FreshRSS

🔒
❌ About FreshRSS
There are new articles available, click to refresh the page.
Today — 7 September 2026Crypto - Money

Alleged White-Hat Hackers Withdraw 4,000 bitcoin from Blockstream’s Liquid Network Federation Reserves

7 September 2026 at 01:16

Bitcoin Magazine

Alleged White-Hat Hackers Withdraw 4,000 bitcoin from Blockstream’s Liquid Network Federation Reserves

The Liquid Network said Sunday that purported white-hat hackers withdrew about 4,000 bitcoin, worth about $320 million, from the federation wallet that backs L-BTC. Bridge nodes were disabled, and the sidechain was paused. Other issued assets, including USDT, DePix and RWAs, were unaffected, the official account said on X.

The Liquid Network is a federated sidechain of Bitcoin, founded by Adam Back’s Blockstream. The Liquid chain issues a variety of assets such as LBTC, which it backs with BTC on the Bitcoin main chain, held in a large multisig of 15 corporate and known members. 11 of the 15 members need to sign a valid multi-signature transaction to move coins from the treasury. Before the hack, the treasury held over 4200 BTC; after the hack, Blockstream’s proof of reserves page reports a little over 207 BTC left. 

The hackers withdrew 4,019.4 BTC from the reserve address in a peg-out transaction using the SideSwap Peg-out Authorization Key. SideWap is a bridge exchange and a member of the Liquid Federation. While details on the mechanism of the hack are not confirmed yet, it appears an inflation bug on the LBTC side chain was exploited by the hackers to create over 4,000 LBTC that did not exist before, and cash them out for on-chain bitcoin from the federation. Because the transaction appeared as valid, given the consensus bug, the federation members’ HSM security servers signed the BTC withdrawal transaction, worth roughly 320 million at the time. 

The hacker moved the funds to an address ending in 6gyqjlte, from which they quickly signed a new transaction with a message on the OP_RETURN arbitrary data field saying “we are whitehats. contact us on chain.” Those coins were still at that address at the time of writing.

A small mainnet transaction to the hacker address followed by an OP_RETURN saying “Please contact security@blockstream.com”, presumably from a Blockstream public address, though that remains unconfirmed. A later OP_RETURN spend from the hacker address carried “Please contact us on Signal @m671aw.70”, however, this may be spam and does not share a link to the address with the stolen funds.

In response to the breach, exchanges were told to pause L-BTC deposits and withdrawals. Bridge nodes on the Liquid Network have been paused, limiting access to the side chain, which continues to produce blocks. 

JAN3 CEO Samson Mow said Aqua’s Liquid features were affected and that on-chain bitcoin still worked. Other wallets in the industry that use the Liquid Network are expected to be affected. Users holding LBTC now effectively have their savings at risk, since the underlying BTC is currently not redeemable. Given the private nature of the Liquid chain, user onchain analytics are scarce and not much public information is known about how much LBTC is held by retail users versus corporations of Blockstream itself. Nevertheless, should the funds not be returned, it would be a heavy blow to the Liquid Network’s user base.

Users of LBTC don’t have many options but to wait for conversations with the hackers to resolve. Given the size of the hack, it would be difficult for the hackers to get away with stealing all that bitcoin, though perhaps not impossible. What may happen is that the hackers ask for a finder’s fee and return the majority of the funds. 

This post Alleged White-Hat Hackers Withdraw 4,000 bitcoin from Blockstream’s Liquid Network Federation Reserves first appeared on Bitcoin Magazine and is written by Juan Galt.

Before yesterdayCrypto - Money

Coinkite’s Coldcard Bug Exposed Single-Sig Risk. Multi-Vendor Multisig Is the New Bitcoin Custody Baseline

27 August 2026 at 02:39

Bitcoin Magazine

Coinkite’s Coldcard Bug Exposed Single-Sig Risk. Multi-Vendor Multisig Is the New Bitcoin Custody Baseline

In the wake of Coldcard’s catastrophic entropy bug, self-custody advocates and experts have begun recommending a new standard, multi-vendor multisignature wallets, an approach that looks to minimize —among other threats— dependency on any single hardware wallet manufacturer.

The Coldcard entropy bug that went undiscovered since at least 2021 has taught a hard lesson to the Bitcoin self-custody advocates and users. No matter how legitimate or competent a wallet provider might seem, how well recommended and reputable, a major bug may be possible. As a result, Bitcoiners are questioning old recommendations and assumptions, including many declaring the ‘death of single sig’ the popular self-custody method of trusting the private key pair generation to one wallet alone. 

The Threat Model

Self-custody by any measure is an advanced practice in Bitcoin. Advocates recommend it as a way to protect user funds from exchange malfeasance like that seen in the cases of FTX and MtGox, among many others. But recent events have driven a revaluation of custody practices, with many bitcoin owners moving coins to exchanges — at least temporarily — while others upgrading or changing their self-custody setups altogether. Nick Neuman, CEO of Casa, claimed that 233k bitcoins moved to safety in reaction to the Coldcard hack.

To understand when self-custody makes sense and for whom, it is essential to understand your personal threat model. A threat model is the careful analysis of threats to an individual, for the purpose of designing security practices and structures ahead of time. 

A simple threat model practice can be to take a step back and think about all the possible things that worry you about self-custody, and add them to a list. Then think about all the things that advocates caution users about, and append them to that same list. Next, sort or rate items on that list based on which are most likely to happen to you, and which are most likely to happen in general. Finally, you can rank each item in the list by how catastrophic it would be if it occurred; can your current setup and plans survive the realization of that threat? 

Two of the most likely causes of loss of funds in Bitcoin self-custody are user error related to backups or forgotten passwords, and of course theft. Many of the wallets believed to be lost bitcoins that have not moved come from bad backups of private keys in the early days, resulting in data loss after a computer failed. Others simply used passwords too difficult to brute force, and then forgot them, encrypting their private keys forever.

On the theft dimension, bad entropy attacks likely rank among the most successful attacks on self-custody to date, with Coldcard joining a significant list of other wallets that have suffered bugs of the sort, intentional or otherwise, such as Trust Wallet, and many lesser-known and possibly malicious mobile wallets. In some cases, fake wallets like the iOS Sparrow Wallets simply stole user funds by keeping a copy of the user-generated private keys and sweeping the funds once deposited. In all of these examples, more thoughtful user behavior before trusting random software with your life savings is the solution. 

Once users have a clear threat model in place and a good enough understanding of the technology, designing security practices becomes more a science than an art. And while every individual has specific circumstances they need to take into account, some structures have emerged as the most resilient to most threats. One such practice becoming widely recommended and adopted among long-term self-custody Bitcoin holders is a carefully formed multisig setup. 

Multi-vendor Multisig

The term “Multi-vendor Multisig” is relatively new in the self-custody niche. The term “multisig” has nevertheless gone viral in 2026, clearly triggered by the Coldcard hack that saw the loss of over 100 million dollars worth of bitcoin, mostly from single seed wallets. Most single-seed Coldcard users appear to have generated their private keys on the device without adding an extra passphrase, extra words that add custom entropy to the private keys, nor without extra dice rolls, which do the same in a different format. 

The weak entropy from the Coldcard firmware — which users had no reason to distrust, given the company’s strong brand — in turn made guessing the related private keys easy, with a bit of custom work, which hackers eventually figured out. 



The resulting viral interest in multisig is warranted. Multisig Bitcoin wallets protect users from such hardware manufacturer errors by letting users construct a Bitcoin address that requires signing from multiple private keys and thus multiple devices, in what is known as a Bitcoin script.

Bitcoin scripts are contracts of sorts that set spending conditions for a bitcoin wallet. All Bitcoin wallets can be thought of as having some kind of script involved, with the simplest and most popular being that anyone who can sign a valid transaction can spend all or any funds therein. Multisig scripts instead require a threshold of valid signatures from different keypairs to result in a valid withdrawal. These scripts are enforced by the Bitcoin consensus rules.

Multi-vendor multisig theory posits that users should make sure every keypair used to construct a Bitcoin multisig is generated from a different wallet vendor. 

One example that is likely popular today might be the use of a Trezor Safe 7 hardware wallet with one key, a second key generated by a Ledger Nano, and a third key generated by a multisig wallet provider, considered a recovery key. A script of this sort would require any 2 valid signatures out of the three possible signatures in the setup.

By using two different hardware wallet providers, the user minimizes trust in any single wallet vendor, protecting them from an entropy failure like the one seen in Coldcard. 

Other Multisig setups can add more keys, with a 3-of-5 threshold also being common and a standard offering of a multisig-specialized wallet like Casa. It is at this point that the terminology commonly used and understood to describe Bitcoin spending software starts to break down, and as a result merits clarification.

Wallets like Casa are software interfaces that let users combine partially signed transactions from different private key pairs. In this scenario, it becomes more useful to describe ‘hardware wallets’ like Trezor or Ledger as ‘key signers’ since no single keypair in the set holds enough of the key material to spend all the Bitcoin held in the Multisig script address. 

