the feature in my head so maybe less confusion than im letting on
&#120326;&#120302;&#120315;&#120304;&#120326;: I think the wording "never known" might give a false sense of security.
&#120305;&#120302;&#120319;&#120316;&#120320;&#120310;&#120316;&#120319;: Ok since i don't think the status quo is desirable, i suggest we rename the feature for the upcoming release, with a name that does not give as much expectation as "private" broadcast, and make weaker claims in our release notes than we did for 31. This way we keep the option for now because it's better than the other broadcast, but also don't risk users depending on something we cannot guarantee.
&#120310;&#120315;&#120320;&#120321;&#120302;&#120308;&#120310;&#120303;&#120303;&#120320;: ah the easy part, naming things
&#120307;&#120311;&#120302;&#120309;&#120319;: -betterthanthedefaultbroadcast it is
&#120320;&#120313;&#120310;&#120323;&#120815;&#120319;__: -broadcast++
&#120321;&#120310;&#120308;&#120306;&#120319;&#120288;&#120302;&#120307;&#120310;&#120302;: yancy: yes! given the current state of the discussion, it's VERY bold
&#120305;&#120302;&#120319;&#120316;&#120320;&#120310;&#120316;&#120319;: I don't think it's a great situation, but i don't have a better idea for 32 literally on the day of branch off.
&#120302;&#120315;&#120305;&#120319;&#120306;&#120324;&#120321;&#120316;&#120321;&#120309;: a release not warning is not enough?
&#120302;&#120315;&#120305;&#120319;&#120306;&#120324;&#120321;&#120316;&#120321;&#120309;: *note
&#120306;&#120322;&#120308;&#120306;&#120315;&#120306;&#120320;&#120310;&#120306;&#120308;&#120306;&#120313;: -notsoprivatebroadcast
&#120320;&#120306;&#120305;&#120310;&#120321;&#120306;&#120305;: this will have to be backported anway, so we'll have a few weeks to discuss.
&#120313;&#120310;&#120308;&#120309;&#120321;&#120313;&#120310;&#120312;&#120306;: and when we fixed the known issues, do we rename it back to "private broadcast"?
&#120305;&#120302;&#120319;&#120316;&#120320;&#120310;&#120316;&#120319;: lightlike: -evenbetterthandefaultbroadcast
&#120302;&#120315;&#120305;&#120319;&#120306;&#120324;&#120321;&#120316;&#120321;&#120309;: lightlike +1 - release note warning is better
&#120305;&#120302;&#120319;&#120316;&#120320;&#120310;&#120316;&#120319;: I don't think a release note is nearly enough to compensate for the potential sense of security providing a feature called "private X" may give to users.
&#120321;&#120310;&#120308;&#120306;&#120319;&#120288;&#120302;&#120307;&#120310;&#120302;: how's "-veilbroadcast" since it's partial in privacy
&#120310;&#120315;&#120320;&#120321;&#120302;&#120308;&#120310;&#120303;&#120303;&#120320;: release note warning should happen regardless
&#120305;&#120302;&#120319;&#120316;&#120320;&#120310;&#120316;&#120319;: Anyways, i don't have much to add on this topic.
&#120307;&#120311;&#120302;&#120309;&#120319;: The meeting is coming to a close in 5min, feel free to continue discussing renaming vs. release notes, but is there anything else anyone wanted to discuss/announce in the meeting?
&#120307;&#120311;&#120302;&#120309;&#120319;: I think renaming should be to some name that doesn't make any promises, like -oneshottorbroadcast then we don't have issues like this with naming
&#120307;&#120311;&#120302;&#120309;&#120319;: (if people want a renaming)
&#120305;&#120327;&#120325;&#120327;&#120308;: no strong feeling about what the name should be, but the point of renaming in my mind is less about the promises the name makes and more to catch people that haven't read release notes or new documentation and go on using private broadcast with the wrong expectations
&#120288;&#120322;&#120319;&#120304;&#120309;[&#120314;]: Isn't the point that the transaction appears to come from a node that isn't the sender?
&#120288;&#120322;&#120319;&#120304;&#120309;[&#120314;]: So, maybe "teleportbroadcast" or "strawmanbroadcast" or smth?
&#120288;&#120322;&#120319;&#120304;&#120309;[&#120314;]: surrogatebroadcast? :p
&#120310;&#120315;&#120320;&#120321;&#120302;&#120308;&#120310;&#120303;&#120303;&#120320;: temudandelion
&#120288;&#120322;&#120319;&#120304;&#120309;[&#120314;]: heh
&#120310;&#120315;&#120320;&#120321;&#120302;&#120308;&#120310;&#120303;&#120303;&#120320;: im JOKING
&#120307;&#120311;&#120302;&#120309;&#120319;: Murch: sounds still fine, as long as it's more descriptive of the mechanism rather than making promises of an end result
&#120326;&#120302;&#120315;&#120304;&#120326;: shielded-broadcast is my bikeshed color
&#120307;&#120311;&#120302;&#120309;&#120319;: sipa about to suggest -minibroadcast
&#120307;&#120311;&#120302;&#120309;&#120319;: Ok, let's end the meeting with this :D
&#120307;&#120311;&#120302;&#120309;&#120319;: #endmeeting</code></pre><p>Read here for the <a href="https://achow101.com/ircmeetings/2026/bitcoin-core-dev.2026-09-10_16_00.html">full meeting</a></p><div><hr></div><h4><strong>Releases</strong></h4><ul><li><p>32.0 feature freeze was 2026-08-20. Branch-off / <code>v32.0rc1</code> was targeted for 2026-09-10 and has not landed. The <a href="https://github.com/bitcoin/bitcoin/milestone/84">32.0 milestone</a> still has 5 open items. Latest still <a href="https://github.com/bitcoin/bitcoin/releases/tag/v31.1">v31.1</a> / <a href="https://github.com/bitcoin/bitcoin/releases/tag/v30.3">v30.3</a> / <a href="https://github.com/bitcoin/bitcoin/releases/tag/v29.4">v29.4</a>.</p></li></ul><div><hr></div><blockquote><p>Thank you for reading. Be sure to tune in again next week for your updates on Bitcoin Core!</p></blockquote><p><em>If there are any comments, suggestions, or errors, do not hesitate to reach out or comment</em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://insider.btcpp.dev/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">bitcoin++'s Insider Edition is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Antoine Poinsot - BTC++ Insider Interviews]]></title><description><![CDATA[Throwback Thursday: Antoine Poinsot at Btcpp Austin 2025]]></description><link>https://insider.btcpp.dev/p/antoine-poinsot-btc-insider-interviews</link><guid isPermaLink="false">https://insider.btcpp.dev/p/antoine-poinsot-btc-insider-interviews</guid><dc:creator><![CDATA[Matthew]]></dc:creator><pubDate>Thu, 10 Sep 2026 18:00:54 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/215068956/c50b6356c6bc0e7db9d60ab9f9cf43d3.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p><span>Throwback Thursday: Antoine Poinsot at Btcpp Austin 2025<br><br>He talks about the Great Consensus Cleanup (BIP54), political risk of protocol changes, foreshadows Lark (lightning channels in the Ark VTXOs), and the benefits of "rebindable signatures".</span></p>]]></content:encoded></item><item><title><![CDATA[Connor Aherne - BTC++ Insider Interviews]]></title><description><![CDATA[Connor Aherne is a, Alabama Bitcoin Club student and Bitcoin Policy Institute summer intern.]]></description><link>https://insider.btcpp.dev/p/connor-aherne-btc-insider-interviews</link><guid isPermaLink="false">https://insider.btcpp.dev/p/connor-aherne-btc-insider-interviews</guid><dc:creator><![CDATA[Matthew]]></dc:creator><pubDate>Wed, 09 Sep 2026 15:02:44 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/214888781/5e9b0b16ccbd7a3b34153db7231243da.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p><span>Connor Aherne is a, Alabama Bitcoin Club student and Bitcoin Policy Institute summer intern. <br><br>He did field research for his policy paper (with Dr. Margot Paez at Bitcoin++ consensus edition this summer, to discover the policy implications of soft forks such as the BIP110 debate.</span></p>]]></content:encoded></item><item><title><![CDATA[One-time signature schemes with Christian Lewe of Alpen Labs]]></title><description><![CDATA[Recorded in Toronto, Canada.]]></description><link>https://insider.btcpp.dev/p/one-time-signature-schemes-with-christian</link><guid isPermaLink="false">https://insider.btcpp.dev/p/one-time-signature-schemes-with-christian</guid><dc:creator><![CDATA[Matthew]]></dc:creator><pubDate>Wed, 09 Sep 2026 15:00:37 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/214894679/ca0c06231e7975caca3d67dd631bf938.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>Recorded in Toronto, Canada.</p><p>Christian Lewe, a researcher at Alpen Labs, explains the one-time signature schemes used in BitVM bridges: Lamport, Winternitz, and adaptor signatures. He describes how anti-chain Winternitz counters the malleability of ordinary hash chains, why these signatures support off-chain proof and fraud-proof workflows, and why BitVM currently needs them under Bitcoin Script&#8217;s opcode limitations.</p><p>The conversation then turns to the potential of `OP_CHECKSIGFROMSTACK` and Schnorr signatures, which could make the bridge construction more efficient if activated. Christian also discusses witness encryption, PIPEs v2, the difficulty of cryptographic research, and Alpen Labs&#8217; work toward simpler, more secure bridges.</p>]]></content:encoded></item><item><title><![CDATA[Egge Wants You to Pay with Bitcoin]]></title><description><![CDATA[Insider Edition talks to Egge, a prolific Cashu developer about how he's accelerating paying with bitcoin]]></description><link>https://insider.btcpp.dev/p/egge-wants-you-to-pay-with-bitcoin</link><guid isPermaLink="false">https://insider.btcpp.dev/p/egge-wants-you-to-pay-with-bitcoin</guid><dc:creator><![CDATA[Tuma (I WILL NEVER DM YOU)]]></dc:creator><pubDate>Wed, 09 Sep 2026 14:02:08 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!jVPa!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4999932b-d8b4-4b5f-b8f1-21a810520f25_1264x848.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Egge is one of the lead developers in the Cashu ecosystem. Former maintainer of cashu-ts, the TypeScript implementation of the protocol, he is now building Coco, a library that aims to make integrating Cashu as easy as possible.</em></p><p><em>We reached out to talk with him about bitcoin-based payments, which will be the main topic at the next Bitcoin++ conference in Berlin.</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!jVPa!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4999932b-d8b4-4b5f-b8f1-21a810520f25_1264x848.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!jVPa!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4999932b-d8b4-4b5f-b8f1-21a810520f25_1264x848.png 424w, https://substackcdn.com/image/fetch/$s_!jVPa!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4999932b-d8b4-4b5f-b8f1-21a810520f25_1264x848.png 848w, https://substackcdn.com/image/fetch/$s_!jVPa!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4999932b-d8b4-4b5f-b8f1-21a810520f25_1264x848.png 1272w, https://substackcdn.com/image/fetch/$s_!jVPa!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4999932b-d8b4-4b5f-b8f1-21a810520f25_1264x848.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!jVPa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4999932b-d8b4-4b5f-b8f1-21a810520f25_1264x848.png" width="1264" height="848" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4999932b-d8b4-4b5f-b8f1-21a810520f25_1264x848.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:848,&quot;width&quot;:1264,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2355647,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://insider.btcpp.dev/i/214722723?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4999932b-d8b4-4b5f-b8f1-21a810520f25_1264x848.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!jVPa!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4999932b-d8b4-4b5f-b8f1-21a810520f25_1264x848.png 424w, https://substackcdn.com/image/fetch/$s_!jVPa!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4999932b-d8b4-4b5f-b8f1-21a810520f25_1264x848.png 848w, https://substackcdn.com/image/fetch/$s_!jVPa!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4999932b-d8b4-4b5f-b8f1-21a810520f25_1264x848.png 1272w, https://substackcdn.com/image/fetch/$s_!jVPa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4999932b-d8b4-4b5f-b8f1-21a810520f25_1264x848.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p><strong>Hi Egge! Tell us a bit about yourself and what you are working on! What are you going to talk about in Berlin?</strong></p><p>I&#8217;m an open-source developer working mostly on Bitcoin payments and <a href="https://cashu.space/">Cashu</a>. My goal is to make Bitcoin payments accessible to anyone, enabling a more sovereign world.</p><p>A lot of my current work revolves around <a href="https://github.com/cashubtc/coco">Coco</a>, a TypeScript framework for building applications on top of Cashu. Cashu already provides really powerful payment rails, but there is still a lot of complexity involved in implementing a full wallet or payment system correctly. Coco tries to abstract a large part of that complexity while still giving developers control over how their application works.</p><p>In Berlin I&#8217;ll be doing a workshop showing how easy it can be to integrate Bitcoin payments into products using Cashu and Coco. I want developers to leave with the feeling that adding Bitcoin payments to an app or ecommerce product doesn&#8217;t have to be a massive undertaking anymore.</p><div><hr></div><p><strong>The topic of Bitcoin++ Berlin is payments. Where do you stand on the Bitcoin monetary-scale? Is Bitcoin more a Store of Value (savings) or a Medium of Exchange (payments)?</strong></p><p>Both are incredibly important, but personally I care even more about Bitcoin as a medium of exchange.</p><p>Bitcoin being a global, accessible, fair and equal form of money is what makes it so powerful. The store-of-value aspect is obviously important for building sustainable wealth, but the freedom to transact freely is even more fundamental to me.</p><p>If I had to choose between a world where Bitcoin becomes the dominant savings asset but everyone continues paying through fiat systems, and a world where hundreds of millions of people actually transact using Bitcoin-native payment rails, I would choose the latter.