Hi Insiders. This is Tuma, open-source reporter from the Insider Edition.
In this week update we feature two specification improvements to the Lightning Network, with the merging of BOLT12 payer proofs, and Cashu, with the possibility to mint and melt ecash tokens through custom payment methods.
We also cover the recent COLDCARD incident. Due to a bug in the entropy generation firmware, users saw their funds drained from their wallets.
We finally discuss the new BIP460 for Cross-Input Signature Aggregation (CISA), the Indian government against India, and some other interesting news.
Highlights from Bitcoin++ — Consensus Edition
I spent 10+ hours in open-source developer calls in the Bitcoin ecosystem last week. Here is what caught my eye:
BOLT12 payer proofs have been merged in the Lightning Network specifications (BOLTs)
During the monthly call, on Monday 27th, Lightning contributor discussed BOLT12 payer proofs, defined in PR1346, which was merged during the call. The work was carried on by developer Vincenzo Palazzo.
This new addition to BOLT12 defines a way to prove that an invoice has been paid. It also allows to prove that the payer proofs was actually created by the secret key used to request the invoice.
This new feature opens up new interesting use-cases, such as BOLT12-based zaps on Nostr. In fact, Amethyst developer Vitor Pamplona announced that the latest release of the Nostr client supported this specific feature, but noted that there is still work to do to actually use it.
Custom payment methods are now defined in the NUT specifications of the Cashu protocol.
During the monthly community call, on Thursday 30th, Cashu developers discussed the new update to the Cashu specifications in PR382, which introduced the possiblity to mint and melt ecash tokens through custom payment methods.
The PR updates NUT-04 (minting) and NUT-05 (melting). While some specific payment methods are described in a dedicated NUT, such as BOLT11, BOLT12, and on-chain, the recent update creates an interface to allow anyone to use any custom payment method.
Developer have already implemented custom backends based on Bark (Second’s Ark implementation) and Spark.
A BIPs Update
In the last days there was some movement in the BIP repository. Specifically, one new BIP has been assigned a number by BIP maintainer Murchandamus.
Numbered BIPs
A list of BIPs that recently got assigned a number
BIP460: CISA for Taproot Key Path Spends
Authors: Fabian Jahr
Assigned On: Jul 28th, 2026
Layer: Consensus (Soft Fork)
PR2212 introduces BIP460, a proposed soft fork to introduce transaction-wide Cross-Input Signature Aggregation. The draft defines a new witness version 2 , enabling Taproot-style key path spending where inputs can aggregate their signatures within a transaction. If used together with full-aggregation, the resulting aggregate signature would have a size of 64 bytes, independent on the number of signatures.
Other News from the Bitcoin World
The COLDCARD incident: On Thursday 30th, an earthquake hit the Bitcoin world: COLDCARD users were seeing their funds drained from their wallet. Engineers from Block soon discovered vulnerabilities in the firmware of different COLDCARD models, namely Mk3, Mk4, Mk5, and Q.
The vulnerabilities were connected to the Random Number Generator (RNG), the component whose goal is to provide entropy during the generation of the private key. Unfortunately, a bug in the firmware prevented the generation to rely on the hardware’s RNG, instead using a pseudo-RNG, based on the some fixed values. Basically, this means that the wallet was generated deterministically.
In particular, the issue was more severe on Mk3 models, while latter models slightly compensate for this issue through secure-element input. Read Block’s report to know all the technical details about the issue. The vulnerabilities have been confirmed by many different sources.
Core-lightning contributor Dusty Daemon deep dived into the COLDCARD firmware code for the Insider, providing his point of view on what happened. Read it here!
Coinkite, the company behind COLDCARD, released a security advisory on the incident, providing also migration guidelines to move funds away from the broken wallets.
We invite user to be careful in this moment of panic. Scammers have already created fake websites, accounts, and guides to profit from the incident. Only follow the official sources.
Bark <> Start9: Second, the company behind Bark, recently announced that Bark Wallet had been released on the Start9 registry.
What Bitcoin Core did: Mike Schmidt posted on X a list of all the different topics that Core developers have been addressing in the last 18 months. Devs worked on many improvements, such as SwiftSync, the new mining interface compatible with Stratum V2, ASmap, and more.
BitChat VS India: Following the protests that took place in India, the local government requested the removal of the BitChat source code. BitChat is a messaging app that allows people to communicate P2P and offline through a Bluetooth mesh. The reaction of the freedom tech communities has been overwhelming: the source code has been copied on dozens of private servers and P2P GitHub alternatives, making the request useless. Interestingly, Calle, the maintainer of the Android version of the app, posted to Nostr that the app is now able to replicate itself, by sending the apk file directly over Bluetooth to its peers.
Looking for an opportunity to join up with some bitcoin devs in person? Join us in Berlin this October 1- 3 to talk about payments in Bitcoin!