So Casa is a Multisig wallet that lets you use a threshold of hardware signers to secure and send bitcoin funds. Fundamentally, they help users interact with Bitcoin script and create consensus-valid transactions easily. Other examples of such multisig wallet providers include Nunchuck, Sparrow desktop wallet and Unchained Capital

In cases like Casa and Unchained, the wallet provider offers users a recovery key controlled by the company, which some users find useful. Nunchuck and Sparrow, on the other hand, are designed for full user autonomy in this regard, though Nunchuck does offer a premium recovery key-related plan as well. 

The Upsides of Multivendor Multisig

Another benefit of a multisig wallet is its potential resistance to the infamous wrench attacks. Countries like France, which make Bitcoin and crypto ownership a matter of public record as a consequence of tax filings, have become focal points for crypto theft-related kidnapping. Self-custody or not, targets of this kind of crime are vulnerable to theft, particularly when the funds can be moved in full quickly, be it from a custodial exchange the user can access from their phone, or some self-custody setup.

Advanced forms of multisig, like multi-jurisdictional or time-locked multisig, make it so that users have to travel, ideally through an airport, in order to reach other key signers needed to construct a valid bitcoin transaction. Or perhaps the recovery key involved in the multisig has the condition that it will not sign for two weeks after the user submits the request and corresponding transaction data. The result is the removal of the final central point of failure in Bitcoin custody: the user’s own willingness to send the bitcoin, particularly when under duress.

While best practices in the case of wrench attacks broadly try to avoid ending up in that situation in the first place, making it difficult to spend your coins actually protects users from a wide range of attacks as well, including phishing schemes and other forms of social engineering that use pressure tactics to fool users into sending funds quickly. 

Multisig has also begun to enable novel forms of Bitcoin insurance, as demonstrated by AnchorWatch, a multisig wallet and insurance company that offers bitcoin theft protection denominated in BTC. The company’s services today are primarily offered to Americans through the Lloyd’s of London insurer. 

The Downsides of Multisig


One critical downside of Multisig is that the user does not only need to have access to the threshold key material needed to sign, be it two hardware wallets as in our example, or one of the hardware wallets and a recovery key from the wallet company. The user also needs to store a copy of the Multisig script or template, so that they can recreate the smart contract and thus the valid withdrawal conditions for spending. Most Multisig wallets store this information for clients, but they will also send a copy to users so they can recover independently of the Multisig wallet, should it one day go offline. 

This post Coinkite’s Coldcard Bug Exposed Single-Sig Risk. Multi-Vendor Multisig Is the New Bitcoin Custody Baseline first appeared on Bitcoin Magazine and is written by Juan Galt.

Open Source vs. Source-Available: What the Coldcard Failure Teaches About Bitcoin Software Incentives

20 August 2026 at 23:49

Bitcoin Magazine

Open Source vs. Source-Available: What the Coldcard Failure Teaches About Bitcoin Software Incentives

Closed versus Open Source code has divided the Bitcoin and broader crypto industry for well over a decade. Bitcoin advocates have long argued that the financial infrastructure of the world should be built in public. Transparency and auditability, they say, are non-negotiable when real money is at stake. Yet the app and legacy layers of finance often disagree. 

Yet the recent Coldcard hack, a popular self-custody hardware wallet where users lost over $100 million worth of bitcoin (more than 1,500 BTC), cast doubt over what “Open Source” actually means. It revealed that perhaps most people, even many hardcore bitcoiners, are poorly educated on the Open Source software development philosophy and when it fails.

The  Principles and Terminology

The language around Open Source can be complicated. Free and Open Source Software (FOSS) and Free/Libre and Open Source Software (FLOSS) refer to software that meets formal definitions of user freedom.

The Free Software Foundation (FSF) defines free software through four essential freedoms:

  • Freedom 0: The freedom to run the program as you wish, for any purpose.
  • Freedom 1: The freedom to study how the program works, and change it so it does your computing as you wish (access to the source code is a precondition for this).
  • Freedom 2: The freedom to redistribute copies so you can help others.
  • Freedom 3: The freedom to distribute copies of your modified versions to others (access to the source code is a precondition for this).

The FSF emphasizes that “free” refers to liberty, not price, in a common quote heard from FOSS advocates: “‘free’ as in ‘free speech,’ not as in ‘free beer.’”

The Open Source Initiative’s Open Source Definition adds ten practical criteria. These include free redistribution without royalties, availability of source code in the preferred form for modification, the right to create and distribute derived works, and no discrimination against persons, groups, or fields of endeavor — including commercial use. A license must meet all ten criteria to qualify as Open Source under the OSI standard.

“Source available” or “source viewable” is different. Code may be publicly readable while the license restricts the right to sell it. Coldcard’s firmware, for example, is released under MIT terms plus the Commons Clause. The Clause specifically removes the right to “Sell” the software — defined as providing it to third parties for a fee or other consideration in a product or service whose value derives entirely or substantially from the software itself. In other words, Coldcard’s firmware could not be used commercially. 

The Commons Clause’s own FAQ states the difference explicitly: “Is this ‘Open Source’? No.” It notes that applying the clause means the software meets many elements of the Open Source Definition but not all of them, and therefore should not be called Open Source.

These distinctions matter. Publishing source code creates the possibility of inspection. Granting the full set of rights defined by the Free Software Definition or the Open Source Definition is what makes software FOSS or FLOSS. But having the badge of approval, being able to wave a FOSS or FLOSS flag, is not the point. Commercial liberty in FOSS unlocks third-party incentives to test and review code that might otherwise not be there, critics argue. 

The four freedoms form the philosophical core of Open Source. In practice they rest on an economic assumption: that enough motivated people will actually examine the code. When that assumption fails, the system produces a classic tragedy of the commons, a situation where a shared resource is overused or neglected because individual users act in their own short-term self-interest rather than in the long-term interest of the group. 

Each person has an incentive to take more (or contribute less) than is sustainable, and the resource degrades as a result. This happens when there is misalignment between the short-term self-interest of the individual and the long-term interest of the group. Sometimes alignment exists; sometimes it does not. 

One Bitcoin developer put the problem bluntly: “Using mocks and stubs of Open Source code in tests is irresponsible and shortsighted. Open Source code is considered safe because anyone can verify it. If you aren’t willing to do the bare minimum of testing the features you actually depend on, then you are behaving like a leech.”

As a result, Open Source does not create safety by itself. It creates the possibility of verification. Whether that verification occurs depends on incentives, skill, and attention. Historical FOSS is believed to harden over time as vulnerabilities are discovered, disclosed and patched, creating solid foundations others build on top of. The Linux kernel is a great example of such hardened FOSS; it powers the vast majority of the world’s servers, cloud infrastructure, Android devices, and embedded systems, making it one of the most widely deployed pieces of software in history.

Open Source as Demonstrated by Bitcoin Core

Bitcoin Core, the reference implementation of Bitcoin, is another prescient large-scale example of pure open-source functioning in the wild. The software, which runs behind most Bitcoin-related infrastructure, is released under the MIT license. Its development process is broadly public by design.

Anyone can open a pull request. Code review is the primary filter and the recommended entry point for new contributors. Reviewers use a formal vocabulary—Concept ACK (acknowledgment and agreement with the goal), Approach ACK (agreement with the goal and method), ACK with a specific commit hash (tested and approved for merge), or NACK (disagreement, which should be accompanied by technical reasoning).

Maintainers weigh consensus among contributors and the technical merits of a change before merging. Consensus-critical changes face a still higher bar and usually require a Bitcoin Improvement Proposal and extensive multi-year discussions on the bitcoin-dev mailing list and IRC.

There is no privileged caste of “Bitcoin Core developers.” Trust is earned through demonstrated competence over time. Maintainers exist for practical reasons—auditing and merging code, managing releases, and basic moderation—but the work produced is pure open-source code that anyone can inspect, build, fork, or run. Developers who get code ‘commits’ merged into Bitcoin Core are broadly called Bitcoin Core Contributors. 

Calle, a long-time open-source Bitcoin developer, summarized the reality recently: “People who think that core is some sort of intransparent institution operating in the shadows are either too lazy or too dumb to go have a look for themselves. Literally everything they do is public, anyone can chime in, and the result of their work is pure Open Source code.”

Funding for this work comes largely through nonprofit and grant structures such as Brink, OpenSats, Spiral, and others rather than a traditional company product roadmap. Technical discussion and debate take place publicly on the bitcoin-dev mailing list and in the #bitcoin-core-dev IRC channel on Libera Chat, where proposals are scrutinized before and during the pull-request process. GitHub issues and pull requests often carry comment histories stretching back a decade. The result is a development culture optimized for correctness and auditability rather than speed or commercial feature velocity.

The Economics of Open Source

Most users of open-source or source-available software never read the code themselves. They rely on the assumption that others are examining it. In the Coldcard case, a critical entropy flaw remained in publicly available firmware for roughly five years before it was exploited and thus discovered. 

