Your signal. Your price.
Adam developed Babylonia to address standard CoinJoin vulnerabilities, where change outputs are easily linked to inputs via subset sum analysis. Babylonia uses probabilistic payments to obscure exact transaction amounts and break ownership heuristics.
Babylonia utilizes adapter signatures and zero-knowledge proofs to let parties execute a trustless, on-chain bet that reveals outcomes atomically. To prevent amount correlation, Adam updated the protocol to split single bets into multiple secret, unequal portions.
Silent payments preserve receiver privacy but require scanning every block transaction. Rob explains that lite clients must choose between trusting an index server with their scan key or downloading heavy block filters to detect payments locally.
Rob analyzed all 255,000 blocks mined since the Taproot activation to measure silent payment client bandwidth. Downloading full block payloads requires 15 gigs compared to 7 gigs for taproot-only block filters, representing a two-fold difference.
BTC Pay Server version 2.4.4 hardens security by completely removing legacy BitPay-style API keys. It also migrates to hashing API keys in database storage and eliminates plaintext API secrets from management page URLs to prevent history logging.
Non-custodial payment processor Swiss Bitcoin Pay temporarily shut down its servers following a data breach that leaked customer emails, Bitcoin addresses, and IBANs. This event follows recent security breaches at both Revolut and hardware wallet manufacturer Trezor.
The four-year lifespan of the Cold Card random number generator bug highlights a massive resource disparity in hardware security. Jameson Lopp points out that Cold Card operates with only two or three engineers, compared to Ledger's team of approximately 100.
Jameson Lopp advises keeping holdings of $1,000 to $10,000 on air-gapped hardware wallets. While manual entropy generation via dice rolls is highly secure, Lopp warns that human-engineered randomness like button-mashing actually degrades key security.
Following a physical swatting attack in 2017, Jameson Lopp developed a privacy system of mailboxes and decoy residences to isolate his real home address. He advises high-profile Bitcoiners to decouple their names and addresses to prevent duress-driven wrench attacks.
Jameson Lopp argues that KYC requirements fail to stop professional money launderers, who easily bypass regulations using cheap identities bought on the dark web. Instead, compliance laws merely create massive personal data honeypots prone to constant leaks.
Phishing scams operate as highly sophisticated business cartels using automated robodialers to screen targets. Jameson Lopp notes that lower-level scammers are paid up to $5,000 daily simply for gaining access to victim email accounts.
Max warns that using pay-as-you-go frontier AI models on privacy-focused platforms like NanoGPT can quickly cost over $100 for basic iterations. He used the service to avoid linking sensitive data to personal accounts.
A social engineering attack on Revolut compromised highly sensitive user data after attackers used a real government agency email domain to request files. Leaked files include passport scans, selfie verifications, and complete Bitcoin transaction histories.
Chinese researchers claim they can break the elliptic curve cryptography protecting Bitcoin with 835 logical qubits, down 60 percent from prior estimates. Q and A notes that avoiding address reuse is vital because spent addresses expose public keys.
Attackers breached email marketing service Bravo to send highly convincing phishing emails to Trezor and BitBox users. By exploiting valid API keys, the phishes successfully bypassed standard SPF and DKIM email authentication checks.
Divine Mobile fixed private DM duplicate text collisions and added a dual deletion request to remove local storage events. Conduit hardened its NIP-42 authentication to ensure inbox DM events are only downloadable by the intended recipient.
Amethyst version 1 integrated NIP-84 portable highlights to reference external or Nostr content. The update also adds NIP-29 group archiving and patches a shared key cache vulnerability that caused hash collisions.
Concord streamlined its relay permission flow to prevent connection request overload and introduced key backup discovery. The client also fixed Cashu proof backfill truncation and added search indexing for event titles and names.
Mostro version 0.18.5 defaulted to NIP-44 encryption for gift wraps and added pre-signature checks on incoming events to mitigate expensive signature-validation attacks. It is also refining its two-out-of-three Cashu escrow system.
Napster launched as a Nostr-based music sharing app, cataloging files using kind 30,421 and tracking online peers via kind 30,422 heartbeats. Transfers are negotiated via NIP-17 private DMs and routed through ephemeral Tor version 3 onion addresses.
MDK optimized encrypted group chats by scanning admin events in a single member walk. Zap.cooking now restricts NIP-46 signer traffic to configured bunker relays, while Nostwort enabled device-wide decryption of NIP-17 gift wraps.
Blockstream communicated with the Liquid hacker via PGP-encrypted onchain messages before the attacker threatened to publish negotiations in plain text. Blockstream plans to pursue every legal avenue to recover the remaining 600 stolen Bitcoin.
Natalia highlighted Silent Link and Natada as non-KYC Bitcoin eSIM options for exiting fiat systems. Silent Link offers data plans for $9 using Lightning and Bitcoin, while Natada provides rented phone numbers and VPN services.
Keon warns that Lightning sender privacy is only perfect when running a non-custodial node that constructs its own routes. Custodial systems, Strike, and Lightning Service Providers doing route construction can observe transaction details.
The Rhysida cybercrime group hacked the Berlin Department of Public Works and Department of Transportation, accessing data on 4 million residents. They published 1.4 million files on the dark web after the city refused a 30 Bitcoin ransom.
Den questioned whether anyone can successfully launder stolen Bitcoin. Keon notes the cold card hacker attempted to launder funds through CoinJoin, ThorChain, and Ethereum swaps, but the efficacy of maintaining unlinkability across these protocols remains highly uncertain.
Monero users Ape and Arrow donated $10 each in XMR, prompting the Ungovernable Network to add an XMR entry field option to their value-for-value page.
Jordan designed Ashigaru Desktop over six months to provide a graphical user interface skin over Ashigaru Terminal, a keyboard-navigated terminal user interface.
Ashigaru Desktop deliberately excludes spend functionality to keep the attack surface small. Jordan advises users to handle spending on mobile via Ashigaru Mobile or alongside Sparrow Wallet.
New wallets created on Ashigaru Desktop require a passphrase. To prevent weak password creation, the wallet features a guided dice-rolling tool utilizing the Electronic Frontier Foundation wordlist.