</p><p>That said, I think the distinction is mostly theoretical. I find it hard to imagine Bitcoin being adopted globally as a payment system without also establishing itself as a major global monetary asset and taking market share from other stores of value.</p><div><hr></div><p><strong>Currently, we can see both a lack of merchants accepting bitcoin and users spending it. Do you think it is more an economical problem &#8212; i.e. bitcoin exchange rate is continuously rising and people do not want to spend it &#8212; or a UX one &#8212; it is difficult to use and accept bitcoin?</strong></p><p>I think it is a combination of several things.</p><p>There are already very orange-pilled merchants who would like to accept Bitcoin, but the additional integration work, accounting, tax considerations and general operational complexity make it unattractive.</p><p>On the user side there are similar problems. People have to figure out how to convert fiat into Bitcoin, which wallet to use, which provider to trust, how custody works, what payment method they need and so on. Even terminology like addresses, invoices, payment requests, sats, Bitcoin, Lightning and ecash can become intimidating very quickly.</p><p>And then you have the classic chicken-and-egg problem. Merchants are more willing to do the work of adding Bitcoin if it lowers their fees or brings them additional customers. Users are more willing to learn how to pay with Bitcoin if they can actually use it in many places.</p><p>I don&#8217;t really buy the argument that people will not spend Bitcoin because it appreciates. People need to consume regardless of what currency they save in.</p><p>&#8220;Spend and replace&#8221; is a completely valid strategy: spend Bitcoin and use the fiat you would otherwise have spent to replace the Bitcoin. You can take that even further and simply get paid in Bitcoin.</p><p>I think the HODL movement has sometimes created this idea that spending Bitcoin is inherently bad. I disagree with that.</p><div><hr></div><p><strong>How do we make sure that Bitcoin is actually used as a payment method? How do we convince more merchants to accept it and more people to spend it?</strong></p><p>A big part of it is simply making the experience dramatically better.</p><p>We need Bitcoin payment systems that can compete with PayPal and Visa on UX. A normal person should not need to understand payment rails, liquidity management or protocol details just to pay for something.</p><p>I think we will increasingly see wallets and merchant applications dynamically choose between different payment mechanisms behind the scenes. <a href="https://github.com/bitcoin/bips/blob/master/bip-0321.mediawiki">BIP321</a> is already moving in this direction by allowing payment requests to contain several possible payment methods.</p><p>We experimented with this in <a href="https://github.com/cashubtc/Numo">Numo</a>, a mobile Cashu point-of-sale application. A merchant can present a single payment-request QR code and accept both Lightning and Cashu bearer payments. The merchant does not need to present different buttons or explain different protocols to the customer.</p><p>There are situations where understanding the underlying technology is absolutely critical. Cold storage is the obvious example: if you are protecting your life savings, you need to understand what you are doing.</p><p>But spending-money applications are different. We should be comfortable hiding complexity there.</p><p>At the same time, I do think we should actively explain why spending Bitcoin matters. Bitcoin does not become a widely used monetary system simply by everyone holding it forever.</p><div><hr></div><p><strong>You are one of the leading voices in the Cashu ecosystem. Do you think Cashu is the best attempt at making Bitcoin everyday money? What are the strongest advantages in using Cashu as money compared to other layers? What are its disadvantages?</strong></p><p>I don&#8217;t think there is an absolute best solution. Every payment system has trade-offs.</p><p>What I think Cashu does exceptionally well is UX. Representing money as a digital bearer asset enables interactions that feel much closer to physical cash.</p><p>You can make offline payments. You can literally put money into a message or an email. You can drop money into a digital tip jar. The receiver does not necessarily have to be online at the exact moment the payment is created.</p><p>Cashu can also interact with the wider Bitcoin ecosystem, so it does not need to exist as an isolated payment network.</p><p>Another major advantage is what it can do for developers. Cashu encapsulates an enormous amount of payment complexity, and the developer tooling has become very good. With libraries like <a href="https://github.com/cashubtc/cdk">CDK</a> and Coco, and increasingly capable AI development tools, building a functional Cashu wallet can genuinely become an afternoon project.</p><p>That accessibility is important to me. If we want thousands of applications experimenting with Bitcoin payments, developers need primitives they can actually build with.</p><p>The most obvious trade-off is custody. A Cashu mint is a custodian, and you have to trust it with the Bitcoin represented by the ecash it issues.</p><p>But Cashu is not supposed to be a vault. I think of it much more like the cash you carry in your pocket. Long-term savings belong in proper Bitcoin self-custody.</p><p>One useful property of Cashu is that the custodial risk can also be distributed across multiple independent mints. Instead of putting all your spending balance with one custodian, you can hold ecash from several.</p><p>There are also interesting approaches for reducing trust further. Federations are one option, although they introduce their own complexity. <a href="https://en.wikipedia.org/wiki/Trusted_execution_environment">TEEs</a> are another promising approach for reducing how much trust needs to be placed in the operator. There are a lot of experiments happening here, and I think we will learn over the next few years which models work best.</p><p>Another challenge is simply domain knowledge. Cashu makes many things technically easier, but users can still be confronted with Bitcoin terminology and then additional concepts such as ecash, tokens and mints.</p><p>That is ultimately a UX problem for us to solve. Users should not need to become protocol experts in order to spend money.</p><div><hr></div><p><strong>Other than Cashu, what are you most excited to see at Bitcoin++ Berlin?</strong></p><p>Definitely the <a href="https://btcpp.dev/berlin26/hackathon">hackathon</a>.</p><p>It is always incredibly fun seeing what people come up with when you put a lot of smart Bitcoin developers in one place and give them permission to experiment.</p><p>Some genuinely novel ideas and projects come out of these hackathons, including things nobody would have predicted beforehand. That experimentation is one of my favorite parts of Bitcoin++.</p><div><hr></div><p><em>We&#8217;d like to thank Egge for his availability for this interview. Would you like to attend Egge&#8217;s workshop and see what devs are working on? Join us in <a href="https://btcpp.dev/berlin26?code=TUMA20">Berlin</a> this October 1- 3 to talk about payments in Bitcoin!</em></p>]]></content:encoded></item><item><title><![CDATA[Liquid Hacked — Last Week in Bitcoin (Aug 31 - Sep 06)]]></title><description><![CDATA[Hi Insiders.]]></description><link>https://insider.btcpp.dev/p/liquid-hacked-last-week-in-bitcoin</link><guid isPermaLink="false">https://insider.btcpp.dev/p/liquid-hacked-last-week-in-bitcoin</guid><dc:creator><![CDATA[Tuma (I WILL NEVER DM YOU)]]></dc:creator><pubDate>Mon, 07 Sep 2026 14:02:01 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!cfBM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba614c75-a494-40d7-a82f-86615ef1f34d_1600x900.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Hi Insiders. This is Tuma, open-source reporter from the Insider Edition.</em></p><p><em>In this week&#8217;s update we feature the latest releases in the ecash ecosystem, Fedimint v0.12.0 and Cashu Dev Kit (CDK) v0.18.0.</em></p><p><em>We also cover the recent hack to the Liquid Network. Attackers, who stated to be whitehats, were able to stole 3998 bitcoin with a peg-out transaction leveraging a bug in the transaction validation logic.</em></p><p><em>We finally cover some other news, such as an implementation of multisig in Bitcoin Core GUI and a proposal to use silent payments in the coinbase transaction to pay miners for their hashrate.</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!cfBM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba614c75-a494-40d7-a82f-86615ef1f34d_1600x900.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!cfBM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba614c75-a494-40d7-a82f-86615ef1f34d_1600x900.jpeg 424w, https://substackcdn.com/image/fetch/$s_!cfBM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba614c75-a494-40d7-a82f-86615ef1f34d_1600x900.jpeg 848w, https://substackcdn.com/image/fetch/$s_!cfBM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba614c75-a494-40d7-a82f-86615ef1f34d_1600x900.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!cfBM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba614c75-a494-40d7-a82f-86615ef1f34d_1600x900.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!cfBM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba614c75-a494-40d7-a82f-86615ef1f34d_1600x900.jpeg" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ba614c75-a494-40d7-a82f-86615ef1f34d_1600x900.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:347184,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://insider.btcpp.dev/i/214551990?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba614c75-a494-40d7-a82f-86615ef1f34d_1600x900.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!cfBM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba614c75-a494-40d7-a82f-86615ef1f34d_1600x900.jpeg 424w, https://substackcdn.com/image/fetch/$s_!cfBM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba614c75-a494-40d7-a82f-86615ef1f34d_1600x900.jpeg 848w, https://substackcdn.com/image/fetch/$s_!cfBM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba614c75-a494-40d7-a82f-86615ef1f34d_1600x900.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!cfBM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba614c75-a494-40d7-a82f-86615ef1f34d_1600x900.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h1><strong>Highlights from the Bitcoin developer ecosystem</strong></h1><p><em>I spent 10+ hours in open-source developer calls in the Bitcoin ecosystem last week. Here is what caught my eye</em>:</p><ul><li><p><a href="https://github.com/fedimint/fedimint/releases/tag/v0.12.0">Fedimint release v0.12.0</a> is out with new v2 modules, support for Iroh v1.0, and more.</p><ul><li><p>During the weekly call, on Monday 31st, Fedimint developers discussed the release of Fedimint v0.12.0, called &#8220;Second Nature&#8221;.</p></li><li><p>The name of the release is linked to the fact that all the new v2 modules &#8212; lnv2, mintv2, and walletv2 &#8212; are now the default, with the older versions now labeled as &#8220;legacy&#8221;. Moreover, the latest version supports <a href="https://www.iroh.computer/blog/v1">Iroh v1.0</a>, the first stable release for the p2p networking stack.</p></li><li><p>v0.12.0 also improves the overall reliability of the system, reduces latency in Lightning payments, and allows recovery with no downtime and no blocking or stalling. Developers also released UniFFI bindings for Kotlin and Swift.</p></li></ul></li><li><p><a href="https://github.com/cashubtc/cdk/releases/tag/v0.18.0">Cashu Dev Kit (CDK) release v0.18.0</a> is out, bringing the implementation up-to-date with the latest protocol changes.</p><ul><li><p>During the weekly call, on Wednesday 2nd, CDK developers announced that they had just released the new version of the Cashu implementation, v0.18.0.</p></li><li><p>One of the most important changes is related to the mint configuration and settings. Previously, the mint configuration could be overridden by local settings and environment variables. v0.18.0 stores the authoritative settings in the primary mint database. The team provided a <a href="https://github.com/cashubtc/cdk/blob/v0.18.0/docs/migrations/v0.18.md">migration guide</a> for mint operators.</p></li><li><p>The release also adds support for animated QR codes (<a href="https://github.com/cashubtc/nuts/blob/main/16.md">NUT-16</a>), signature-based authentication for mint quote redemption (<a href="https://github.com/cashubtc/nuts/blob/main/20.md">NUT-20</a>), BOLT12 offers descriptions (<a href="https://github.com/cashubtc/nuts/blob/main/25.md">NUT-25</a>), and deterministic nonces for DLEQ for offline ecash (<a href="https://github.com/cashubtc/nuts/blob/main/12.md">NUT-12</a>).</p></li></ul></li></ul><div><hr></div><h1>A BIPs Update</h1><p><em>There was no newsworthy update in the last few days in the <a href="https://github.com/bitcoin/bips">BIP repository</a>. We&#8217;ll provide new updates as soon as a new BIP gets published or gets assigned a number.</em></p><div><hr></div><h1>Other News from the Bitcoin World</h1><ul><li><p><strong>Liquid Hacked</strong>: On Sunday 6th, news got around that the Liquid Network, Blockstream&#8217;s sidechain, had been hacked by whitehats. The attackers <a href="https://x.com/btcinsider__/status/2096688045235822986">stole 3998 bitcoin</a> from the Liquid bridge.</p><ul><li><p>Hackers contacted Blockstream directly <a href="https://mempool.space/tx/c103de95817b43f2df635ec6f35ff126ca26a7c6d20570c4b01866b2b3e69a19#flow=&amp;vout=0">onchain</a> using an OP_RETURN. The discussion went back and forth, with the attackers asking the company to fix the bug before returning the funds. Developers Sjors shared a <a href="https://gist.github.com/Sjors/9d24363e67529079cc2ae4305ff90fcd">gist</a> reporting all the discussion between hackers and Blockstream.