The bug entered the codebase during a major 2021 rewrite that also removed remaining GPL-derived code from Trezor, the first hardware wallet and now the second largest in the self-custody industry. The library at the center of the entropy failure, which replaced trezor-crypto, is called libngu and had minimal external scrutiny, with only 7 stars and fewer than 20 forks in over 5 years of being used in production. Compare that to the 512 stars worn by the trezor-crypto library alongside 212 forks, or the 793 forks and 1.8k stars of the more modern trezor-firmware. Source availability alone did not produce the review that mattered, because other for-profit, well-funded companies were restricted from using it, or so critics would argue. 

The stakes are higher in Bitcoin than in most software domains. A critical flaw can be converted directly into liquid funds on the open market. While the first half of the Coldcard funds stolen are still held in a handful of addresses and the hacker may one day be caught, copycat hackers that followed were more careful, and some have stolen more bitcoin and laundered it successfully, per Galaxy Research. Bitcoin’s censorship resistance and immutable transactability create both a powerful incentive for attackers and a Darwinian filter; only projects that continuously attract competent review, and users and companies that take serious precautions, tend to survive long-term.

Licensing choices shape those incentives according to FOSS advocates who criticized Coinkite’s licensing decisions for years. Pure open-source licenses maximize the pool of potential reviewers and forks. Restricted “source available” licenses can reduce commercial free-riding but also shrink the circle of people with both the legal right and the economic motive to invest deep attention. Alas, the burden of code review falls back on the company under a restrictive license, placing it in some sense closer to closed source than open.

How AI Changes Open and Closed Source Development

Artificial intelligence is now also altering the balance between FOSS and Closed source.

After the Coldcard incident, a volunteer effort known as the Bitcoin Red Team—led by developers including Calle and Rob Hamilton of AnchorWatch, and supported by OpenSats—used frontier AI models to scan hundreds of open-source Bitcoin repositories. In one intensive period, the team filed thousands of findings, including dozens classified as critical or high severity, across hundreds of projects. Responsible disclosures were made to maintainers before broader publication. The exercise demonstrated that systematic AI-assisted review can surface issues at a scale and speed previously impractical for purely human teams.

On this front, it is worth noting that the Red Team found Chinese open-weight models far more reliable than closed-source American models, which, even with cyber permissions and top-line access, refused to answer Red Team queries, a trend that the American developers lament. 

At the same time, the flood of AI-generated code has created a new denial-of-service pressure on FOSS maintainers. Reviewing AI output often takes longer than generating it. Some open-source projects outside Bitcoin have restricted issue trackers or imposed strict anti-AI contribution rules simply to stay functional.

On the closed-source side, the traditional advantage of security through obscurity is eroding. Modern AI models can read, de-obfuscate, probe endpoints and reason about code at high speed. The practical difference between open and closed source is now mostly relegated to back-end code that never gets shared online. Closed-source code, as a result, stands only on the quality of professional audits, the speed of patch deployment, and the incentive structure that keeps competent people with access looking.

Bitcoin and the broader crypto industry are applying unusual pressures to free and open-source software. The combination of real monetary value at risk, adversarial economics, and now AI-scale analysis is forcing the software models to evolve. Returning to analog pre-digital systems is hardly an option for infrastructure that holds up modern society. Only the most audited projects are likely to survive the pressures of AI-aided hackers and the weight of digital-first finance.

This post Open Source vs. Source-Available: What the Coldcard Failure Teaches About Bitcoin Software Incentives first appeared on Bitcoin Magazine and is written by Juan Galt.

Hunting Down the Coldcard Hacker. Wave 1 Thief May Be Known to FBI

18 August 2026 at 19:02

Bitcoin Magazine

Hunting Down the Coldcard Hacker. Wave 1 Thief May Be Known to FBI

Law enforcement may already know who emptied more than a thousand Bitcoin from Coldcard wallets in the first and largest wave of the July 2026 drains. Block’s investigation believes they traced the attacker’s on-chain sweeps to a paid account at a major blockchain data provider whose internal logs matched the theft pattern with “extraordinary specificity.” 

PSA: The attack is ongoing, targeting weak private keys generated on devices as old as the MK2 with firmware 4.0.1 onwards. If you may have one, double-check and move funds asap. See Coinkite advisory and status page

The coins from that wave—1,082.65 BTC—still sit untouched in the attacker’s address, leaving hope that a clawback may be possible to the victims and rightful owners of that first wave of stolen bitcoin. The question now is, who is the hacker and whether the same lead points to a sophisticated outsider, or whether the five-year-old entropy bug that made the theft possible was something closer to the insider “retirement attack” Coinkite itself once warned about.

What We Know

On July 30, 2026, an attacker began systematically draining Bitcoin from Coldcard hardware wallets that had generated seeds under vulnerable firmware, a bug that was undiscovered for years. The first and largest wave alone moved 1,082.65 BTC. Subsequent waves followed, with estimates over 2k BTC. Alex Thorn at Galaxy Research has tracked the activity through a combination of on-chain pattern analysis and voluntary victim reports. As of early August, confirmed and estimated losses across multiple waves exceeded 1,800 BTC from more than 5,000 addresses, though exact final totals continue to be refined as new reports arrive. In dollar terms, roughly $118 million has been confirmed stolen.

Thorn has publicly discussed the possibility that law enforcement already holds a concrete lead on the operator behind the largest tranche. In a Bitcoin Policy Institute segment hosted on the Bitcoin Magazine YouTube channel, Thorn stated: “Wave one’s identity, attacker identity, may be known to law enforcement.” He added that Wave 1 remains the biggest single chunk identified so far, with the coins still sitting in the attacker’s address, and noted that Wave 2’s pattern looks similar enough that it could involve the same actor. Wave 2 adds another 76 or so bitcoin to the total. 

The primary source for the claim that the hacker’s identity might be known is Clay Garrett, engineering lead at Block working on Bitkey. On July 31, 2026, Garrett posted the findings from Block’s investigation:

“During our investigation of the Coldcard drain yesterday, we identified an unusual pattern in the sweeps. That pattern led us to a hypothesis that has since been confirmed: the operator used a paid account at a well-known blockchain-services provider to query the source addresses and perform other related activity during the sweeps.”

“We contacted the provider directly. Their internal logs matched the suspected workflow with extraordinary specificity, including the number, timing and sequence of requests. The provider was supplying its standard services in response to requests that did not reveal their broader purpose. We have seen no evidence that the provider knowingly participated in or facilitated the suspected theft.” Garrett said, and added that; “We are sharing the relevant information with the appropriate authorities. We will provide further updates when doing so will not interfere with the investigation.”

Thorn and others have noted that later, smaller waves show different operational patterns—some rapid, opportunistic drains followed by quick laundering—suggesting additional actors may have reverse-engineered the same weak seed space after the initial public disclosure. Self-reported confirmed drains appear to have slowed sharply after August 6, though many potentially vulnerable seeds generated on the affected firmware between 2021 and the July 2026 patch remain at risk until users migrate.

A Retirement Attack?

The nature of the failure has led to conspiracy theories about insider attacks that Coinkite itself once discussed publicly. In October 2021, the official COLDCARD account defined a “retirement attack” as the scenario “when the project makers could have a ‘bug’ in the entropy generation for later retrieval.” The post is still available here. The 2026 vulnerability produced exactly that outcome: seeds generated with far less entropy than intended, leaving them searchable years later. Some in the Bitcoin space now believe that the hack may have been an inside job at Coinkite, though others disagree and the evidence in the public record remains too scarce to know anything definitive. Further evidence will likely not come out for years, until litigation exposes it.

It’s when the project makers could have a “bug” in the entropy generation for later retrieval.

— COLDCARD (@COLDCARDwallet) October 10, 2021

The critical change entered the codebase on March 1, 2021, in a commit titled “First pass w/ libNgU” (b18723dd). That commit replaced remaining Trezor-derived cryptography and BIP-39 code with a new library, libngu, and rewired seed generation. The intended result was that the call for randomness resolved to the STM32 hardware’s true random number generator. However, the bug redirected the call to MicroPython’s software Yasmarang PRNG instead, resulting in an effective entropy collapse to roughly 40 bits on older models and around 72 bits on newer ones. That meant the Bitocin private keys generated were effectively guessable by modern computing hardware. This swap of cryptographic libraries was pushed to the codebase by Doc-Hex, also known as Peter Gray, the Chief Technical Officer of Coinkite. 

The move was arguably driven by licensing pressure, according to Foundation Devices CEO and founder Zach Herbert, though Coinkite has denied this as a primary motivation for the code change, saying, “COLDCARD had to make this change to move to libsecp256k1; the license change is irrelevant to this. libsecp256k1 is the standard library used by Bitcoin Core.”

Coldcard had been using Trezor-derived code under the GPLv3 open source license. After Foundation Devices forked related material, Coinkite sought to move remaining components to a more restrictive MIT + Commons Clause arrangement that limited commercial reuse. The rewrite was large and carried complex engineering goals; it was this integration that arguably left the silent failure in the entropy path.

