Your signal. Your price.
Liquid Network attackers returned 3,400 of the 4,000 stolen Bitcoin but kept nearly 600 coins as a ransom. Adam Back confirmed the Liquid peg will remain fully covered one-to-one, while Blockstream refuses to negotiate with the hackers.
The revised US market structure bill removes criminal safe harbor protections for noncustodial software developers, leaving them vulnerable to money transmission charges. DeFi protocols deemed decentralized in name only must also register with the CFTC.
An authentication bypass flaw in legacy Alby Hub versions allowed attackers to gain full node control if the API port was exposed. Node operators should upgrade to version 1.2.4 and restrict public internet exposure.
Attackers breached email marketing service Bravo to send highly convincing phishing emails to Trezor and BitBox users. By exploiting valid API keys, the phishes successfully bypassed standard SPF and DKIM email authentication checks.
The Yeti Cold 2.0 protocol outlines a complex 3-of-7 multisig scheme using CD-ROMs, Bitcoin Core, and offline laptops. Max and Q and A criticize the setup as a hazardous user experience that increases the likelihood of self-custody loss.
Electrum Rust Server 0.12 introduced a new indexing library requiring a full reindex, while Fedimint patched a critical gateway payment vulnerability. Q and A also updated his open-source Bitcoin Seed Tool to support seed XOR splitting.
An attacker exploited Liquid's consensus engine to drain 4,000 BTC from its 11-of-15 multisig federation. The hacker returned 3,400 BTC but kept 600 BTC as an involuntary bounty, demanding a 10% voluntary payment for the rest.
Blockstream communicated with the Liquid hacker via PGP-encrypted onchain messages before the attacker threatened to publish negotiations in plain text. Blockstream plans to pursue every legal avenue to recover the remaining 600 stolen Bitcoin.
Keon warns that Lightning sender privacy is only perfect when running a non-custodial node that constructs its own routes. Custodial systems, Strike, and Lightning Service Providers doing route construction can observe transaction details.
Den questioned whether anyone can successfully launder stolen Bitcoin. Keon notes the cold card hacker attempted to launder funds through CoinJoin, ThorChain, and Ethereum swaps, but the efficacy of maintaining unlinkability across these protocols remains highly uncertain.
Ezra Regreira reports that Blockstream refused to pay a 10% ransom to hackers who exploited the Liquid Network federation wallet. The hackers initially withdrew 4,000 Bitcoin but returned 3,400 after Blockstream patched the affected bridge nodes.
Ashigaru Desktop deliberately excludes spend functionality to keep the attack surface small. Jordan advises users to handle spending on mobile via Ashigaru Mobile or alongside Sparrow Wallet.
New wallets created on Ashigaru Desktop require a passphrase. To prevent weak password creation, the wallet features a guided dice-rolling tool utilizing the Electronic Frontier Foundation wordlist.
Users without a personal Electrum server can discover alternative trusted nodes. The app connects to the Dojo Bay reference instance over Tor to locate available Electrum servers.
Whirlpool mixes on Ashigaru Desktop operate in 0.025 BTC and 0.25 BTC pools. Change that falls below these minimums goes to the bad bank, which cannot be mixed.
The Mix To feature allows users to route coins automatically to a hardware wallet, such as Passport Prime, once they reach a specified mix count. This process uses watch-only output descriptors.
Ashigaru Desktop supports concurrent mixing for multiple wallets. Users can lock the application interface with a password while the background mixing processes continue to run securely.
Blockstream Liquid was hacked for 4,000 BTC after an attacker exploited an inflation vulnerability. The exploit resulted from a flawed code patch released on September 1, 2024, which attempted to fix an older 2018 range proof vulnerability.
Adam Back announced the Liquid network peg will remain one-for-one. Blockstream and its partners are plugging the remaining 600 BTC deficit after the hacker returned 3,400 BTC through encrypted OP_RETURN negotiations, keeping 15 percent as an unsolicited bounty.
Trezor and BitBox warned users of phishing emails sent via compromised third-party newsletter services. The fraudulent security alerts falsely claimed devices suffered from an entropy vulnerability.
Nacho Pauls points out that tax and regulatory requirements in Canada and Finland mandate corporate miners to use FPPS pools. This constraint prevents many institutional mining operations from adopting Ocean's non-custodial payout structure.
Brian Armstrong explains that Coinbase is banking AI agents via self-custodial wallets and crypto rails, bypassing traditional KYC identity requirements to let agents pay for API resources and digital goods.
Coin Corner launched an insured multisig Bitcoin custody vault with partner Anchor Watch. David Bennett argues that wrapping custody in complex multisig structures risks isolating Bitcoin from its original purpose as accessible peer-to-peer cash.
Jack Dorsey's payment company Block filed an application with the Office of the Comptroller of the Currency to launch Builders Bank and Trust. The proposed national trust bank will offer Bitcoin and stablecoin custody without accepting commercial deposits.
To manage cash flow volatility, Chris Drzyzga designs a three-bucket treasury strategy. Short-term operational cash sits in fiat, intermediate reserves fund upcoming capital expenditures, and strategic capital held longer than eighteen months goes into cold-storage Bitcoin.