</p></li><li><p>The bug seems to be connected to <a href="https://docs.liquid.net/docs/confidential-transactions">confidential transactions</a> (CT), one of the feature available on the Liquid network that allows a user to hide the amount and the type of asset being sent by default. Since CTs do not show the amount being spent, two types of proofs are needed to verify that a transaction is valid: a balance proof and a range proof. The former checks that the amounts of L-BTC in input and in output are the same. The latter, checks that an hidden output falls within a positive amount.</p></li><li><p>Calle provided a <a href="https://x.com/callebtc/status/2096877551884919120">possible explanation</a> of what happened. Basically, since the range proof is particularly expensive to compute, Liquid nodes can cache a successful proof in memory, stored by assigning a label called <strong>cache key</strong>. Attackers were able to build two transactions with colliding cache keys. The first one was a valid transaction, checked by nodes and stored. The second one, on the other hand, was an invalid transaction, effectively creating L-BTC out of thin air. However, having the same cache key, nodes did not perform all checks and made it pass as valid.</p></li><li><p>The situation is still evolving. Check out <a href="https://x.com/btcinsider__">BTC++ Insider Edition</a> X account for the latest updates</p></li></ul></li><li><p><strong>Silent Payments in Coinbase Transactions</strong>: Developer average_gary wrote a <a href="https://delvingbitcoin.org/t/silent-payments-coinbase/2833">post</a> on Delving Bitcoin explaining his idea to use silent payments to allow miners to get paid to different addresses for the provided hashrate without revealing an xpub.</p><ul><li><p>The proposal would require a dedicated BIP since it is not currently possible to use the silent payments protocol defined in <a href="https://github.com/bitcoin/bips/blob/master/bip-0352.mediawiki">BIP352</a> as it is. The author is looking for feedback on the idea before moving on to a formal draft.</p></li></ul></li><li><p><strong>Multisig in Bitcoin Core GUI</strong>: Developer sdbtc <a href="https://x.com/sndbtc/status/2095577106390372810">announced</a> that he was able to integrate multisig in the Bitcoin Core GUI by using Claude. He is now reviewing the code created by the LLM and polishing the implementation with the objective of opening a real PR in the repository.</p></li></ul><div><hr></div><h1>Reads from BTC++ Insider Edition</h1><ul><li><p><strong><a href="https://insider.btcpp.dev/p/bitpolito-how-italys-largest-bitcoin">BitPolito: How Italy&#8217;s Largest Bitcoin Student Org Is Passing the Reins to the Next Generation</a></strong></p></li><li><p><strong><a href="https://insider.btcpp.dev/p/dont-start-a-node-in-the-past-this">Don&#8217;t start a node in the past - This Week in Bitcoin Core #56</a></strong></p></li></ul><div><hr></div><p><em>Looking for an opportunity to join up with some bitcoin devs in person? Join us in <a href="https://btcpp.dev/berlin26?code=TUMA20">Berlin</a> this October 1- 3 to talk about payments in Bitcoin!</em></p>]]></content:encoded></item><item><title><![CDATA[Don't start a node in the past - This Week in Bitcoin Core #56]]></title><description><![CDATA[This week we make sure that nodes don&#8217;t have lagging clocks...]]></description><link>https://insider.btcpp.dev/p/dont-start-a-node-in-the-past-this</link><guid isPermaLink="false">https://insider.btcpp.dev/p/dont-start-a-node-in-the-past-this</guid><dc:creator><![CDATA[kevkevin]]></dc:creator><pubDate>Fri, 04 Sep 2026 14:01:12 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!MJw8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cee73e5-1dd4-4081-a559-6f40592a5154_1456x816.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Hello &#128075; folks, I&#8217;m Kevkevin. I&#8217;m an open-source developer and reporter for Insider Edition. Last week, I reviewed several pull requests from the <a href="https://github.com/bitcoin/bitcoin/pulls">Bitcoin Core</a> repo.<br><br>In <a href="https://github.com/hodlinator">hodlinator</a>&#8217;s headers-sync PR, if your system clock is so far behind the chain-start median time past that the unsigned commitment cap wraps, Core now aborts the node instead of eating low-work headers. Fresh datadirs hit this path. Existing chainstate already shuts down at load.</p><p><a href="https://github.com/sedited">Sedited</a> points at the <a href="https://github.com/bitcoin/bitcoin/milestone/84">32.0 milestone</a>, eight items are still open and branch-off is next week. <a href="https://github.com/pinheadmz">Pinheadmz</a> is still triaging agent findings on the new HTTP server. <br><br>Sipa did quote furszy: &#8220;Claude is down, sorry&#8221;, and fjahr asked if he forgot how to join IRC without agent help :). </p><p>The two PR&#8217;s that took the most review this week are the headers-sync abort, and a <code>-walletnotify</code> command-injection fix that the Red Team found.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!MJw8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cee73e5-1dd4-4081-a559-6f40592a5154_1456x816.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!MJw8!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cee73e5-1dd4-4081-a559-6f40592a5154_1456x816.png 424w, https://substackcdn.com/image/fetch/$s_!MJw8!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cee73e5-1dd4-4081-a559-6f40592a5154_1456x816.png 848w, https://substackcdn.com/image/fetch/$s_!MJw8!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cee73e5-1dd4-4081-a559-6f40592a5154_1456x816.png 1272w, https://substackcdn.com/image/fetch/$s_!MJw8!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cee73e5-1dd4-4081-a559-6f40592a5154_1456x816.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!MJw8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cee73e5-1dd4-4081-a559-6f40592a5154_1456x816.png" width="1456" height="816" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1cee73e5-1dd4-4081-a559-6f40592a5154_1456x816.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:816,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!MJw8!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cee73e5-1dd4-4081-a559-6f40592a5154_1456x816.png 424w, https://substackcdn.com/image/fetch/$s_!MJw8!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cee73e5-1dd4-4081-a559-6f40592a5154_1456x816.png 848w, https://substackcdn.com/image/fetch/$s_!MJw8!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cee73e5-1dd4-4081-a559-6f40592a5154_1456x816.png 1272w, https://substackcdn.com/image/fetch/$s_!MJw8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cee73e5-1dd4-4081-a559-6f40592a5154_1456x816.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h4><strong>Merged PR&#8217;s</strong></h4><h5><strong>Every week, several changes are officially added to Bitcoin Core. This week, </strong>multiple <strong>changes were merged. Here are some I found interesting this week.</strong></h5><ul><li><p><strong><a href="https://github.com/bitcoin/bitcoin/pull/35351">net: Disallow invalid HeadersSyncState due to lagging clock</a></strong> by <strong><a href="https://github.com/hodlinator">hodlinator</a></strong></p><p>Headers presync sizes <code>m_max_commitments</code> from the elapsed time since the chain-start median time plus <code>MAX_FUTURE_BLOCK_TIME</code>. If your local clock is more than that far <em>behind</em> chain-start median time past, elapsed goes negative, the unsigned cap wraps to something huge, and low-work headers keep coming instead of the peer getting dropped.<br></p><p>The old idea (#35208) was to clamp the cap to zero and let <code>HeadersSyncState</code> keep eating headers. This PR refuses to construct an invalid state at all and aborts the node. In practice, if you already have chainstate, startup already notices the lagging clock and shuts down first. A fresh datadir is the path that actually hits this. hodlinator filed #36134 to make that comment match reality, and that one merged too.</p><p></p></li><li><p><strong><a href="https://github.com/bitcoin/bitcoin/pull/36048">util: keep wallet names literal in notification commands</a></strong> by <strong><a href="https://github.com/l0rinc">l0rinc</a></strong><br>l0rinc fixed a v24 regression in <code>-walletnotify</code>.<br></p><p>On non-Windows, <code>%w</code> in the notify command is replaced with the shell-escaped wallet name. Since #25803, <code>ReplaceAll()</code> has been feeding that replacement through <code>std::regex_replace()</code>. Regex replacement treats <code>$'</code> as &#8220;the rest of the subject,&#8221; so a wallet name containing <code>$'</code> can smash the quoting and run extra shell as the node user.<br></p><p>This is not a P2P bug. You need an authenticated RPC caller who is allowed to create wallets. #35833 already started restricting control characters in new names; this one restores the literal, non-recursive contract <code>ReplaceAll()</code> that existed before the Boost-to-<code>std::regex</code> switch. The Red Team found it.</p></li></ul><h5><strong>There are always changes being updated and reviewed in real-time. Here are some notable PR&#8217;s that are still up and looking for reviews.</strong></h5><ul><li><p><strong><a href="https://github.com/bitcoin/bitcoin/pull/36096">rpc: avoid quadratic JSON construction when keys are unique</a></strong> by <strong><a href="https://github.com/l0rinc">l0rinc</a></strong></p></li></ul><p>l0rinc asked for a review in Thursday&#8217;s meeting. It is open, not a draft, and not Needs rebase. Last week&#8217;s prefetch PR (<a href="https://github.com/bitcoin/bitcoin/pull/36000">#36000</a>) is still open too, he said a reindex-chainstate is often &gt;50% faster now (about 30017s &#8594; 19609s on his HDD box). Branch-off is next week, so if you have one review slot, start here and keep #36000 in the other tab.</p><blockquote><p>Problem: <code>getprioritisedtransactions</code> lets node operators inspect fee adjustments. While building the response, the RPC checks each transaction ID against all previous IDs, even though duplicates are impossible. The same unnecessary search appears in a few other RPC responses built directly from <code>std::map</code> or <code>std::set</code> keys.</p><p>Fix: Each changed response key comes from an <code>std::map</code> or <code>std::set</code>, where keys are unique, so insertion can skip the linear <code>findKey()</code> call.</p></blockquote><p>On a Pi 4 his reproducer was almost a minute before the fix and about half that after. Same shape anywhere we build JSON from map/set keys.</p><div><hr></div><h4><strong>IRC meeting notes</strong></h4><h5><strong>Every week on Thursday, there is an IRC meeting. Here are some short notes from that meeting.</strong></h5><pre><code>--- Topic 1 ---

<strong>fjahr</strong>: #topic QA WG Update (brunoerg)
<strong>brunoerg</strong>: I ran a mutation analysis for the silent payments PR and got a positive feedback about the findings and many mutants were addressed. Now that the implementation is on master, I re-ran the analysis for sp code as part of the weekly run. It got 100% of mutation score (that's perfect) - I will probably run a full analysis to check if there is any leftover. Results can be seen at: https://secp256k1.space
<strong>brunoerg</strong>: I also re-ran the mutation analysis for src/script/interpreter.cpp, since it's critical code I generated all the possible mutants. I got over 1000 mutants for this file which only 80 of them survived. There are some PRs adding more test cases for the interpreter which I hope we will soon have full coverage of them.
<strong>brunoerg</strong>: Naiyoma is helping me to test the parallelization of the analysis, I hope to get it ready soon, it will make our mutation workflow faster and more practical.
<strong>brunoerg</strong>: Also, I appreciate feedback from kernel people in #647. the idea is doing differential fuzzing between the kernel and the Core's internals.
<strong>brunoerg</strong>: That's all
<strong>fjahr</strong>: cool, thanks!

--- Topic 2 ---

<strong>fjahr</strong>: #topic QML GUI WG Update (johnny9dev)
<strong>johnny9dev</strong>: continue to work on the staging branch and fixing issues
<strong>johnny9dev</strong>: thats all for now

--- Topic 3 ---

<strong>fjahr</strong>: #topic Benchmarking WG Update (l0rinc, andrewtoth)
<strong>l0rinc</strong>: A few of the quadratic iteration fixes were merged, #36096 is similar, review would be appreciated.
<strong>l0rinc</strong>: And as mentioned yesterday, #36000 was tuned a bit more, now a reindex-chainstate is often &gt;50% faster.
<strong>l0rinc</strong>: IBD is probably internet bandwidth bounded now, will experiment with parallel undo/block flushes to see if it helps.
<strong>l0rinc</strong>: Will also profile a neutered validation-less and UTXO-less node to see the remaining bottlenecks.
<strong>l0rinc</strong>: That's it from me, thanks

--- Topic 4 ---

<strong>fjahr</strong>: #topic Kernel WG Update (sedited)
<strong>sedited</strong>: Been getting some good review on #35641 . Also had some external projects say they would be interested in its capability.
<strong>sedited</strong>: and will circle around to the things request in the pr brunoerg linked before
<strong>sedited</strong>: that's all

--- Topic 5 ---

<strong>fjahr</strong>: Anything else to discuss? Possibly the release?
<strong>sedited</strong>: there's still a few items in the milestone: https://github.com/bitcoin/bitcoin/milestone/84
<strong>sedited</strong>: would be good to get them in before branch-off.
<strong>fjahr</strong>: Please review! Anything else?
<strong>pinheadmz</strong>: Im getting lots of agent findings in the new HTTP
<strong>pinheadmz</strong>: im triaging solutions before branch off
<strong>pinheadmz</strong>: so just keep em coming.