Skepticism about the migration away from the Trezor crypto library emerged as early as April 7, 2021, by a member of the Coinkite Telegram group, who wrote: “do we really want to replace the many-years-old TrezorCrypto code that has been heavily scrutinized by white hatters like Johoe and penetration tested by wallet.fail”, adding “switch may be a talented pseudonymous coder, but their commit history sucks.” The criticism, however, was insufficient and quickly waved away by NVK, who criticized the Trezor library as a “shitcoin shitshow.” Ironically, sharing that codebase with the broader crypto market, under an open license meant that Trezor’s crypto library had much deeper code review than Libngu would ever get, even years later. 

Switch and Peter Gray aka Doc-Hex

The swap of cryptographic libraries that introduced the bug was pushed to the codebase by Doc-Hex, the Chief Technical Officer of Coinkite, also known as Peter D. Gray. He replaced the GPLv3 Trezor cryptography library with Libngu, a little-known codebase created by so-called “Switch”, a nym that, up until the creation of Libngu, had no obvious previous history. The Switch account appeared on X on August 3, 2019 with a mention of DEFCON, the international hacker’s conference, an event normally attended by cybersecurity engineers of all kinds. 

On October 16, 2020, Switch thanked Doc-Hex on X for merging his code; “Thanks for merge @DocHex … I’m making yet another bitcoin library. Could be useful on @COLDCARDwallet someday.” A few days later, Switch tweeted out a link to Libngu, proud to have built a “useful thing.”  

However, here is where it gets weird. According to research by Bitcoin core contributor James O’Beirne, Switch and Peter D. Gray have signed code commits with the same GPG keys. O’Beirne demonstrated through GPG commit signatures that dozens of commits authored as switck were signed with the personal key of Peter D. Gray, Coinkite co-founder and CTO, who also operates as DocHex. Zach Herbert also claimed that phone numbers ending in the same two digits were tied to both the DocHex and switck X accounts (post). Additional researchers pointed to matching DNS registration patterns.

Neither Gray nor Coinkite has publicly addressed the GPG-signature findings as of this writing, and they did not respond when asked to comment on the topic. The Switch account is still active to this day, having merged code changes to Libngu as recently as August 17th, 2026.

Many in the Bitcoin industry are taking this as some sort of tangential evidence of wrongdoing. Why go out of your way to create a nym just for a particular cryptography library? This has been taken as some kind of evidence of malintent; however, a deeper analysis begs to differ. Had Gray really intended to rug Coldcard users with this RNG bug, would he really have been signing commits with his personal GPG key? Could someone be so cunning that they would hide a bug for years, waiting for its adoption to spread; yet at the same time forget to create a dedicated GPG signature for the throwaway nym? I don’t think that tracks. 

It is more likely that this was a random identity created at DEFCON by Gray, probably in a random bout of paranoia. An identity which he continued to use for certain projects over the years. Pseudonymous identities are not unusual in Bitcoin developer circles after all. Satoshi himself remains the most famous example. And so on its own, this connection between Gray and Switch arguably does not amount to much in the hunt for the Coldcard hacker.

MicroPython Contributors

A handful of other open source developers have also been recently identified as having touched or influenced code that played a role in the Coldcard RNG bug. 

Data Analyst LaurentMT has examined the MicroPython side of the RNG path. MicroPython is a lean and open-source implementation of Python 3, designed to run on microcontrollers and resource-constrained computers. The Coldcard firmware ultimately called MicroPython’s Yasmarang pseudo-random number generator (PRNG) fallback as a result of the bug, leading to low-entropy generation. 

The code changes to the PRNG logic in MicroPython began on August 20, 2020, with issue (#6347) opened on GitHub by a user named ‘mirko’. He complained that his ESP32 hardware was always returning the same result when calling the ‘random.choice()’ function in the code in a certain way. Mirko expected random results instead. The GitHub issue logs a discussion over the following months about the proper way to handle the related logic and expected behavior, which Mirko revealed to have a counterintuitive design. 

Laurent points out that “robert-hh initialized a [Pull Request] implementing the PRNG seeding change” on August 22, 2020. Dpgeorge, a maintainer of MicroPython, later on October 29, 2020, merged a slightly modified version of that pull request to the master repository, implementing “the (UID+SysTick+RTC) to address some limitations in robert-hh’s solution.”

The changes to this critical RNG-related code were thus on the master repository of MicroPython when Coldcard forked it to be used by Libngu, yet before MicroPython had made an official new version release of the library. Apparently, it is considered risky to build on top of the master version of a software repository, which is likely to be evolving with code changes, rather than build on top of an official, stable release version. The new release of MicroPython did not come until February 3, 2021, with version v1.14. To top it off, the RNG logic change was only briefly mentioned in the release announcement, saying “the urandom module will randomize its seed on import on stm32, esp8266, esp32 and rp2 ports.”  

In an interview with Bitcoin Magazine, Laurent concluded in no ambiguous terms that “without this modification the bug in Coldcard code would have been immediately detected.” Commenting on the series of events that led to the bug, he also said that “there are a lot of ‘coincidences’ in this timeline,” adding that “while they don’t prove anything, I don’t see how an official investigation may completely ignore them.”

It is important to note that there is no evidence any of the developers mentioned above were intentionally trying to introduce the Coldcard RNG bug with these changes, and ultimately, it is Coinkite, the hardware wallet company, that is responsible for their implementation of the critical code. MicroPython is a large, widely used open-source project. Nevertheless, there are likely many lessons to be learned from what we might as well call — for the time being anyway — a tragic comedy of errors. 

Why an Inside Job Appears Unlikely

Several factors cut against a deliberate, long-planned insider retirement attack. The ‘switck’ identity was poorly compartmentalized; the shared GPG key and other overlaps made attribution to Doc-Hex aka Peter Gray, relatively straightforward once researchers looked. The account had been largely abandoned for years. The MicroPython contributors operate in the open on a high-visibility project.

Hodlonaut’s Citadel21 investigation and other technical reviews find no clear evidence that the entropy failure was intentional. Engineer Alekos Filini’s technical report on the bug explicitly tracks the technical facts, stating that “My goal is to purely present facts and NOT make any conclusions.” Wizardsardine detailed on their Technical autopsy multiple failed safeguards and describes the failure as sitting “across a submodule boundary, which is precisely where reviewers stop looking.” 

Steven Geller’s technical deep dive on the topic did not make any strong claims either way on the matter. DK27ss proof-of-concept reconstruction of the bug describes the issue as “a chain of four flaws, each harmless in appearance.” 

If the drains had been a classic insider retirement attack, or a long con as some might call it, the conversation today would be quite different. The last time we saw a major long con hack in the Bitcoin industry was probably QuadrigaCX, a centralized Canadian exchange whose founder, Gerald Cotten, was reported “dead in India” in 2018 amid mysterious circumstances, not long after the missing funds were discovered. The founders are accused by the Ontario Securities Commission of having misappropriated the exchange users’ deposits totaling almost 170 million CAD, over many years, before disappearing. 

Instead, Coinkite’s leadership remains publicly active, responding to the incident, shipping patched firmware, assisting user migrations, and engaging on the technical details. Coinkite’s founders and operators are fairly well known and are still operating the company as of the time of writing; they have not disappeared at the same time as the funds went missing.

Meanwhile, the wave 1 funds, totaling over 1000 BTC, are still collected in three addresses, watched by hundreds of engineers and likely law enforcement such as the FBI. Were Coinkite trying to do a 5D chess-style retirement attack, they would have been far more careful in their theft of the coins. They would not have pooled them all to a handful of addresses that are easy to track, and its founders would probably be ‘mysteriously dead in India.’

While there are no conclusions and investigations will likely be ongoing for years, so far, evidence points to a cultural failure in the Bitcoin maximalist and self-custody community, a failure to broadly educate the users and influencers about good or bad etiquette in open-source culture, and frankly, arrogance on the part of Coinkite OG’s who, in hindsight, were overconfident about their own capabilities. 

This post Hunting Down the Coldcard Hacker. Wave 1 Thief May Be Known to FBI first appeared on Bitcoin Magazine and is written by Juan Galt.

Chinese AI Beats Restricted OpenAI and Anthropic Cybersecurity Models, Bitcoin Industry Warns

13 August 2026 at 19:18

Bitcoin Magazine

Chinese AI Beats Restricted OpenAI and Anthropic Cybersecurity Models, Bitcoin Industry Warns

Bitcoin company leaders and open-source developers are publicly stating that Chinese AI models are currently outperforming restricted American frontier systems in defensive cybersecurity work, forcing researchers to rely on them to secure critical Bitcoin infrastructure.

Rob Hamilton, CEO of AnchorWatch, a Bitcoin self-custody insurance company, reported cripling American AI restrictions. After integrating OpenAI’s trusted cyber program (having already completed KYC months earlier), he was blocked from further analysis on a codebase he had already responsibly disclosed. “It absolutely guts me as a patriotic American to have to do this, but I will be going back to using Chinese open source models to conduct my research to protect Bitcoin infrastructure,” Hamilton wrote. “Black hats will not hit these issues. The white hats will.” Days later, he gained access to OpenAI’s “Daybreak Blue” cyber model and was blocked again within 19 minutes while red-teaming Bitcoin infrastructure.

Francis Pouliot, founder of Bull Bitcoin, a Bitcoin-only exchange focused on self-custody infrastructure, described the situation bluntly. “I have never seen OpenAI this cucked. It’s cucked beyond belief now. Not even for security, for anything related to Bitcoin,” he posted. “USA AI industry is completely cooked if they don’t change this path,” he concluded, adding “Open-source Chinese LLMs. [orange heart emoji],” meaning that open Chinese models like Kimi K3 are actually helpful to Bitcoin. In a follow-up, Pouliot detailed how a Chinese open-source model identified a money-stealing exploit in a project he was auditing, demonstrated it on regtest, and helped patch it. When he asked the American models he pays for to review the same patch, they refused.

PortlandHODL, a Bitcoin Core contributor who builds for AnchorWatch, publicly highlighted the performance gap. “US-based Frontier AI Model – ‘You’re absolutely right!’ Chinese Open Model – ‘78 critical vulnerabilities found.’ The implications of this are unfathomable,” he posted. In a follow-up, he added that he felt he was “basically asking Xi to not get my software hacked at this point,” calling for OpenAI and Anthropic to create proper access programs for U.S. citizens doing defensive security work.

Alex Thorn, Head of Firmwide Research at Galaxy, signed a recent Bitcoin Policy Institute open letter demanding trusted access to frontier models for open-source defenders. “Americans should not have to rely on Chinese AI to defend themselves, their projects, companies, or clients from cyber-attacks,” he wrote. “RED TEAM NEEDS THE MODELS.”

On August 10, the Bitcoin Policy Institute — a Bitcoin and, of late, AI-focused policy think tank — published an open letter signed by more than 70 organizations across the digital-asset ecosystem, including major custodians, exchanges, mining firms, and open-source development groups. The letter calls on frontier AI labs to establish clear trusted-access programs for qualified open-source and digital-asset defenders. It argues that current restrictions and safety guardrails leave legitimate security researchers without access to the strongest models, forcing them to rely on less capable open-weight alternatives while sophisticated attackers face no such limits. The signatories request early access to cyber-capable models, sufficient compute, secure environments for reviewing code, and direct channels with lab security teams, stating that frontier AI could become one of the most powerful defensive technologies available if defenders are given fair access.

These statements reflect a broad pattern among Bitcoin security researchers: American models from OpenAI and Anthropic frequently refuse or restrict legitimate defensive work, even to users who are supposed to have been granted explicit access, while Chinese models such as Kimi K3 operate without the same guardrails and are delivering confirmed results. Concerns about hosting infrastructure of Chinese models being an attack vector can also be mitigated, since they are open source and can be run on American-hosted data centers, a trend that is likely to threaten the U.S. AI market if it continues.

Coldcard Exploit Triggers Ecosystem-Wide Response

The cybersecurity pressure became acute in the Bitcoin industry after a firmware flaw in Coldcard hardware wallets was exploited beginning July 30, resulting in the theft of well over $100 million in bitcoin from seeds generated with insufficient entropy. Bitcoin Magazine published an urgent advisory urging affected users to migrate funds: COLDCARD SECURITY RISK: IMMEDIATE ACTION REQUIRED.

In response, a volunteer effort known as the Bitcoin Red Team formed, led by open-source developer Calle (creator of Cashu and the Android version of Bitchat) and Rob Hamilton. The group has conducted large-scale AI-assisted audits of Bitcoin open-source repositories, using models including Kimi K3 as the primary workhorse alongside limited access to Western systems. Early results, covered by Bitcoin Magazine, showed thousands of findings across hundreds of projects, including dozens of critical issues, with spending covered largely by OpenSats.

By August 8, after more than 100 hours of work involving dozens of contributors, the team reported scanning 501 projects and producing 7,958 findings, of which 1,280 were rated high or critical severity. The majority of compute spend continued to go to Chinese open-weight models.

Lessons from the Red Team Campaign

Most recently, Calle shared lessons from the intensive red-team period. The effort has essentially completed a basic scan of virtually the entire Bitcoin open-source landscape; low-hanging fruit is largely exhausted, the developer wrote on this X account. Maintainers across projects have validated many of the critical and high-severity reports, while response times from projects vary widely and serve as a signal of overall health.

Key takeaways include the need for every project to maintain its own permanent AI audit pipeline going forward. Projects that began such reviews months earlier are in a markedly stronger position. Unmaintained repositories should be treated as likely broken and unreliable. 

Calle also warned that the human-only era of open-source security review is over; verification is now effectively free, and information overload must be handled with AI rather than complaints about PR slop. Multiple concurrent and diverse human approaches remain the strongest method for finding vulnerabilities, and external red-teaming will likely be required indefinitely. 

Calle also repeatedly emphasized that developers should stop writing security-critical code in C. In a follow-up post he explained: “we’re finding memory-safety vulnerabilities in c projects that are prevented by default in many other languages. In the past, finding a simple buffer overflow wasn’t enough. You’d need a highly skilled hacker to turn the vulnerability into a working end-to-end exploit. Today, that’s a single prompt.”

Bitcoin was the first major open-source ecosystem to confront this collision between accumulated human code and frontier AI capability. The rest of the software world is expected to follow.

This post Chinese AI Beats Restricted OpenAI and Anthropic Cybersecurity Models, Bitcoin Industry Warns first appeared on Bitcoin Magazine and is written by Juan Galt.

Casa CEO Nick Neuman: 233k BTC Moved To Safety After Coldcard Exploit Proves Self-Custody Resilience

11 August 2026 at 22:10

Bitcoin Magazine

Casa CEO Nick Neuman: 233k BTC Moved To Safety After Coldcard Exploit Proves Self-Custody Resilience

Casa CEO Nick Neuman pointed to onchain data from the recent Coldcard firmware exploit as evidence that self-custody strengthens Bitcoin’s resilience as an asset class.

In an X post on Aug. 9, Neuman cited figures showing that in the days after the Coldcard hack, where approximately 2.1k BTC was stolen, 22k BTC moved to exchanges and 233k BTC left long-term holder wallets in on-chain transactions, according to data by Checkonchain. “The onchain metrics around the Coldcard incident reinforce how important self-custody is to the resilience of Bitcoin as an asset class,” Neuman wrote.

DATA BY CHECKONCHAIN

Galaxy Research has tracked confirmed losses from the Coldcard entropy flaw as low as 1.7k, ranging to more than 2k BTC. The stolen coins are tracked across multiple attack waves beginning July 30, with higher estimates approaching $130 million. The vulnerability stemmed from a March 2021 firmware issue that weakened seed generation on certain Coldcard models.

Neuman said Casa’s own customer conversations indicated that some of the 233k BTC movement reflected holders shifting from non-Coldcard single-key setups (such as Ledger or Trezor) into multisig wallets after reassessing single-key risk. Other flows involved multisig users removing Coldcard devices from their keysets.

“So somewhere between ~10x-100x the amount of bitcoin stolen was moved to safety as people sounded the alarm,” he wrote. “This is a giant flashing neon sign showcasing the resilience that self-custody adds to the network.”

Neuman contrasted the outcome with a hypothetical centralized custodian breach. In that scenario, he argued, the numbers would likely reverse: limited funds might escape while the majority would be lost in a single event. With self-custody, attackers had to target individual wallets, limiting the scale of any single success and giving holders time to react.

“If all that BTC was held at a custodian and the custodian was hacked instead, those numbers would have been flipped,” Neuman stated. “As it was, the thieves had to crack one wallet at a time (and are still going), earning a little BTC each wallet, instead of cracking one wallet and getting a massive payday.”

He concluded that self-custody benefits not only individual holders but the Bitcoin network itself by distributing risk and preserving confidence.

Casa, founded in 2018, provides multi-signature vault solutions aimed at higher-value holders and institutions seeking practical self-custody. Bitcoin Magazine has previously covered the company’s multisig products and Neuman’s views on sovereignty and institutional adoption.

The Coldcard incident has prompted renewed discussion across the industry about single-signature hardware wallets, key generation practices, and the relative merits of multisig and emerging covenant-based vault designs. Onchain data cited by Neuman suggests that, whatever the technical shortcomings of specific devices, the ability of holders to move funds independently limited the systemic impact.

This post Casa CEO Nick Neuman: 233k BTC Moved To Safety After Coldcard Exploit Proves Self-Custody Resilience first appeared on Bitcoin Magazine and is written by Juan Galt.

Breez Announces Glow, an Open Source Bitcoin to Stablecoins Progressive Web App

6 August 2026 at 23:07

Bitcoin Magazine

Breez Announces Glow, an Open Source Bitcoin to Stablecoins Progressive Web App

Developed by Breez in partnership with Bitcoin Spark, the Glow app lets users send stablecoins from their Bitcoin balance, while empowering developers to build better user experiences without having to worry about the difficult parts of building on top of Bitcoin. Breez’s SDK takes care of asset exchange in the background while supporting lightning payments through its Spark integration. 