<strong>fjahr</strong>: #endmeeting</code></pre><p>Read here for the <a href="https://achow101.com/ircmeetings/2026/bitcoin-core-dev.2026-09-03_16_00.html">full meeting</a></p><div><hr></div><h4><strong>Releases</strong></h4><ul><li><p>No releases</p></li><li><p>v32.0 is coming soon&#8230;</p></li></ul><div><hr></div><blockquote><p>Thank you for reading. Be sure to tune in again next week for your updates on Bitcoin Core!</p></blockquote><p><em>If there are any comments, suggestions, or errors, do not hesitate to reach out or comment</em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://insider.btcpp.dev/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">bitcoin++'s Insider Edition is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[BitPolito: How Italy’s Largest Bitcoin Student Org Is Passing the Reins to the Next Generation]]></title><description><![CDATA[Francesco Pelle, after an incredible 2 years at the helm, talks to Insider about his time leading BitPolito and his work ushering in the student org&#8217;s next chapter]]></description><link>https://insider.btcpp.dev/p/bitpolito-how-italys-largest-bitcoin</link><guid isPermaLink="false">https://insider.btcpp.dev/p/bitpolito-how-italys-largest-bitcoin</guid><dc:creator><![CDATA[Tuma (I WILL NEVER DM YOU)]]></dc:creator><pubDate>Wed, 02 Sep 2026 14:03:12 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Csgb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85269bea-aada-4c4f-9668-c00bd583a71c_1264x848.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Csgb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85269bea-aada-4c4f-9668-c00bd583a71c_1264x848.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Csgb!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85269bea-aada-4c4f-9668-c00bd583a71c_1264x848.png 424w, https://substackcdn.com/image/fetch/$s_!Csgb!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85269bea-aada-4c4f-9668-c00bd583a71c_1264x848.png 848w, https://substackcdn.com/image/fetch/$s_!Csgb!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85269bea-aada-4c4f-9668-c00bd583a71c_1264x848.png 1272w, https://substackcdn.com/image/fetch/$s_!Csgb!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85269bea-aada-4c4f-9668-c00bd583a71c_1264x848.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Csgb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85269bea-aada-4c4f-9668-c00bd583a71c_1264x848.png" width="1264" height="848" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/85269bea-aada-4c4f-9668-c00bd583a71c_1264x848.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:848,&quot;width&quot;:1264,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1986652,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://insider.btcpp.dev/i/213528201?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85269bea-aada-4c4f-9668-c00bd583a71c_1264x848.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Csgb!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85269bea-aada-4c4f-9668-c00bd583a71c_1264x848.png 424w, https://substackcdn.com/image/fetch/$s_!Csgb!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85269bea-aada-4c4f-9668-c00bd583a71c_1264x848.png 848w, https://substackcdn.com/image/fetch/$s_!Csgb!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85269bea-aada-4c4f-9668-c00bd583a71c_1264x848.png 1272w, https://substackcdn.com/image/fetch/$s_!Csgb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85269bea-aada-4c4f-9668-c00bd583a71c_1264x848.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>Chances are if you&#8217;re in the Italian Bitcoin community, or perhaps even those outside of it, you&#8217;ve heard of the most popular Italian students club: Politecnico of Turin&#8217;s <a href="https://www.bitpolito.it/">BitPolito</a>. Or maybe you&#8217;ve seen their logo, a pixelated blue cow, somewhere at a Bitcoin conference.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!p7hV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9afd2753-ab7c-4d1d-9b86-ddd66bb887d2_4913x3127.svg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!p7hV!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9afd2753-ab7c-4d1d-9b86-ddd66bb887d2_4913x3127.svg 424w, https://substackcdn.com/image/fetch/$s_!p7hV!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9afd2753-ab7c-4d1d-9b86-ddd66bb887d2_4913x3127.svg 848w, https://substackcdn.com/image/fetch/$s_!p7hV!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9afd2753-ab7c-4d1d-9b86-ddd66bb887d2_4913x3127.svg 1272w, https://substackcdn.com/image/fetch/$s_!p7hV!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9afd2753-ab7c-4d1d-9b86-ddd66bb887d2_4913x3127.svg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!p7hV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9afd2753-ab7c-4d1d-9b86-ddd66bb887d2_4913x3127.svg" width="1456" height="927" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9afd2753-ab7c-4d1d-9b86-ddd66bb887d2_4913x3127.svg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:927,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:985,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/svg+xml&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://insider.btcpp.dev/i/213528201?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9afd2753-ab7c-4d1d-9b86-ddd66bb887d2_4913x3127.svg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!p7hV!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9afd2753-ab7c-4d1d-9b86-ddd66bb887d2_4913x3127.svg 424w, https://substackcdn.com/image/fetch/$s_!p7hV!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9afd2753-ab7c-4d1d-9b86-ddd66bb887d2_4913x3127.svg 848w, https://substackcdn.com/image/fetch/$s_!p7hV!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9afd2753-ab7c-4d1d-9b86-ddd66bb887d2_4913x3127.svg 1272w, https://substackcdn.com/image/fetch/$s_!p7hV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9afd2753-ab7c-4d1d-9b86-ddd66bb887d2_4913x3127.svg 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>BitPolito was founded in 2018 by three students of the Politecnico di Torino: Giorgio Rasetto, <a href="https://x.com/bitsalv">Salvatore Scorsone</a>, and <a href="https://btcpp.dev/whois/gitgab19">Gabriele Vernetti</a>. Inspired by their shared passion for the world&#8217;s most popular cryptocurrency, the three students united to bring a Italy&#8217;s first Bitcoin focused student&#8217;s club to life. Their objective: to bridge the gap between the academic world and the Bitcoin industry, helping members develop skills and create value for Bitcoin, by creating an educational environment focused on R&amp;D in computer science and mathematics, holding classes for students, and organizing events in Turin and around Italy.</p><p>No price noise, just <em>educational</em> signal.</p><p>According to the latest annual report (2025/2026), BitPolito has more 55 active members. Historically, around 220 members have been active in the student&#8217;s organization, and there are now more than 30 former students actually working in the Bitcoin industry. For example, Gabriele Vernetti, one of the founders &#8212; known in cyberspace as GitGab19 &#8212;, is now one of the main maintainers of the Stratum V2 project.</p><p>The association is always present to the biggest Bitcoin events around the world. Other than talks at several Bitcoin++ events, in 2024/2025 the BitPolito guys could be found at the Plan B Forum in Lugano, BTC Prague, Baltic Honeybadger, and BTCHEL, and the Barcelona Cypher Conference.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ejFc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7ff97dd-8d1d-4ea6-97a7-05246d2bac45_1024x1280.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ejFc!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7ff97dd-8d1d-4ea6-97a7-05246d2bac45_1024x1280.jpeg 424w, https://substackcdn.com/image/fetch/$s_!ejFc!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7ff97dd-8d1d-4ea6-97a7-05246d2bac45_1024x1280.jpeg 848w, https://substackcdn.com/image/fetch/$s_!ejFc!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7ff97dd-8d1d-4ea6-97a7-05246d2bac45_1024x1280.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!ejFc!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7ff97dd-8d1d-4ea6-97a7-05246d2bac45_1024x1280.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ejFc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7ff97dd-8d1d-4ea6-97a7-05246d2bac45_1024x1280.jpeg" width="1024" height="1280" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c7ff97dd-8d1d-4ea6-97a7-05246d2bac45_1024x1280.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1280,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:265227,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://insider.btcpp.dev/i/213528201?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7ff97dd-8d1d-4ea6-97a7-05246d2bac45_1024x1280.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ejFc!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7ff97dd-8d1d-4ea6-97a7-05246d2bac45_1024x1280.jpeg 424w, https://substackcdn.com/image/fetch/$s_!ejFc!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7ff97dd-8d1d-4ea6-97a7-05246d2bac45_1024x1280.jpeg 848w, https://substackcdn.com/image/fetch/$s_!ejFc!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7ff97dd-8d1d-4ea6-97a7-05246d2bac45_1024x1280.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!ejFc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7ff97dd-8d1d-4ea6-97a7-05246d2bac45_1024x1280.jpeg 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In Italy, their impact can be also felt outside of the Politecnico. They organize events all over Italy &#8212; more than 70 according to the latest report &#8212;, they take part in the Italian-only conferences, such as the BitCare Forum in Breascia, and provide education to anyone willing to learn. With their &#8220;Bitcoin al Liceo&#8221; program, BitPolito is bringing Bitcoin and the Cypherpunk culture to high school students around Turin, while &#8220;BitGeneration&#8221; brings together the best educators in the Italian ecosystem to provide everyone with a full understanding of Bitcoin directly at the Politecnico.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!X5WK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0cf7ecd7-c9b1-4f3e-98d6-3925b505101f_2246x2808.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!X5WK!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0cf7ecd7-c9b1-4f3e-98d6-3925b505101f_2246x2808.jpeg 424w, https://substackcdn.com/image/fetch/$s_!X5WK!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0cf7ecd7-c9b1-4f3e-98d6-3925b505101f_2246x2808.jpeg 848w, https://substackcdn.com/image/fetch/$s_!X5WK!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0cf7ecd7-c9b1-4f3e-98d6-3925b505101f_2246x2808.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!X5WK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0cf7ecd7-c9b1-4f3e-98d6-3925b505101f_2246x2808.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!X5WK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0cf7ecd7-c9b1-4f3e-98d6-3925b505101f_2246x2808.jpeg" width="1456" height="1820" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0cf7ecd7-c9b1-4f3e-98d6-3925b505101f_2246x2808.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1820,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:5920713,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://insider.btcpp.dev/i/213528201?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0cf7ecd7-c9b1-4f3e-98d6-3925b505101f_2246x2808.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!X5WK!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0cf7ecd7-c9b1-4f3e-98d6-3925b505101f_2246x2808.jpeg 424w, https://substackcdn.com/image/fetch/$s_!X5WK!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0cf7ecd7-c9b1-4f3e-98d6-3925b505101f_2246x2808.jpeg 848w, https://substackcdn.com/image/fetch/$s_!X5WK!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0cf7ecd7-c9b1-4f3e-98d6-3925b505101f_2246x2808.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!X5WK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0cf7ecd7-c9b1-4f3e-98d6-3925b505101f_2246x2808.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>BitPolito has also been invited to participate in an event organized by the Camera dei Deputati &#8212; one of the Italian parliamentary chambers &#8212; to present their view on what Bitcoin is and why it is important for a better future.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZeN7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7835658f-9a32-40e3-997a-b2cec7d58633_1023x1280.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZeN7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7835658f-9a32-40e3-997a-b2cec7d58633_1023x1280.jpeg 424w, https://substackcdn.com/image/fetch/$s_!ZeN7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7835658f-9a32-40e3-997a-b2cec7d58633_1023x1280.jpeg 848w, https://substackcdn.com/image/fetch/$s_!ZeN7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7835658f-9a32-40e3-997a-b2cec7d58633_1023x1280.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!ZeN7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7835658f-9a32-40e3-997a-b2cec7d58633_1023x1280.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZeN7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7835658f-9a32-40e3-997a-b2cec7d58633_1023x1280.jpeg" width="1023" height="1280" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7835658f-9a32-40e3-997a-b2cec7d58633_1023x1280.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1280,&quot;width&quot;:1023,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:196910,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://insider.btcpp.dev/i/213528201?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7835658f-9a32-40e3-997a-b2cec7d58633_1023x1280.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ZeN7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7835658f-9a32-40e3-997a-b2cec7d58633_1023x1280.jpeg 424w, https://substackcdn.com/image/fetch/$s_!ZeN7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7835658f-9a32-40e3-997a-b2cec7d58633_1023x1280.jpeg 848w, https://substackcdn.com/image/fetch/$s_!ZeN7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7835658f-9a32-40e3-997a-b2cec7d58633_1023x1280.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!ZeN7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7835658f-9a32-40e3-997a-b2cec7d58633_1023x1280.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p><a href="https://x.com/bitciccio">Franscesco Pelle</a> has been BitPolito&#8217;s president since July 2024. After two years successfully leading the club, he is now stepping down, leaving the role to a member of the next generation. Francesco recently completed his academic journey in Management Engineering, and is graduating from the Politecnico. While his passion for Bitcoin and the BitPolito is as strong as ever, he is ready to move forward to his new chapter of life: &#8220;My main interests are entrepreneurship and product management. I currently work as a product manager at a startup, and I want to continue developing my skills in this field&#8221;, he says.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Bbuz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3bf780a-fad5-4f46-8fa8-565d66cb57b5_2560x1707.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Bbuz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3bf780a-fad5-4f46-8fa8-565d66cb57b5_2560x1707.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Bbuz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3bf780a-fad5-4f46-8fa8-565d66cb57b5_2560x1707.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Bbuz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3bf780a-fad5-4f46-8fa8-565d66cb57b5_2560x1707.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Bbuz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3bf780a-fad5-4f46-8fa8-565d66cb57b5_2560x1707.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Bbuz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3bf780a-fad5-4f46-8fa8-565d66cb57b5_2560x1707.jpeg" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d3bf780a-fad5-4f46-8fa8-565d66cb57b5_2560x1707.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:673264,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://insider.btcpp.dev/i/213528201?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3bf780a-fad5-4f46-8fa8-565d66cb57b5_2560x1707.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Bbuz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3bf780a-fad5-4f46-8fa8-565d66cb57b5_2560x1707.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Bbuz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3bf780a-fad5-4f46-8fa8-565d66cb57b5_2560x1707.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Bbuz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3bf780a-fad5-4f46-8fa8-565d66cb57b5_2560x1707.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Bbuz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3bf780a-fad5-4f46-8fa8-565d66cb57b5_2560x1707.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><blockquote><p>&#8220;<em>There is no single moment that I would describe as the most important one. Serving as president of BitPolito has been one of the most rewarding experiences of my journey so far. It was both a privilege and a responsibility to be part of a group of people united by values that I consider fundamental, starting with freedom and the other principles at the heart of Bitcoin.&#8221;</em></p></blockquote><p>Giorgio Rasetto, one of the founders, and the rest of BitPolito&#8217;s OGs personally chose Francesco as the new president in 2024, when Giorgio himself completed his academic journey and decided to focus on his Bitcoin career. &#8220;They selected the person they believe is best suited to ensure continuity in the team&#8217;s activities, responsibilities, and leadership,&#8221; Francesco says, pointing out that he &#8220;had also demonstrated a strong commitment to BitPolito and its mission.&#8221; This seems to have reassured the founders they were entrusting someone who genuinely cared about what they were building.</p><p>Being the first president outside of the circle of the original founders, continuity has been one of the most important focuses of Francesco&#8217;s term. How do you make sure that the ethos, the values, and the ideas that led to BitPolito will remain intact, even after the founders are gone? &#8220;My main goal was to ensure BitPolito&#8217;s continuity and allow the work built over the previous years to continue. Today, the team includes highly motivated people who genuinely care about the project.&#8221;</p><p>One of the best ways to ensure continuity is through education. New members are not always operational until they have absorbed what Bitcoin is really about. Moreover, the structural organization has been made so that new members can easily integrate with the ongoing activities and the association in general.</p><blockquote><p><em>&#8220;The president is responsible for providing leadership and maintaining an overall view of the team&#8217;s activities. The president does not hold exclusive decision-making power: they are part of a board where decisions and responsibilities are shared with the heads of the team&#8217;s internal divisions.&#8221;</em></p></blockquote><p>The role of the presidency in BitPolito is a high-profile one. Other than giving a common direction to the organization and making sure that all the important initiative are completed on time, the president is responsible for managing institutional relationships with companies, projects, and, most importantly, with the Politecnico itself. During his term, Francesco was able to secure &#8220;significantly more financial support from Politecnico di Torino than in the past,&#8221; &#8212; something he is proud of &#8212; so that the members could continue attending events and travelling across Europe, promote both BitPolito and the Politecnico, and strengthen the relationships they had built over the years.</p><div><hr></div><p>Francesco is proud of everything he has done during his presidency. He is proud of how BitPolito has impacted the Italian Bitcoin scene and how their events have allowed many people to get a closer look to Bitcoin and get fascinated by the ideas behind it. &#8220;Discovering Bitcoin can have a profound impact on someone&#8217;s life, and I believe that BitPolito has helped create that change for many people in Italy over time,&#8221; he says. Most importantly, though, he is proud of having been able to remain true to himself while &#8220;creating an environment where people could feel at home, take an active role, and freely bring forward their own initiatives.&#8221;</p><blockquote><p><em>&#8220;I do not have any real regrets. There are certainly things I would have liked to do better or spend more time on, but they do not change how I feel about the overall experience. I am satisfied with what I did, and I am confident that the team will continue in the best possible way under its new leadership.&#8221;</em></p></blockquote><p>Some things remain undone, like creating a more clearly defined and robust structure for the team&#8217;s internal processes and activities. Francesco is not worried, though. He is sure that the new president and the team will be able to fill this gap and continue on the same track of the people before them.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!PkEY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed644fde-1efc-4dd2-80bd-6e1af7e6c5c5_1032x1280.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!PkEY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed644fde-1efc-4dd2-80bd-6e1af7e6c5c5_1032x1280.jpeg 424w, https://substackcdn.com/image/fetch/$s_!PkEY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed644fde-1efc-4dd2-80bd-6e1af7e6c5c5_1032x1280.jpeg 848w, https://substackcdn.com/image/fetch/$s_!PkEY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed644fde-1efc-4dd2-80bd-6e1af7e6c5c5_1032x1280.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!PkEY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed644fde-1efc-4dd2-80bd-6e1af7e6c5c5_1032x1280.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!PkEY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed644fde-1efc-4dd2-80bd-6e1af7e6c5c5_1032x1280.jpeg" width="1032" height="1280" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ed644fde-1efc-4dd2-80bd-6e1af7e6c5c5_1032x1280.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1280,&quot;width&quot;:1032,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:271287,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://insider.btcpp.dev/i/213528201?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed644fde-1efc-4dd2-80bd-6e1af7e6c5c5_1032x1280.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!PkEY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed644fde-1efc-4dd2-80bd-6e1af7e6c5c5_1032x1280.jpeg 424w, https://substackcdn.com/image/fetch/$s_!PkEY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed644fde-1efc-4dd2-80bd-6e1af7e6c5c5_1032x1280.jpeg 848w, https://substackcdn.com/image/fetch/$s_!PkEY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed644fde-1efc-4dd2-80bd-6e1af7e6c5c5_1032x1280.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!PkEY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed644fde-1efc-4dd2-80bd-6e1af7e6c5c5_1032x1280.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>The new president has already been chosen. <a href="https://linkedin.com/in/lucavis">Luca Visconti</a>, former Project Manager for the AI team, will take the presidency soon. The handover has already started and Francesco is delighted about his successor.</p><blockquote><p><em>&#8220;I was impressed by how active he was and by the dedication with which he approached the responsibilities of the role&#8221;</em></p></blockquote><p>According to Francesco, after years of expanding the network outside of the borders of Turin, the new president will have to focus the association back to where it all began. Engaging students, spread Bitcoin awareness among them, and grow the team.</p><div><hr></div><p><em>Bitcoin++ Insider Edition would like to thank BitPolito president Francesco Pelle for his availability and wishes him a bright future for his Bitcoin career. We also would like to congratulate Luca Visconti for his new role and wish him a term full of success and satisfaction.</em></p>]]></content:encoded></item><item><title><![CDATA[Glass Coins — Last Week in Bitcoin (Aug 24 - 30)]]></title><description><![CDATA[Hi Insiders.]]></description><link>https://insider.btcpp.dev/p/glass-coins-last-week-in-bitcoin</link><guid isPermaLink="false">https://insider.btcpp.dev/p/glass-coins-last-week-in-bitcoin</guid><dc:creator><![CDATA[Tuma (I WILL NEVER DM YOU)]]></dc:creator><pubDate>Mon, 31 Aug 2026 14:03:22 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!ZkX7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef38fbec-ea28-465c-8187-74bbf93fb1c6_1600x900.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Hi Insiders. This is Tuma, open-source reporter from the Insider Edition.</em></p><p><em>In this week&#8217;s update we feature nutroot secrets, the latest improvement to the Cashu protocol, which allows spending conditions to be included directly in the secret.</em></p><p><em>We also cover the first Shielded CSV developer call, where devs provided an overview of the high-level architecture. The team also announced that the protocol was renamed Glass Coins.</em></p><p><em>Finally, we discuss the most interesting news from the Bitcoin ecosystem. In particular, we cover BIP SHRINCS, the vulnerabilities found in Core-lightning, and the discontinuation of the Hardware Wallet Interface (HWI) library.</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZkX7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef38fbec-ea28-465c-8187-74bbf93fb1c6_1600x900.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZkX7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef38fbec-ea28-465c-8187-74bbf93fb1c6_1600x900.jpeg 424w, https://substackcdn.com/image/fetch/$s_!ZkX7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef38fbec-ea28-465c-8187-74bbf93fb1c6_1600x900.jpeg 848w, https://substackcdn.com/image/fetch/$s_!ZkX7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef38fbec-ea28-465c-8187-74bbf93fb1c6_1600x900.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!ZkX7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef38fbec-ea28-465c-8187-74bbf93fb1c6_1600x900.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZkX7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef38fbec-ea28-465c-8187-74bbf93fb1c6_1600x900.jpeg" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ef38fbec-ea28-465c-8187-74bbf93fb1c6_1600x900.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:347184,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://insider.btcpp.dev/i/213525049?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef38fbec-ea28-465c-8187-74bbf93fb1c6_1600x900.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ZkX7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef38fbec-ea28-465c-8187-74bbf93fb1c6_1600x900.jpeg 424w, https://substackcdn.com/image/fetch/$s_!ZkX7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef38fbec-ea28-465c-8187-74bbf93fb1c6_1600x900.jpeg 848w, https://substackcdn.com/image/fetch/$s_!ZkX7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef38fbec-ea28-465c-8187-74bbf93fb1c6_1600x900.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!ZkX7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef38fbec-ea28-465c-8187-74bbf93fb1c6_1600x900.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h1><strong>Highlights from the Bitcoin developer ecosystem</strong></h1><p><em>I spent 10+ hours in open-source developer calls in the Bitcoin ecosystem last week. Here is what caught my eye</em>:</p><ul><li><p>Cashu devs are working on nutroot secrets, a new way to express spending conditions inspired by taproot.</p><ul><li><p>During the monthly community call, on Thursday 27th, Cashu developers discussed the latest changes to the protocol specifications (NUTs). Notably, discussion focused around <a href="https://github.com/cashubtc/nuts/pull/421">PR421</a>, which introduces the so-called <strong>nutroot secrets</strong>. The PR has not been merged yet, since devs are waiting for the different projects to implement this feature.</p></li><li><p>Nutroot secrets change the way the protocol manages spending conditions. Instead of relying on a separate JSON file, the <code>secret</code> commits to a merkle tree which includes all the different spending conditions.</p></li><li><p>While nutroot secrets are clearly inspired by how taproot works in Bitcoin, developers clarified that only the commitment structure has been used and little else. No taproot property should be taken for granted.</p></li><li><p>Nutroot secrets comes with a new cryptographic algorithm. Developers decided to migrate to a new curve, BLS12-381, from the current scheme using secp256k1. This is because BLS makes signature publicly verifiable. The new algorithm is being introduced through <a href="https://github.com/cashubtc/nuts/pull/371">PR371</a>.</p></li></ul></li><li><p>Shielded CSV has been renamed Glass Coins, and promises a better transaction throughput on Bitcoin with improved privacy.</p><ul><li><p>On Thursday 27th, <a href="https://btcpp.dev/whois/robin-linus">Robin Linus</a>, <a href="https://btcpp.dev/whois/jonasnick">Jonas Nick</a>, and <a href="https://btcpp.dev/whois/liam-eagen">Liam Eagen</a> held the first developer call for Shielded CSV, a private payments protocol designed for maximum throughput and minimal latency.</p></li><li><p>The protocol is based on Client-side Validation (CSV), a technique that allows users to validate transactions off-chain, while relying on on-chain transactions only to prevent double-spending. The protocol comes with a minimal on-chain footprint.</p></li><li><p>The founders announced that the protocol had been renamed Glass Coins and shared a <a href="https://hackmd.io/H7BO61ART0CazAh752K2eQ">specifications file</a> containing all the high-level information about it.</p></li></ul></li></ul><div><hr></div><h1>A BIPs Update</h1><p><em>There was no newsworthy update in the last few days in the <a href="https://github.com/bitcoin/bips">BIP repository</a>. We&#8217;ll provide new updates as soon as a new BIP gets published or gets assigned a number.</em></p><div><hr></div><h1>Other News from the Bitcoin World</h1><ul><li><p><strong>A BIP for SHRINCS</strong>: Blockstream&#8217;s Head of Research Jonas Nick <a href="https://x.com/n1ckler/status/2092740384938226107">announced</a> the first draft of <a href="https://github.com/SHRINCS/shrincs-bip/blob/main/SHRINCS.md">BIP SHRINCS</a>, the first proposal for a post-quantum signature scheme for Bitcoin.</p><ul><li><p>The proposed scheme, called SHRINCS, provides the ability to obtain small signatures &#8212; in the context of post-quantum cryptography &#8212; of 548 bytes. It does so by using a stateful signature scheme &#8212; smaller signatures, but you must keep track of used keys (state) &#8212;, while giving the user the possibility to fall back to a stateless scheme in case the state is lost, at the cost of bigger signatures ( &gt; 5kB).</p></li><li><p>If you want to know more about SHRINCS, the Insider published a <a href="https://insider.btcpp.dev/p/how-to-make-smaller-post-quantum">deep dive on SHRINCS</a> some months ago. We also published a <a href="https://insider.btcpp.dev/p/bitcoin-shrimps-how-blockstreams">deep dive on SHRIMPS</a>, a proposal to minimize risks in a post-quantum world that can be combined with SHRINCS.</p></li></ul></li><li><p><strong>Vulnerabilities on CLN</strong>: Last week, Core-lightning contributors announced that several vulnerabilities had been found in the Lightning implementation. According to Christian Decker, no known vulnerability can be leveraged to steal funds.</p><ul><li><p>Christian Decker also <a href="https://x.com/Snyke/status/2092989040098181170">provided</a> information about the approach that CLN was following to address the vulnerabilities. The team will provide an embargoed release by publishing signed binaries without making the source code available. 