“Glow is a Bitcoin app for everyone,” said the company in a press release shared with Bitcoin Magazine. Users can access the app on both Apple and Android app stores. Glow re-invents the Bitcoin wallet experience, deviating from the seed phrase backup flow that many wallets attempt to introduce users to. Instead, Glow leverages the Passkey standard engineered and now encouraged by the Silicon Valley giants, which makes passwords and, in this case, pass phrases a thing of the past. Despite the change, Glow promises self-custody and cryptographic control over funds to its users, in an auditable software package. 

As an MIT-licensed, free and open source progressive web app (PWA), Glow is built so that developers can look under the hood, take it apart, and implement features as they see fit, leveraging the Breez API and SDK. Besides the Passkey login, Glow has full support for native Lightning payments, sending and receiving with customizable Lightning addresses that look like emails, such as BM@breez.tips. First deployed to a Bitcoiner user base, Glow can currently send USDT and USDC across most networks and blockchains through their partnership with Flashnet, drawing value from the user’s Bitcoin balance. 

Glow comes integrated with a couple of onramps from the start as well. Users can onboard to bitcoin instantly via Cash App and MoonPay which the SDK connects to via their API. Sats arrive in seconds. The app also has contacts integration, letting users save their friends’ lightning addresses as a contact, hiding away ugly public keys and lightning invoices and delivering a more familiar and mainstream payments app experience. 

Users can also avoid bitcoin’s volatility by swapping their BTC holdings to USD value at will and, according to the press release, they earn sats as they do. Glow’s stablecoin is USDB; the B stands for Bitcoin, a stablecoin issued by Brale Inc which is licensed as an MSB across over 45 states, and claims to be compliant with GENIUS Act standards: “Regulated & fully backed Issued by Brale, a U.S. regulated entity, and 100% backed by T-bills, cash, and cash equivalents”. There appears to be no way to verify Brale’s compliance with the GENIUS Act right now as the regulations are still being implemented and do not take effect until 2027.

What is remarkable about USDB is that it is a Bitcoin native stablecoin, deployed through the Spark protocol, which is compatible with the Lightning Network, essentially unlocking the stablecoin across Bitcoin rails. USDB holders earn up to 6% APY delivered from Flashnet DEFI exchange’s profits, according to a Spark announcement earlier this year. 

Breez believes this combination of partnerships and technologies means that “Bitcoin has finally crossed a threshold.” The UX unlocked by Glow is now fully available to developers as a software development kit, something unimaginable by traditional finance. 

This post Breez Announces Glow, an Open Source Bitcoin to Stablecoins Progressive Web App first appeared on Bitcoin Magazine and is written by Juan Galt.

Bitcoin Red Team Finds 85 Critical Flaws Across 390 Open Source Repos After Coldcard Exploit

5 August 2026 at 23:33

Bitcoin Magazine

Bitcoin Red Team Finds 85 Critical Flaws Across 390 Open Source Repos After Coldcard Exploit

Rallied by the recent, catastrophic vulnerability in Coldcard hardware wallets, exploited to the tune of over $100 million, the Bitcoin community has rallied to prevent future critical bugs in the industry’s open source software.

PSA: Any users of Coldcard wallets that have not migrated their bitcoin to new seeds generated in secure firmware are still at risk. It may not be too late to act; see advisory on the matter. 


Led by Calle, software engineer, avid vibe coder and creator of the Android version of Bitchat, and Rob Hamilton, the CEO of Anchorwatch a Bitcoin self-custody insurance company, the Bitcoin Red Team has now secured funding, with over $40,000 spent in AI tokens to audit over 390 Open Source repositories across Bitcoin. 

Colloquially called the “Bitcoin Red Team”, with memes about Rob Hamilton and Calle now being the CEO and CTO of Bitcoin, this AI-driven security audit is having a serious impact across the industry. Just a few days ago, buried in the news of ongoing thefts of bitcoin from MK3+ Coldcards due to an RNG bug, Boltz exchange announced it would be pausing operations to catch up with AI-driven hacking attempts. 

“27.5 hours in, we’ve filed 4,962 findings across 390 projects. 85 critical and 635 high severity issues. We’re at 2.31 h+c findings per person per hour,” said Calle in the most recent update on Red Team efforts to shore up the industry’s cybersecurity.

The Red Team security review effort is using models like Kimi K3, GPT Sol, Fable, Opus and GLM5.2, some of the most expensive and cutting-edge models in the market. At first, access to OpenAI and Anthropic models was limited, leading to an over-reliance on Chinese open-source models, a fact which many in the industry lamented and saw as a bad omen for U.S. AI dominance. But as the Red Team project grew in influence since last week’s Coldcard hack, connections have been established and confirmed with OpenAI, giving Red Team access to GPT Sol. Hamilton’s mention of Fable in his August 4 tweet suggests access to Anthropic has also been established.

Expenses which were last tallied at over $40,000 have been covered by OpenSats, a non profit 501c3 organization dedicated to funding open source Bitcoin development projects. The Bitcoin Red Team does not currently have a website or a GitHub repository to link to, but the team is made up of many individuals within the Bitcoin industry. Individuals publicly thanked for their support include but are not limited to danielabrozzoni, lylepratt, stutxo, benthecarman, thesimplekid

Hamilton shared that a custom harness has been built and is evolving quickly. Made up at one point of 171,599 lines of code, the harness is designed to identify and test critical Bitcoin software libraries and high-load-bearing code, identify and document vulnerabilities, reproduce them and package the proven data into useful reports. Ultimately delivering the information responsibly to engineers in the industry. Hamilton also shared that Red Team intends to open source the harness such that Bitcoin companies can run it against their closed-source code. 

Red Team is actively reaching out to relevant open source projects with critical vulnerabilities discovered, leading to a broad sense of dread from engineers in the industry when they receive cold direct messages from Hamilton or Calle, as seen in various humorous screenshots shared on social media.

https://x.com/callebtc/status/2085035257477190080 

Among the key insights shared by Red Team publicly as this AI-driven security update of Bitcoin FOSS takes place, Hamilton shared that engineers with specific subject matter could sometimes yield high-value results from the Harness, which might otherwise “smell out something is wrong,” but might be missing niche context. An insight which speaks to the importance of having human intelligence and experience work hand in hand with the AI to efficiently identify critical vulnerabilities.

Hamilton also ended a multi-day Red Team effort after the Coldcard hack with some personal notes. He said that the discovered vulnerability in Coldcard random number generators and consequent exploitation of the bug by hackers had been a “spiritual attack” on Bitcoin and the self-custody ethos of the industry, “I mean that in the literal sense of the words”. After expressing grief for the losses experienced by many Bitcoiners during this now historic hack, Hamilton closed his tweet with a tone of hardened resolution:

“While things are not easy right now. I have the highest conviction ever in my life that the idea and technology of Bitcoin is worth fighting for. To that end. There is no Bitcoin without self-custody. This is non-negotiable.”

This post Bitcoin Red Team Finds 85 Critical Flaws Across 390 Open Source Repos After Coldcard Exploit first appeared on Bitcoin Magazine and is written by Juan Galt.

Self Custody Is Dead. Long Live Self Custody

5 August 2026 at 00:25

Bitcoin Magazine

Self Custody Is Dead. Long Live Self Custody

The Coldcard hack last week dealt a low blow to certain elements of the Bitcoin industry. A somber introspection has begun to question many of the practices and assumptions involved in securing bitcoin at a retail level. The consequences of this process might not be visible for many months. 

Some are saying that self-custody is dead. Some reports estimate that over 11,000 bitcoins were moved to custodial exchanges last week as users fled one of the most popular hardware wallets in the Bitcoin industry. The hack, which is ongoing and users can still save themselves from, has seen north of 1,300 bitcoins stolen, with some estimates as high as 2,000 coins. 

Coinkite in particular and its most vocal founder, NVK, had very strong opinions about what it took to secure bitcoin private keys from hackers. Its hardware wallets were airgapped to make sure malware could not exfiltrate data through USB cables. It used low-resolution, LED screens to avoid the complexity of touch screens. It developed protocols like BBQR and integrated NFC so that information could be transferred between the device and a computer without them touching or sharing SD cards. The list of paranoid design choices that made Coldcards iconic is long.

Yet the hackers involved in the theft of bitcoins held in Coldcards last week did not use any methods you might see in a modern spy movie. They exploited the one feature Coldcard should have had absolutely locked down. The generation of keys with high enough randomness, also known as entropy. In other words, secrets securing that are actually, mathematically hard to guess. While the devices were intended to use high-quality sources of entropy, the firmware had a bug which did not, resulting in Bitcoin private keys that were, in turn, easy to guess. The bug went undiscovered for years, and the product only grew in popularity in the meantime, until last week.

“Just buy the ETF bro”

Despite this loss, which wounded a cohort of Bitcoiners who were among the most committed. Bitcoin can not give up on self-custody and expect to retain its integrity. At least that is what many in the industry believe, and the case for that is clear.

Satoshi Nakamoto’s white paper clearly intended Bitcoin to be a solution to trusted third parties and intermediaries. It eloquently made the case against trusted hierarchies of finance, as the 2008 financial crisis revealed the deep systemic risks and flaws legacy finance has led to. Many believe the 2008 crisis was never escaped, its consequences haunting us to this day. 