14 days after the release, developers will publish the source code, which can be used by anyone to verify the released binaries thanks to their reproducible build system.</p></li><li><p>The patch release <a href="https://github.com/ElementsProject/lightning/releases/tag/v26.06.7">v26.06.7</a> was published on August 28th. The team invited anyone running a CLN to upgrade as soon as possible. In case anyone wants to wait for the source code to be released before upgrading, the suggestion is to restart the node using the <code>--offline</code> command, which allows the node to cut out external connections, without losing on-chain enforcement against potential cheating peers.</p></li></ul></li><li><p><strong>Goodbye HWI</strong>: Bitcoin Core contributor Ava Chow <a href="https://github.com/bitcoin-core/HWI/issues/850">announced</a> that the Hardware Wallet Interface (HWI) library &#8212; which enables support to hardware signers in Bitcoin Core &#8212; will be put in maintenance mode. This means that no new functionality will be added from now on, except for MuSig2 which is currently under development.</p><ul><li><p>One of the reason behind the choice, other than being a solo-dev project, is the fact that it is developed in Python and it does not allow for reproducible builds. This means it cannot be shipped with the whole Bitcoin Core package.</p></li><li><p><a href="https://github.com/wizardsardine/bhwi">BHWI</a> &#8212; developed by Wizardsardine &#8212; has been chosen as the possible successor to HWI. The library is built in Rust and it already supports the major hardware signers on the market.</p></li></ul></li></ul><div><hr></div><p><em>Looking for an opportunity to join up with some bitcoin devs in person? Join us in <a href="https://btcpp.dev/berlin26?code=TUMA20">Berlin</a> this October 1- 3 to talk about payments in Bitcoin!</em></p>]]></content:encoded></item><item><title><![CDATA[Bitcoin SHRIMPS - How Blockstream’s Latest Quantum Proposal Looks to Minimize Risks]]></title><description><![CDATA[Introduction]]></description><link>https://insider.btcpp.dev/p/bitcoin-shrimps-how-blockstreams</link><guid isPermaLink="false">https://insider.btcpp.dev/p/bitcoin-shrimps-how-blockstreams</guid><dc:creator><![CDATA[Tuma (I WILL NEVER DM YOU)]]></dc:creator><pubDate>Sat, 29 Aug 2026 14:04:15 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!FKfu!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f775105-74da-4b62-a64a-494ce26bc075_1376x768.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!FKfu!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f775105-74da-4b62-a64a-494ce26bc075_1376x768.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!FKfu!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f775105-74da-4b62-a64a-494ce26bc075_1376x768.jpeg 424w, https://substackcdn.com/image/fetch/$s_!FKfu!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f775105-74da-4b62-a64a-494ce26bc075_1376x768.jpeg 848w, https://substackcdn.com/image/fetch/$s_!FKfu!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f775105-74da-4b62-a64a-494ce26bc075_1376x768.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!FKfu!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f775105-74da-4b62-a64a-494ce26bc075_1376x768.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!FKfu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f775105-74da-4b62-a64a-494ce26bc075_1376x768.jpeg" width="1376" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1f775105-74da-4b62-a64a-494ce26bc075_1376x768.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:1376,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:865118,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://insider.btcpp.dev/i/213259026?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f775105-74da-4b62-a64a-494ce26bc075_1376x768.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!FKfu!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f775105-74da-4b62-a64a-494ce26bc075_1376x768.jpeg 424w, https://substackcdn.com/image/fetch/$s_!FKfu!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f775105-74da-4b62-a64a-494ce26bc075_1376x768.jpeg 848w, https://substackcdn.com/image/fetch/$s_!FKfu!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f775105-74da-4b62-a64a-494ce26bc075_1376x768.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!FKfu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f775105-74da-4b62-a64a-494ce26bc075_1376x768.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Introduction</h2><p>It&#8217;s 2034 and mid-day on a Thursday. Your mom just called, she needs some urgent help paying a ransom to get access to her emails and bank passwords &#8212; someone&#8217;s locked her computer. You go to find your hardware wallet only to discover that your dog just destroyed your &#8216;primary&#8217; signing device. Luckily, you moved your funds back in 2028 to a new key format that Blockstream Research launched in 2026, SHRIMPS, which will let you use your backup key to sign for your funds without a problem and without spending all the available balance for fees.</p><p>Backing up wallet state is a big issue for post-quantum hash-based signatures. Blockstream Research&#8217;s latest update is a push in the direction of better, stateless backups without giving up gains in conserving blockspace.</p><div><hr></div><p>The previous Blockstream Research post-quantum signature scheme was reported on by Insider Edition. Our <a href="https://insider.btcpp.dev/p/how-to-make-smaller-post-quantum">deep dive on SHRINCS</a>, a quantum-resistant scheme combining both <a href="https://insider.btcpp.dev/i/197656976/stateful-and-stateless">stateful and stateless</a> hash-based signatures shows how stateful and stateless schemes can be combined in a single signature. Stateful schemes allow for smaller signatures, at the cost of needing to keep track of which signatures have been already used (this is the &#8216;state&#8217; you&#8217;re tracking).</p><p>If the record of what signatures have already been made is lost, like in our opening horror story, you can no longer use the keys without risking compromising their security, which would allow someone else to move your funds.</p><p>On the other hand, we have stateless signing schemes. These can be easily restored from a static backup such as a seed phrase, but the signatures they produce are quite large &#8212; you trade cheap onchain signatures for a guarantee of being able to use it if lose your device.</p><p>SHRINCS, <a href="https://blog.blockstream.com/op_checkshrincs-a-hash-based-signature-opcode-for-post-quantum-bitcoin/">Blockstream Research&#8217;s first</a> post-quantum (PQ) signature proposal, fuses a stateful and stateless scheme to give you the best of both worlds. The combined signature scheme uses the stateful scheme which produces smaller signatures for ordinary operations, but falls back to the stateless, more expensive signatures, if your signing history is lost. SHRINCS&#8217;s stateless signing mode removes the risk of producing weak or forgeable signatures from lost state, while allowing you to benefit from smaller, stateful signatures in the default case.</p><p>On March 27th, Director of Blockstream Research <a href="https://x.com/https://btcpp.dev/whois/jonasnick">Jonas</a> <a href="https://x.com/n1ckler">Nick</a> introduced a new scheme called <a href="https://delvingbitcoin.org/t/shrimps-2-5-kb-post-quantum-signatures-across-multiple-stateful-devices/2355">SHRIMPS</a> on the popular technical forum, Delving Bitcoin. SHRIMPS is another PQ signature scheme proposal. As a product of one of Bitcoin&#8217;s most experienced research labs, it aims to improve on the earlier SHRINCS proposal.</p><p>By default, a SHRINCS backup signing device would default to using the stateless signing mechanism. In this case, your keys lose the ability to produce smaller signatures, moving from 324 bytes per signature to up to 8KB, a 25x increase in on-chain weight. This is problematic, given that you pay for every byte used in a bitcoin transaction. Backup signing devices, if used, would produce 25x more expensive transactions.</p><p>SHRIMPS, the latest proposal, aims to optimize the fallback option of SHRINCS. Instead of having a single fallback option, SHRIMPS would allow user&#8217;s backup devices to sign in a compact form until a threshold number of signatures is reached, and only once the limit on smaller signatures is reached, falling back to the more expensive, larger signature signing option.</p><h3>Basics of SHRIMPS</h3><p>The construction of SHRIMPS combines <strong>two</strong> instances of <a href="https://insider.btcpp.dev/p/sphincs">SPHINCS+</a>, a stateless hash-based PQ signature scheme. SPHINCS+ is complex. It&#8217;s constructed using several WOTS+ and XMSS nested trees to produce a single quantum safe key-pair. A SPHINCS+ key-pair can be used to sign many messages safely.</p><p>The depth of navigating the SPHINCS+ hash tree to locate the public/private key is what contributes to the large size of SPHINCS+ stateless signatures. The statelessness comes from the low probability of ever picking the same path in the tree again, at random. However, there is an upper bound to how many signatures can be produced in a SPHINCS+ tree before the odds of picking the same path again goes above what is considered &#8216;safe&#8217;.</p><p>In the SPHINCS+ literature, <code>q_s</code>is this upper limit. It&#8217;s the bound on the number of signatures that can be securely produced under a single SPHINCS+ key tree. <code>q_s</code> also governs the depth of the nested SPHINCS+ trees. So a smaller <code>q_s</code> means smaller resulting signatures, as it takes less data to describe the path through the SPHINCS+ forest. A smaller tree means less signatures that can be safely produced, but also less data per signature.</p><p>SHRIMPS uses this <code>q_s</code> to create two different SPHINCS+ key trees, and then binds them together into a single key, which can sign using either of the two SPHINCS+ trees. The trees only differ on the value of their <code>q_s</code> parameter: The first instance, referred to as compact path, uses a low <code>q_s</code>, which allows for smaller, but very limited number of signatures; the second instance uses a larger <code>q_s</code>. It produces much larger signatures, but can sign an almost infinite number of times.</p><p>Since both options are using SPHINCS+, both tree options are independently stateless. Unlike in SHRINCS where on one path you must remember what you&#8217;ve signed, SHRIMPS&#8217; paths only need to remember how many times the lower-bound SPHINCS+ tree has been used.</p><p>According to Nick, for the compact instance <code>q_s = 2^10</code> would be a good, conservative bound &#8212; providing around 1024 signatures &#8212;, while the fallback instance should be implemented with a sufficiently large parameter, such as <code>q_s = 2^40</code> or <code>q_s = 2^64</code> &#8212; an upper bound of around 1.85 x 10^19 signatures.</p><p>The SHRIMPS public key <code>p_k</code> is the hash of the public keys of each of the two SPHINCS+ treesets. A signature consists of a SPHINCS+ signature under the chosen instance <code>s_k1</code> and the public key of the other <code>p_k2</code>. The verifier reconstructs the signing instance&#8217;s public key <code>p_k1</code> from the SPHINCS+ signature, hashes <code>p_k1</code> and <code>p_k2</code> to reconstruct the combined public key, and compares it to the known SHRIMPS public key, <code>p_k</code>.</p><p>When initializing a new device by providing a seed, it will deterministically derive keys for each of the two SPHINCS+ instances. Each device will have its own, independent, persistent state to check whether the compact path has already been used or not.</p><h3>How Many Signatures?</h3><p>Assuming that the compact signature can be used to sign at most once for every device, <code>q_s</code> basically becomes the upper limit to the number of devices that could be initialized, <code>n_dev</code>. Setting <code>q_s = n_dev = 2^10</code> means giving the user the possibility to initialize more than one thousand devices, which seems a lot, even in the most pessimistic cases. Hopefully, no one would lose access or break a device more than one thousand times!</p><p>The &#8220;budget&#8221; could also be expanded to provide each device with more than one compact-path signature to be used. For example, setting <code>n_devsigs = 2^4</code> would provide the possibility to sign 16 times with the compact instance with each device, nevertheless resulting in a signature smaller than 3KB. In this case, the parameter would be set to <code>q_s = n_dev x n_devsigs</code> .</p><p>As we said, each device needs to store an independent counter to decide whether to use the compact signature or not. The counter will be <code>log2&#8289;(n_devsigs + 1)</code> bits in size, depending on the number of signatures available for each device.</p><p>In the simplest case &#8212; one device, one compact signature &#8212; the signing flow would require to check whether the independent, single-bit counter is <code>0</code> or <code>1</code>. In the first case, the device will sign using the compact SPHINCS+, resulting in a 2.5KB signature at 128bit security. Otherwise, it falls back to the larger instance. In case <code>n_devsigs &gt; 1</code> , the device will be able to use the compact signatures several time until exhaustion &#8212; 16, in case <code>n_devsigs = 2^4</code>.</p><p>If the number of compact-path signatures exceeds the <code>q_s</code> budget, security does not break down immediately. Instead, it degrades gradually, as the the table provided by Nick clearly shows. With a budget set to <code>q_s = 2 ^10</code> , the security of the scheme is 128.0 bits. Using <code>2^11</code> signatures doesn&#8217;t degrade security, which only start to drop tp 125.1 bits when signing with the compact scheme <code>2^12</code> times (i.e. 4 times the available budget).</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!R6bT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73c4a264-9c47-484e-928b-e689351217cf_343x250.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!R6bT!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73c4a264-9c47-484e-928b-e689351217cf_343x250.png 424w, https://substackcdn.com/image/fetch/$s_!R6bT!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73c4a264-9c47-484e-928b-e689351217cf_343x250.png 848w, https://substackcdn.com/image/fetch/$s_!R6bT!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73c4a264-9c47-484e-928b-e689351217cf_343x250.png 1272w, https://substackcdn.com/image/fetch/$s_!R6bT!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73c4a264-9c47-484e-928b-e689351217cf_343x250.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!R6bT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73c4a264-9c47-484e-928b-e689351217cf_343x250.png" width="343" height="250" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/73c4a264-9c47-484e-928b-e689351217cf_343x250.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:250,&quot;width&quot;:343,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:15972,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://insider.btcpp.dev/i/213259026?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73c4a264-9c47-484e-928b-e689351217cf_343x250.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!R6bT!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73c4a264-9c47-484e-928b-e689351217cf_343x250.png 424w, https://substackcdn.com/image/fetch/$s_!R6bT!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73c4a264-9c47-484e-928b-e689351217cf_343x250.png 848w, https://substackcdn.com/image/fetch/$s_!R6bT!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73c4a264-9c47-484e-928b-e689351217cf_343x250.png 1272w, https://substackcdn.com/image/fetch/$s_!R6bT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73c4a264-9c47-484e-928b-e689351217cf_343x250.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>Putting it all together</h3><p>As previously said, the aim of SHRIMPS is to improve on the stateful scheme side of SHRINCS to provide a safe path towards funds recovery. When using SHRINCS, if a single signing device is lost, the scheme allows the user to recover its keys using a static backup. However, it will default to use the heavy stateless scheme as soon as the state for the smaller signature scheme is lost.</p><p>SHRIMPS provides an intermediate step between the lean stateful signatures (324 bytes) and the huge stateless ones (~8KB), by allowing for a series of devices, each which can track their state independently and produce smaller SPHINCS+ signatures until the counter expires.</p><p>Putting together SHRINCS and SHRIMPS would result in the following workflow:</p><ul><li><p>The first device is initialized, and the stateful scheme is used to sign any transaction. The stateful scheme is used until the state is known, to avoid breaking the cryptographic assumptions of the scheme. Each signature is 324bytes in size.</p></li><li><p>Once the state is lost (i.e. first device is no more usable), a new device is initialized. The compact SPHINCS+ instance is used to sign until the budget <code>n_devsig</code> for the device is reached. Each signature is ~2.5KB in size.</p></li><li><p>When the whole budget has been drained, the SPHINCS+ with the larger <code>q_s</code> parameter, and thus larger signatures, is used. Each signature would be between ~4KB and ~8KB depending on the exact parameters chosen, but the number of signatures available is high enough to allow for practically unlimited signing.</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!pmgb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8fbb3d12-72d4-4fb3-8199-f8da3ed81438_601x321.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!pmgb!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8fbb3d12-72d4-4fb3-8199-f8da3ed81438_601x321.png 424w, https://substackcdn.com/image/fetch/$s_!pmgb!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8fbb3d12-72d4-4fb3-8199-f8da3ed81438_601x321.png 848w, https://substackcdn.com/image/fetch/$s_!pmgb!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8fbb3d12-72d4-4fb3-8199-f8da3ed81438_601x321.png 1272w, https://substackcdn.com/image/fetch/$s_!pmgb!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8fbb3d12-72d4-4fb3-8199-f8da3ed81438_601x321.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!pmgb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8fbb3d12-72d4-4fb3-8199-f8da3ed81438_601x321.png" width="601" height="321" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8fbb3d12-72d4-4fb3-8199-f8da3ed81438_601x321.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:321,&quot;width&quot;:601,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:28680,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://insider.btcpp.dev/i/213259026?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8fbb3d12-72d4-4fb3-8199-f8da3ed81438_601x321.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!pmgb!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8fbb3d12-72d4-4fb3-8199-f8da3ed81438_601x321.png 424w, https://substackcdn.com/image/fetch/$s_!pmgb!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8fbb3d12-72d4-4fb3-8199-f8da3ed81438_601x321.png 848w, https://substackcdn.com/image/fetch/$s_!pmgb!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8fbb3d12-72d4-4fb3-8199-f8da3ed81438_601x321.png 1272w, https://substackcdn.com/image/fetch/$s_!pmgb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8fbb3d12-72d4-4fb3-8199-f8da3ed81438_601x321.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In the following table, we can see the size of the signatures produces by the different algorithms:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!9Y35!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b4424e2-0a96-4c9c-a094-e59cc8196da3_293x143.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!9Y35!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b4424e2-0a96-4c9c-a094-e59cc8196da3_293x143.png 424w, https://substackcdn.com/image/fetch/$s_!9Y35!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b4424e2-0a96-4c9c-a094-e59cc8196da3_293x143.png 848w, https://substackcdn.com/image/fetch/$s_!9Y35!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b4424e2-0a96-4c9c-a094-e59cc8196da3_293x143.png 1272w, https://substackcdn.com/image/fetch/$s_!9Y35!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b4424e2-0a96-4c9c-a094-e59cc8196da3_293x143.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!9Y35!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b4424e2-0a96-4c9c-a094-e59cc8196da3_293x143.png" width="293" height="143" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9b4424e2-0a96-4c9c-a094-e59cc8196da3_293x143.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:143,&quot;width&quot;:293,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:13743,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://insider.btcpp.dev/i/213259026?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b4424e2-0a96-4c9c-a094-e59cc8196da3_293x143.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!9Y35!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b4424e2-0a96-4c9c-a094-e59cc8196da3_293x143.png 424w, https://substackcdn.com/image/fetch/$s_!9Y35!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b4424e2-0a96-4c9c-a094-e59cc8196da3_293x143.png 848w, https://substackcdn.com/image/fetch/$s_!9Y35!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b4424e2-0a96-4c9c-a094-e59cc8196da3_293x143.png 1272w, https://substackcdn.com/image/fetch/$s_!9Y35!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b4424e2-0a96-4c9c-a094-e59cc8196da3_293x143.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h3>Post-quantum Bitcoin is Moving</h3><p>Brink recently announced that they had hired quantum cryptography researcher Conduition, to focus on making Bitcoin quantum-secure. His main area of focus will be to make SHRINCS a reality, providing a usable protocol and draft BIP for the signature scheme. This seems to point to the fact that SHRINCS could be a viable solution in a post-quantum future. Building upon this protocol, thus, follows a natural course. SHRIMPS is another clever solution to improve the UX of post-quantum signatures even more.</p><p>And earlier this month, following the rash of LLM powered attacks on existing Bitcoin infrastructure, Jonas Nick <a href="https://delvingbitcoin.org/t/libshrincs-a-c-implementation-with-a-machine-checked-security-proof/2795">announced</a> a preliminary C library &#8212; <a href="https://delvingbitcoin.org/t/libshrincs-a-c-implementation-with-a-machine-checked-security-proof/2795">libshrincs</a>. It is a handwritten C library implementing WOTS+C, the one-time signature used by SHRINCS for the stateful signing path.</p><p>On August 27th Jonas Nick also <a href="https://x.com/n1ckler/status/2092740384938226107">announced</a> the publication of <a href="https://github.com/SHRINCS/shrincs-bip/blob/main/SHRINCS.md">BIP SHRINCS</a>, the draft proposal specifying all the underlying cryptography needed for the scheme to work. While using SHRINCS in Bitcoin Script would require a separate BIP, this proposal defines the design choices, new parameter set, and improvement on top of the <a href="https://delvingbitcoin.org/t/shrincs-324-byte-stateful-post-quantum-signatures-with-static-backups/2158">original proposa</a>l. The BIP is up for debate and the SHRINCS working group &#8212; composed by <a href="https://btcpp.dev/whois/conduition">Conduition</a>, Mike Casey, <a href="https://github.com/EthanHeilman">Ethan Heilman</a>, <a href="https://github.com/remix7531">Remix</a>, <a href="https://github.com/starius">Boris Nagaev</a>, <a href="https://github.com/error0024">Mikhail Kudinov</a>, <a href="https://btcpp.dev/whois/distributed-lab">Oleksandr Kurbatov</a>, and Nick himself&#8212; is waiting for feedback on the proposal.</p><p>Research on post-quantum signature for scarce resource environments is still at the beginning, but the ball is already moving. Improving on the small signatures, and fallback in case of state loss is another step towards a better experience using Bitcoin securely and cheaply in a post-quantum world.</p>]]></content:encoded></item><item><title><![CDATA[Leo from BitDevs Vancouver - BTC++ Insider Interviews]]></title><description><![CDATA[Leo of Lightning Labs and BitDevs Vancouver hosts BitDevs Toronto 001 in Parkdale during the bitcoin++ conference.]]></description><link>https://insider.btcpp.dev/p/leo-from-bitdevs-vancouver-btc-insider</link><guid isPermaLink="false">https://insider.btcpp.dev/p/leo-from-bitdevs-vancouver-btc-insider</guid><dc:creator><![CDATA[Matthew]]></dc:creator><pubDate>Wed, 26 Aug 2026 16:03:44 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/212862138/d7d3f67bf028441498d50efb10e92124.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>Leo of Lightning Labs and <a href="https://bitdevs.ca/">BitDevs Vancouver</a> hosts BitDevs Toronto 001 in Parkdale during the bitcoin++ conference.</p><p>He is equipping the local community to carry it forward through BitDevs Toronto.</p>]]></content:encoded></item><item><title><![CDATA[Bitcoin and Signal — It All Started with a Hackathon]]></title><description><![CDATA[Last month, on July 7th, news spread amongst Bitcoiners.]]></description><link>https://insider.btcpp.dev/p/radar-chat-it-all-started-with-a</link><guid isPermaLink="false">https://insider.btcpp.dev/p/radar-chat-it-all-started-with-a</guid><dc:creator><![CDATA[Tuma (I WILL NEVER DM YOU)]]></dc:creator><pubDate>Wed, 26 Aug 2026 14:01:21 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!GSOG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F203d999f-a8ab-4fc5-afa1-ce974994b7b8_1280x720.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!GSOG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F203d999f-a8ab-4fc5-afa1-ce974994b7b8_1280x720.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!GSOG!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F203d999f-a8ab-4fc5-afa1-ce974994b7b8_1280x720.jpeg 424w, https://substackcdn.com/image/fetch/$s_!GSOG!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F203d999f-a8ab-4fc5-afa1-ce974994b7b8_1280x720.jpeg 848w, https://substackcdn.com/image/fetch/$s_!GSOG!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F203d999f-a8ab-4fc5-afa1-ce974994b7b8_1280x720.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!GSOG!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F203d999f-a8ab-4fc5-afa1-ce974994b7b8_1280x720.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!GSOG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F203d999f-a8ab-4fc5-afa1-ce974994b7b8_1280x720.jpeg" width="1280" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/203d999f-a8ab-4fc5-afa1-ce974994b7b8_1280x720.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:490881,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://insider.btcpp.dev/i/212829032?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F203d999f-a8ab-4fc5-afa1-ce974994b7b8_1280x720.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!GSOG!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F203d999f-a8ab-4fc5-afa1-ce974994b7b8_1280x720.jpeg 424w, https://substackcdn.com/image/fetch/$s_!GSOG!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F203d999f-a8ab-4fc5-afa1-ce974994b7b8_1280x720.jpeg 848w, https://substackcdn.com/image/fetch/$s_!GSOG!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F203d999f-a8ab-4fc5-afa1-ce974994b7b8_1280x720.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!GSOG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F203d999f-a8ab-4fc5-afa1-ce974994b7b8_1280x720.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Last month, on July 7th, news spread amongst Bitcoiners. Someone had finally added support for bitcoin payments to Signal, the open-source, end-to-end encrypted messaging app.</p><p>Well, not Signal exactly. Radar Chat, a newly launched fork of the open source Signal project, takes the private communication network of Signal and adds Bitcoin, p2p electronic cash.</p><p>One of the minds behind the integration is Cake Wallet&#8217;s COO, <a href="https://x.com/sethforprivacy">Seth for Privacy</a>.</p><p>On X, he presented Radar Chat to the world, describing it as the best way to address one the biggest issues our digital life has: sending money and communicating should be our most private acts, but in reality this is where surveillance is strongest. Radar Chat aims to provide a unified tool for people to protect themselves from surveillance for both the movement of money and information.</p><p>Radar Chat&#8217;s launch is exciting, but it is not exactly novel. Someone had already created a proof of concept of a similar solution some months before Radar Chat finally saw the light of day, and launched a campaign to raise awareness on the fact that <strong>private messaging needs private money</strong>.</p><div><hr></div><h2>It All Started with an Hackathon</h2><p>Back in October 2025, developers from all over Europe came together in Berlin, Germany to compete to win the Bitcoin++ &#8212; <a href="https://btcpp.dev/berlin25/hackathon#project-6c0bc72a-b0c1-46c5-a31d-11275add7eac">Lightning Edition Hackathon.</a></p><p>One team had a simple, but powerful idea. Not many people know about it, but Signal has a built-in cryptocurrency wallet which can be used to exchange money between users. It only supports MobileCoin, a shitcoin that not even its creator remembers exists. The team, composed of some of the most knowledgeable developers in the Cashu ecosystem, decided to swap that wallet with a Cashu one, using the UniFFI bindings for Swift and Kotlin available on the Cashu Development Kit.</p><p>The project, <strong><a href="https://btcpp.dev/berlin25/hackathon/projects/6c0bc72a-b0c1-46c5-a31d-11275add7eac">Nuts Are Pure Signal</a></strong>, won. At the hackathon finals, they demoed sending ecash tokens back and forth between an Android and an iOS device using their custom Signal client.</p><p>The <a href="https://github.com/a1denvalu3/Signal-Android">Android fork</a> is still available on GitHub.</p><div><hr></div><h2>Private Messaging Needs Private Money</h2><p>Less than two weeks later, the Cashu team, with the help of the Bitcoin Design Community, launched <a href="https://x.com/CashuBTC/status/1978853994635117043?s=20">a dedicated campaign</a> to raise awareness on the fact that private communication and private money go hand-in-hand.</p><p>The campaign was well received, with prominent bitcoiners, such as Peter Todd and Jack Dorsey, vocally supporting the effort. Bitcoin Designer Erik Cativo discussed in a <a href="https://blog.cashu.space/bitcoin-for-signal-a-campaign-retrospective/">retrospective</a> that one of the strong points of the campaign was its focus on the design, which helped &#8220;presenting the idea elegantly and professionally&#8221;. The X hashtag <a href="https://x.com/search?q=bitcoinforsignal&amp;src=typed_query">#bitcoinforsignal</a> remains the proof of the impact of the campaign.</p><div><hr></div><h2>Closing the Loop</h2><p>Seth did not forget to give credit to the campaign. On July 10th, he published the following <a href="https://x.com/sethforprivacy/status/2075610810487816346">tweet</a> with the #bitcoinforsignal hashtag.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!AKcq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9734dc7-dce1-48f2-8738-c27a485490fb_589x625.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!AKcq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9734dc7-dce1-48f2-8738-c27a485490fb_589x625.png 424w, https://substackcdn.com/image/fetch/$s_!AKcq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9734dc7-dce1-48f2-8738-c27a485490fb_589x625.png 848w, https://substackcdn.com/image/fetch/$s_!AKcq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9734dc7-dce1-48f2-8738-c27a485490fb_589x625.png 1272w, https://substackcdn.com/image/fetch/$s_!AKcq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9734dc7-dce1-48f2-8738-c27a485490fb_589x625.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!AKcq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9734dc7-dce1-48f2-8738-c27a485490fb_589x625.png" width="589" height="625" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f9734dc7-dce1-48f2-8738-c27a485490fb_589x625.