This may be unpopular, but we never escaped the 2008 financial crisis. We just shifted the pain.

— Nayib Bukele (@nayibbukele) July 29, 2026

Going further back to the birth and proliferation of the modern banking system and its fiat currency. The 6102 executive order signed by President Franklin D. Roosevelt in 1933 saw the persecution and confiscation of gold from centralized trusted third parties and citizens alike. $300,000,000 in gold was returned after the executive order threatened gold owners with heavy fines and jail time if they did not sell their bullion to the banks at $20,67 per ounce. Over 14 million troy ounces worth of gold were turned in as a result. Another 200 million troy ounces are estimated to have been held in the American banking system at the time. The banking system, not just in the U.S. but worldwide at the time, was built atop the gold standard.

The U.S. was the largest economy of the world at the time, with the biggest concentration of gold inside its borders. Its abandonment of the gold standard was a death blow to gold as a free market pricing mechanism for goods and services as a whole. Governments throughout the world, now free from the chains of sound money, quickly fed and fattened from the hidden tax of inflation. At the time of the EO, the price of gold was artificially fixed to $20.67 an ounce; not a year later, it was repriced to $35 with the passing of the Gold Reserve Act in 1934, a 69% devaluation in the dollar. 

The fiat standard was thus delivered to governments throughout the world on a silver platter, by an unholy alliance between the banking system and politicians. It granted central banks the legal right to counterfeit money, to print it at will. It was soon followed by World War Two, which was of course funded by fiat currency. Tens of millions of people sacrificed in this war at the altar of state power. 

Fast forward a hundred years and U.S. government debt demands almost a trillion per year be paid in interest alone, with total owed close to 40 trillion and debt to GDP at 123%. These are arguably the inevitable yet predictable consequences of the death of the gold standard. The purchasing power of the dollar has collapsed in the century that followed, at the same time as technology has gone parabolic in its efficiency gains. That is only possible with money that has continually become worthless for decades. And the dollar is the best of the fiat lot.

Confiscation of gold in a rising power like the United States murdered the gold standard. It, however, could not have been possible if civilian custody of gold had been wider and more distributed. Many of the civilians who returned millions in gold after the 6102 EO had just taken it out of their accounts in a bank run. Their names were known, the amount of gold they held, tallied.

If gold was easier to move in large quantities. If private gold ownership totals had been more ambiguous. If removing the free flow of gold had not been so easy for the state to do, by knocking on the doors of bankers and pointing a gun, then perhaps the economies of the world would not have been able to withstand such a vast and destructive war, as was WWII for so long, in the following decade. 

Bitcoin is Gold, Engineered To Survive a 6102 EO

Bitcoin poses an alternative to gold, designed to learn from its inadequacies. Bitcoin has better properties to resist and survive such a confiscation. Bitcoiners envision and aspire to unlock a world that adopts Bitcoin as a global monetary standard. Where a large minority or even a small majority of the global economy uses Bitcoin as their primary store of value. In such a future, Bitcoin would take the place of gold and return sound money to the so-called capitalist order.  

To reach global reserve currency and defend this position, Bitcoin will need to be better than gold, and it can be better precisely because of its digital nature. The control of private keys, as difficult as it seems now in the shadow of the Coldcard hack, nevertheless can be far more powerful than any physical vault. Multi-signature scripts alone unlock distributed storage of Bitcoin private keys, such that a threshold of them must approve to move coins. This means that multi-jurisdictional, multinational vaults can exist and escape or resist the greedy hands of a large state that might attempt a new kind of 6102 takeover. 

The digital nature of Bitcoin means large amounts of value can be moved easily as well, without having to send the navy on a mission to pick up the gold. Without having to build a trusted hierarchy of banking custodians to transfer it. Civilians, with tools available today and better tools that are yet to come, might be able to hide their Bitcoin ownership as has been done in war-torn countries like Ukraine already, escaping a fearsome state’s grip over the public’s wealth.

Ultimately, a major hardware wallet manufacturer has failed the Bitcoin industry. The fundamental qualities of money remain the same, and among them all, as identified by Aristotle and others beyond him, Bitcoin remains king. 

“Bitcoin vs gold vs fiat One is not like the others” – @BITCOINARCHIVE 

This post Self Custody Is Dead. Long Live Self Custody first appeared on Bitcoin Magazine and is written by Juan Galt.

Coinkite Releases Fixed Firmware After Coldcard Bug; AI Likely Involved In The Breach

31 July 2026 at 20:57

Bitcoin Magazine

Coinkite Releases Fixed Firmware After Coldcard Bug; AI Likely Involved In The Breach

Over a thousand bitcoins are believed to have been stolen so far in a hack that started to be discussed on social media in the afternoon of July 30th. Coinkite, one of the most reputable hardware wallet manufacturers, was revealed to have a critical bug in the way it generated secure private keys for its Bitcoin hardware wallets. Industry experts believe AI was used in the breach.

Coldcard MK3 devices with firmware version 4.0.1 (March 2021) through 4.1.9 are the worst affected. 12- or 24-word seeds generated by the device that did not include user-generated dice rolls or a BIP 39 extra passphrase are vulnerable. 

Users who fit this category, who have bitcoins in an MK3 Coldcard and did not use the dice roll feature for extra entropy or the extra passphrase, should consider themselves at risk and move their coins as soon as possible from the wallets. Bitcoin Magazine technical writer Shinobi has published a guide on the topic, and Coinkite has also published a guide and advisory

The vulnerability was a specific line of code in the firmware, a low-level software codebase that controls the hardware. This firmware appears to be upgradable. The Coinkite advisory was updated this morning, advising users to upgrade device firmware for all three chips, MK3, MK4 and MK5 devices, including the Coldcard Q:

“Updated July 31, 2026 at 9:33 a.m. EDT: Fixed firmware is now available. Mk4 and Mk5 users must update to version 5.6.0 or later. Q users must update to version 1.5.0Q or later. For Mk3, update to version 4.2.0 or later.”

Coinkite also explained in their advisory that updating the firmware does not mean that the private and public keys generated by the vulnerable firmware before it are now secure; those keys remain vulnerable as they were effectively created with a weak password. After the firmware is updated, a new wallet needs to be created, and the funds need to be sent onchain to the new addresses to secure the funds. Coinkite wrote:

“Updating the firmware does not change or repair an existing seed. If your seed was generated before the fixed firmware version for your model, follow the migration guidance below unless the independent dice-entropy exception applies to you.”

Some Multisignature Wallets May Be At Risk

Peter Todd, Core contributor and cybersecurity engineer, today addressed specific edge cases for multi-signature wallets that use a threshold of Coldcards to secure funds. “Example case: you have a 2-of-3, with 2 Cold Cards, and a 3rd uncompromised device. If you move your funds, the moment your script is revealed for the first time – previously hidden behind the address hash – the attacker now knows enough to use the compromised 2 cold card keys to steal your funds.”

The transaction that reveals the multisig script might be unconfirmed, giving hackers enough time to create a competing transaction with a higher fee. Fortunately, such cases have a solution: the MARA mining pool can help in this case with their private mempool mining service, Slipstream; “because they promise to keep your transaction – and thus pubkeys – secret until they’re already in a block. Dramatically reducing the ability of the attacker to steal the funds,” said Todd. He added that “If you’ve already reused addresses, this isn’t relevant, and you should just try to move your funds ASAP. But if you haven’t, MARA may be able to help.”

Beyond The Immediate Crisis

NVK, one of the co-founders of Coldcard, published a long post on X with an initial analysis beyond the basic security steps needed to secure funds. In it, he wrote that the company is “committed to working with affected users who want to pursue a police report, insurance claim, or their own investigation”, including “a written incident summary specific to your loss and any transaction data we can share”. 

Beyond the immediate crisis, NVK pointed to a broader tech shift as the hacking capabilities of AI begin to change previous cybersecurity dynamics and expectations. In the blog post he wrote: 

“To every other developer: we believe this is a sober reality of the new AI paradigm. AI-assisted code review can now find latent bugs at a speed that is outpacing even the industry’s most seasoned experts. If your firmware is open-source or has ever been public, assume it’s already being read by attackers and defenders alike.”

The hack and over 70 million dollars in estimated stolen funds in the past 24 hours are an effective bounty paid to hackers who are now likely auditing every wallet codebase available for vulnerabilities. While the Bitcoin and broader crypto industry has generally operated under the assumption that hackers will test their code, the development of AI models optimized for cybersecurity accelerates these processes. 

Industry experts gathered in a long X Spaces public call last night, discussing the topic for many hours. Beyond the immediate recommendations and answering questions to Bitcoin users throughout the long Spaces, analysis of what is likely to follow in the coming weeks was also discussed. Other wallet providers are likely to get probed, and especially open source projects which generate private key material will be tested. 