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:625,&quot;width&quot;:589,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:68468,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://insider.btcpp.dev/i/212829032?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9734dc7-dce1-48f2-8738-c27a485490fb_589x625.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!AKcq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9734dc7-dce1-48f2-8738-c27a485490fb_589x625.png 424w, https://substackcdn.com/image/fetch/$s_!AKcq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9734dc7-dce1-48f2-8738-c27a485490fb_589x625.png 848w, https://substackcdn.com/image/fetch/$s_!AKcq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9734dc7-dce1-48f2-8738-c27a485490fb_589x625.png 1272w, https://substackcdn.com/image/fetch/$s_!AKcq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9734dc7-dce1-48f2-8738-c27a485490fb_589x625.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>Radar Chat is not based on Cashu, but provides a Lightning wallet based on Spark. While the technology is different, the ethos remains the same.</p><p>Freedom of speech and freedom to transact belongs together.</p><div><hr></div><h2>What&#8217;s Next?</h2><p>In his <a href="https://insider.btcpp.dev/p/insider-reviews-a-lodging-of-wayfaring">review of &#8220;A Lodging of Wayfaring Men&#8221;</a>, Max Hillebrand chooses Bitcoin++ as one of the modern lodges in which the future is being built. &#8220;Bitcoin++ pulls protocol engineers into the same room to prototype and ship across a single shared agenda,&#8221; he says. Having hackathon projects inspire real products and real advancement in the ecosystem is one of the things we are more proud of.</p><h3>Next Stop: Berlin</h3><p>Bitcoin++ is coming back to <a href="https://btcpp.dev/berlin26?code=TUMA20">Berlin</a> next month, 1-3 October 2026. Join us, if you want to be part of the builders shaping the future of Bitcoin!</p>]]></content:encoded></item><item><title><![CDATA[Script Restoration with Julian Moik]]></title><description><![CDATA[00:00 &#8212; Julian&#8217;s First Bitcoin Conference]]></description><link>https://insider.btcpp.dev/p/script-restoration-with-julian-moik</link><guid isPermaLink="false">https://insider.btcpp.dev/p/script-restoration-with-julian-moik</guid><dc:creator><![CDATA[Matthew]]></dc:creator><pubDate>Mon, 24 Aug 2026 21:42:59 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/212614100/19f9587a32a74280497a331204b7481c.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>00:00 &#8212; Julian&#8217;s First Bitcoin Conference</p><p>At his first Bitcoin conference, Julian is enjoying the chance to meet people he previously knew only through Twitter.</p><p>00:40 &#8212; What Is Script Restoration?</p><p>Script Restoration is a broad effort to make Bitcoin Script more expressive. The goal is to give developers a stronger foundation for building new protocols on Bitcoin.</p><p>01:48 &#8212; Why Drop &#8220;Great&#8221; from the Name?</p><p>The proposal is now called simply &#8220;Script Restoration.&#8221; It restores historical functionality while extending Script with newer capabilities.</p><p>02:51 &#8212; Continuing Rusty Russell&#8217;s Work</p><p>Rusty Russell&#8217;s research and writing helped shape the proposal. Julian continued developing those ideas after seeing that few others were actively working on them.</p><p>05:06 &#8212; Is Script Restoration a Single BIP?</p><p>Rather than one large proposal, Script Restoration comprises multiple BIPs addressing computational budgeting, restored functionality, introspection, and related extensions.</p><p>06:52 &#8212; Covenant and Introspection Opcodes</p><p>The conversation covers OP_TX, PREVOUTs, and selector-based transaction introspection, comparing this general approach with OP_TXHASH, TEMPLATEHASH, and CTV.</p><p>09:12 &#8212; Script Restoration and Simplicity</p><p>Extending the existing scripting language is compared with replacing it more comprehensively. Script Restoration represents a smaller departure from Bitcoin&#8217;s current design than Simplicity.</p><p>11:13 &#8212; What Makes Script Restoration Exciting?</p><p>Research around verifiable computation could bring new capabilities to Bitcoin. Greater expressivity may improve scalability, privacy, and the user experience.</p><p>13:08 &#8212; Benefits for Bitcoin Users</p><p>Script Restoration is a low-level change intended primarily for developers and researchers. Users would experience its benefits indirectly through better wallets, protocols, and second layers.</p><p>15:23 &#8212; What Is ShieldedCSV?</p><p>ShieldedCSV is presented as a client-side validation design offering privacy and scalability. The blockchain would prevent double-spending without publicly validating every transaction.</p><p>16:44 &#8212; Making Permissionless Bridging Feasible</p><p>Script Restoration could provide the primitives needed for permissionless bridging. That could make designs such as ShieldedCSV more practical without relying on one-way bridges.</p><p>19:28 &#8212; Taproot, Ark, and Unknown Possibilities</p><p>Taproot and Ark illustrate how a protocol upgrade&#8217;s best applications may emerge later. Script Restoration could similarly unlock ideas that researchers have not conceived yet.</p><p>19:43 &#8212; Following Julian&#8217;s Work</p><p>Listeners are invited to read and review the published BIPs or contact Julian on X. The next steps include testing the implementation on the Bitcoin Inquisition signet and gathering more feedback.</p>]]></content:encoded></item><item><title><![CDATA[Antoine De Vuyst - BTC++ Insider Interviews]]></title><description><![CDATA[Antoine De Vuyst traces his Bitcoin origins to Toronto&#8217;s early bitcoin Decentral meetups organized by Anthony De Iorio.]]></description><link>https://insider.btcpp.dev/p/antoine-de-vuyst-btc-insider-interviews</link><guid isPermaLink="false">https://insider.btcpp.dev/p/antoine-de-vuyst-btc-insider-interviews</guid><dc:creator><![CDATA[Matthew]]></dc:creator><pubDate>Mon, 24 Aug 2026 19:40:14 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/212600852/1943ccdf1727024010f6ac22449031ec.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p><a href="https://x.com/Antoinedvy">Antoine De Vuyst</a> traces his Bitcoin origins to Toronto&#8217;s early bitcoin Decentral meetups organized by <a href="https://x.com/diiorioanthony">Anthony De Iorio</a>.</p><p>He&#8217;s interested in metaprotocols and shares his hackathon project based on Counterparty.</p>]]></content:encoded></item><item><title><![CDATA[Multisig Lightning — Last Week in Bitcoin (Aug 17 - 23)]]></title><description><![CDATA[Hi Insiders.]]></description><link>https://insider.btcpp.dev/p/multisig-lightning-last-week-in-bitcoin</link><guid isPermaLink="false">https://insider.btcpp.dev/p/multisig-lightning-last-week-in-bitcoin</guid><dc:creator><![CDATA[Tuma (I WILL NEVER DM YOU)]]></dc:creator><pubDate>Mon, 24 Aug 2026 14:03:12 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!i8-F!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fbbd3ab-d511-4f88-8885-e2c710e90124_1600x900.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Hi Insiders. This is Tuma, open-source reporter from the Insider Edition.</em></p><p><em>In this week update we feature the current effort from the LDK team to add support for recurrent payments in BOLT12. We also discuss a new plugin for Core-lightning to rebalance channels in a node.</em></p><p><em>We also cover the most interesting news from the Bitcoin ecosystem. Notably, we talk about Iceberg, a new nested threshold MuSig2 signature scheme, that allows Lightning operators to thresholdize one participant inside a multi-signature protocol.</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!i8-F!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fbbd3ab-d511-4f88-8885-e2c710e90124_1600x900.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!i8-F!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fbbd3ab-d511-4f88-8885-e2c710e90124_1600x900.jpeg 424w, https://substackcdn.com/image/fetch/$s_!i8-F!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fbbd3ab-d511-4f88-8885-e2c710e90124_1600x900.jpeg 848w, https://substackcdn.com/image/fetch/$s_!i8-F!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fbbd3ab-d511-4f88-8885-e2c710e90124_1600x900.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!i8-F!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fbbd3ab-d511-4f88-8885-e2c710e90124_1600x900.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!i8-F!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fbbd3ab-d511-4f88-8885-e2c710e90124_1600x900.jpeg" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4fbbd3ab-d511-4f88-8885-e2c710e90124_1600x900.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:347184,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://insider.btcpp.dev/i/212524754?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fbbd3ab-d511-4f88-8885-e2c710e90124_1600x900.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!i8-F!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fbbd3ab-d511-4f88-8885-e2c710e90124_1600x900.jpeg 424w, https://substackcdn.com/image/fetch/$s_!i8-F!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fbbd3ab-d511-4f88-8885-e2c710e90124_1600x900.jpeg 848w, https://substackcdn.com/image/fetch/$s_!i8-F!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fbbd3ab-d511-4f88-8885-e2c710e90124_1600x900.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!i8-F!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fbbd3ab-d511-4f88-8885-e2c710e90124_1600x900.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h1><strong>Highlights from the bitcoin developer ecosystem</strong></h1><p><em>I spent 10+ hours in open-source developer calls in the Bitcoin ecosystem last week. Here is what caught my eye</em>:</p><ul><li><p>The LDK team is working to introduce recurrent payments in BOLT12.</p><ul><li><p>During the biweekly call, on Monday 17th, LDK contributors discussed <a href="https://git.rust-bitcoin.org/lightningdevkit/rust-lightning/pulls/4882">PR4882</a> in <code>rust-lightning</code> which aims to introduce recurrent payments int BOLT12.</p></li><li><p>PR4882 is implementing the protocol flow and all the primitives needed for recurring payments to work. On the other hand, recurrence tracking, persistence, and scheduling will be handled downstream &#8212; For example in LDK Node.</p></li><li><p>The implementation of recurrent payments is going hand in hand with the drafting of the specification in the BOLT repository. Specifically, LN contributors are working on <a href="https://github.com/lightning/bolts/pull/1240">PR1240</a>.</p></li></ul></li><li><p>A plugin for Core-lightning for rebalancing channels in a node.</p><ul><li><p>During the biweekly call, on Monday 17th, Core Lightning developers discussed a new plugin to rebalance channels called <code>xrebalance</code> , develoeped by the main <a href="https://insider.btcpp.dev/p/clboss">CLBOSS</a> maintainer Ken Sedgwick.</p></li><li><p>Rebalancing is done through independent circular self-payments between different channels on the same node, leveraging the <code>askrene</code> plugin for improved routing computation.</p></li><li><p>The plugin is still experimental and under active development, and works out-of-the-box with CLN versions <a href="https://github.com/ElementsProject/lightning/releases/tag/v26.04">v26.04</a> or higher.</p></li></ul></li></ul><div><hr></div><h1>A BIPs Update</h1><p><em>In the last days there was some movement in the <a href="https://github.com/bitcoin/bips">BIP repository</a>. Specifically, one new BIP has been assigned a number by BIP maintainer <a href="https://github.com/murchandamus">Murchandamus</a>.</em></p><h2>Numbered BIPs</h2><p><em>A list of BIPs that recently got assigned a number</em></p><h3>BIP332: Stale Tip Relay</h3><p><strong>Authors</strong>: <a href="https://github.com/ajtowns">Anthony Towns</a>, <a href="https://github.com/w0xlt">w0xlt</a>, <a href="https://github.com/pseudoramdom">Ram</a></p><p><strong>Assigned On</strong>: Aug 20th, 2026</p><p><strong>Layer</strong>: Peer Services</p><p><a href="https://github.com/bitcoin/bips/pull/2241">PR2241</a> introduces BIP 332, which defines a new, opt-in P2P message called <code>staletip</code> whose goal is to announce recent stale chain tips to peers. The message contains the block height at which a stale branch diverges (the fork point), a vector containing the block headers belonging to the stale branch, and a flag signaling willingness to serve that block data. This may be useful for monitoring the network health, since increases in the stale block rate may expose validation or relay bottlenecks, network partitions, or <a href="https://bitcoinops.org/en/topics/selfish-mining/">selfish mining</a> behavior.</p><div><hr></div><h1>Other News from the Bitcoin World</h1><ul><li><p><strong>Iceberg, a multisig for managing Lightning channels</strong>: Paul Gerhart, <a href="https://btcplusplus.dev/whois/nadav-kohen">Nadav Kohen</a>, <a href="https://btcplusplus.dev/whois/jesseposner">Jesse Posner</a>, and Matias Furszyfer published a <a href="https://eprint.iacr.org/2026/1757">paper</a> presenting a new cryptographic primitive, nested threshold multi-signatures, which allows to thresholdize one participant inside a multi-signature protocol.</p><ul><li><p>As a first implementation of this scheme, the group presented Iceberg, the first construction for nested threshold <a href="https://bitcoinops.org/en/topics/musig/#musig2">MuSig2</a> signatures. It enables one side of a Lightning channel to operate as a <code>t-of-n</code>threshold group while appearing to the counterparty as a standard MuSig2 participant.</p></li><li><p>The proposed scheme can be used today, without any modification neither to the Bitcoin protocol, nor to Lightning.</p></li></ul></li><li><p><strong>New major version for Coco</strong>: The Cashu team <a href="https://x.com/CashuBTC/status/2089697390315946324">announced</a> that a new major version &#8212; <a href="https://github.com/cashubtc/coco/releases/tag/v2.0.0">v2.0.0</a> &#8212; for Coco had been released.</p><ul><li><p>Coco is a TypeScript library that provides the easiest way to develop Cashu-based wallets or integrate the ecash protocol in various applications.</p></li><li><p>The latest version brings the library up-to-date with the latest developments in the Cashu ecosystem. It implements minting and melting operations through BOLT12 (<a href="https://github.com/cashubtc/nuts/blob/main/25.md">NUT-25</a>) and on-chain payments (<a href="https://github.com/cashubtc/nuts/blob/main/30.md">NUT-30</a>), payment requests based on <a href="https://github.com/cashubtc/nuts/blob/main/18.md">NUT-18</a>, and custom units.</p></li></ul></li><li><p><strong>The new Simplicity Community</strong>: Blockstream <a href="https://x.com/Blockstream/status/2090803335846637866">announced</a> the official launch of the <a href="https://community.simplicity-lang.org/">Simplicity Community</a>, a place for devs to discuss the latest technical developments on the smart contract language and showcase the latest applications built on it.</p></li><li><p><strong>Responsible disclosure of an LND bug</strong>: Recently, Bastien Teinturier responsibly disclosed a vulnerability he found on LND nodes running versions before <a href="https://github.com/lightningnetwork/lnd/releases/tag/v0.20.0-beta">v20.0</a>. Specifically, an LND node would forget about a collaboratively closed channel after one single confirmation, losing protection against chain reorgs. In case of a reorg, an attacker would be able to publish a revoked commitment transaction for the channel. Since the node had already forgotten the channel, it would not publish a penalty transaction, letting the attacker drain all of the channel&#8217;s funds.</p></li></ul><div><hr></div><p><em>Looking for an opportunity to join up with some bitcoin devs in person? Join us in <a href="https://btcpp.dev/berlin26?code=TUMA20">Berlin</a> this October 1- 3 to talk about payments in Bitcoin!</em></p>]]></content:encoded></item></channel></rss>