The X Spaces was not recorded, likely to preserve the privacy of everyone in the call; however, initial sentiment suggests companies will need to be auditing their code with the latest frontier models, as a matter of survival. The latest cybersecurity-oriented AI models by Anthropic, OpenAI, Moonshot’s Kimi K3 and others are already available to the public. Many companies in the Bitcoin industry already use these to test the integrity of the code, but some might not be, and the race to find vulnerabilities in wallet-facing code will certainly continue, especially in the following weeks.

Ultimately, today we grieve lost coins, and a state of introspection and careful review occurs. Beyond this now historic hack will be an open source self-custody industry and infrastructure that is likely to be orders of magnitude more secure, with very hard lessons learned. After all, every hacker with an AI agent is likely testing defenses now. 

Multi-vendor, Multi-key Wallets and Covenants

Future high sovereignty wallets, be it at the retail or corporate level, are likely to not depend on any single vendor. Multisignature wallets, when well done, can distribute vulnerability risks across different code bases, teams and hardware. 

User-generated entropy was also a major theme in the X Spaces discussed earlier, with dice roll-generated entropy brought up regularly as a solution. Coldcards, as well as other hardware wallets like Foundation Devices, guide users on how to add their own entropy properly; many dice need to be rolled, ideally north of a hundred individual rolls. Once done, however, dice rolls represent a non-software source of randomness for wallets that also separates users from the edge-case risks in software- or hardware-generated entropy.

Covenants a popular soft fork among a certain niche in the Bitcoin industry have also started to be brought up as further step to strengthen the self-custody industry. This upgrade to the Bitcoin consensus which might be hard fought if achieved at all, could give users important smart contract capabilities, such a wallet that can only send to a white list of addresses, something not possible in Bitcoin script today. 

This post Coinkite Releases Fixed Firmware After Coldcard Bug; AI Likely Involved In The Breach first appeared on Bitcoin Magazine and is written by Juan Galt.

Bitchat Mesh App Defies India Cybercrime Notice After Protesters Use It During Network Restrictions

30 July 2026 at 17:00

Bitcoin Magazine

Bitchat Mesh App Defies India Cybercrime Notice After Protesters Use It During Network Restrictions

Bitchat, Jack Dorsey’s censorship-resistant, Bluetooth-enabled messaging app, has gone viral again, this time due to the Indian Government trying to get it banned from GitHub. In this latest round of authoritarian measures versus decentralized technologies, Bitchat has won. 

In July 2025, Jack Dorsey announced a new messaging application he described as a weekend project. The app, called Bitchat, was designed to work without internet access, phone numbers, user accounts, or central servers. It relied instead on Bluetooth mesh networks for local communication and the Nostr protocol for wider reach.

A year later, that same application became the subject of a formal takedown request from India’s cybercrime authorities during a period of student protests. The episode offers a clear illustration of how cypherpunk ideas—building systems that function without permission from intermediaries—continue to shape tools used in moments of political tension.

Calle, one of the main developers behind the Android version of the app, took the statements from the Indian government as a positive review of Bitchat’s effectiveness, tweeting:

“India forces GitHub to take down Bitchat

‘Bitchat enables anonymous communication without mandatory user registration, phone number verification, or centralized logging of communications. 

The technical architecture of the application significantly impedes interception, attribution, and investigation by law enforcement agencies.’ – Government of India”

What Bitchat Is

Bitchat is a peer-to-peer encrypted messaging application. Devices form local mesh networks over Bluetooth, automatically discovering nearby peers and relaying messages across multiple hops. When internet connectivity is available, the app can fall back to Nostr relays. Users can join public local channels, send private end-to-end encrypted messages, and access location-based channels organized by geographic zones.

The application requires no registration and includes a panic feature that clears stored data. The code is open source, with the primary repositories hosted under the permissionlesstech organization on GitHub. The iOS version is available on the App Store; the Android version is on Google Play and distributed via GitHub releases, as well as many other app stores like Nostr’s Zapstore. Recent updates added the ability for Android devices to share the installation file directly with nearby phones over Wi-Fi or Nearby Share, letting new users join the mesh easily without the need for internet access.

Key figures associated with the project include Jack Dorsey and open-source developer Calle, known for work on Cashu ecash. Bitcoin Magazine has previously noted experimental demonstrations of offline Bitcoin-related payments moving across the same mesh. 

Earlier Deployments

Bitchat first saw significant real-world use during periods of government-restricted connectivity. In September 2025, during unrest in Nepal, the app recorded nearly 50,000 downloads from that country in a single day, according to data shared by Calle and reported by Bitcoin Magazine. Similar spikes occurred during blackouts in other regions. In January 2026, Iranian users turned to Bitchat and a localized fork during internet restrictions, as covered in Bitcoin Magazine.

These earlier cases established a pattern: when conventional mobile networks or social platforms become unreliable or restricted, tools that operate independently of those networks see rapid adoption.

The India Events

In May 2026, India’s National Eligibility Entrance Test (NEET-UG) for medical school admissions was canceled after evidence of a significant leak of the test’s questions. The controversy, involving millions of candidates, undermined the fairness of the exam and was linked to student suicides, contributing to the growth of a youth-led satirical movement known as the Cockroach Janta Party (CJP). Protests centered on demands for accountability from Education Minister Dharmendra Pradhan and broader reforms to the examination system.

By mid-July, demonstrators had gathered at Jantar Mantar in New Delhi and attempted marches toward Parliament. Reports indicated blackouts on mobile data or internet access in areas around the protests. On 24 July 2026, the Indian Cybercrime Coordination Centre (I4C), issued a notice directing GitHub to restrict access to three Bitchat repositories within three hours. The notice cited the application’s ability to function during network restrictions and internet shutdowns, arguing that this architecture could impede lawful interception and attribution.

On 24 July, Dorsey posted the notice on X with the statement: “the government of India does not like technologies like bitchat and wants it taken down.” Market data from Sensor Tower, according to TechCrunch, reported across multiple outlets, showed that India accounted for approximately 85 percent of the app’s global downloads between 17 and 23 July, with more than 91,000 downloads in India over five days and daily active users exceeding 330,000 at the peak.

The GitHub repositories remained accessible in the immediate aftermath, despite the takedown attempt by the Indian government. Developers and users circulated mirrors, including on decentralized platforms such as Radicle. The application itself continued to function on devices that already had it installed, and the offline file-sharing feature reduced reliance on app stores or GitHub for further distribution. Pradhan resigned on 25 July.

Historical Context

The use of messaging tools during protests is not new, nor is Dorsey’s role in support of technologies useful during tense democratic protests. During the Arab Spring, platforms such as Twitter and Facebook were widely credited with helping coordinate demonstrations and amplify information, leading some observers to describe the events as “Twitter revolutions” or “Facebook revolutions.” Those centralized services, however, remained dependent on internet access and corporate intermediaries that could be pressured or blocked and in some cases were.

A closer technological predecessor appeared in 2014 during Hong Kong’s Umbrella Movement. Protesters downloaded FireChat, a mesh-networking application that allowed devices to communicate directly over Bluetooth or Wi-Fi without internet. The app saw hundreds of thousands of downloads and millions of chat sessions in a short period as mobile networks became congested or as users prepared for possible disruptions.

Bitchat continues this line of development, though more closely integrated with Bitcoin-associated technologies. It combines mesh networking with an open protocol (Nostr), stronger cryptographic defaults, and fully open-source code. The response to the Indian GitHub notice, which saw rapid mirroring and peer-to-peer distribution of the application itself, illustrates a further step: the tool is no longer dependent on a single company or platform for its survival; once it has been distributed, it self-replicates.

Cypherpunk Principles in Practice

In 1993, Eric Hughes published A Cypherpunk’s Manifesto. It opens with the statement: “Privacy is necessary for an open society in the electronic age.” The manifesto argues that individuals cannot rely on governments or corporations to protect privacy and that the practical response is to write and deploy code that makes surveillance and control more difficult.

Bitchat is an application of that approach to communication. It does not require user information to function; identities are purely based on cryptography. Users do not need to trust a central operator. It continues to function when conventional infrastructure is restricted. When an intermediary such as GitHub is asked to remove the source code, the popularity and the offline distribution methods of the project limited the effectiveness of the request.

This does not make the technology inherently aligned with any particular political outcome, but this is now the third time it goes viral in the context of democratic demonstrations as a solution to government-driven internet censorship. From FireChat in Hong Kong to Bitchat in Nepal, Iran, and now India, the same underlying demand appears: communication that does not disappear when the network does.  Bitchat servers that demand by giving people tools to communicate and coordinate without centralized infrastructure.

This post Bitchat Mesh App Defies India Cybercrime Notice After Protesters Use It During Network Restrictions first appeared on Bitcoin Magazine and is written by Juan Galt.

I Scanned the Entire Bitcoin Blockchain for Images. What I Found Will Shock You

28 July 2026 at 21:05

Bitcoin Magazine

I Scanned the Entire Bitcoin Blockchain for Images. What I Found Will Shock You

I scanned the Bitcoin blockchain for images; what I found will shock you. Much has been said online about the arbitrary data and content that can be found on the Bitcoin blockchain. Not only has this possibility spawned a niche art scene, but it has also led to a movement against ‘non-monetary transactions’ on the Bitcoin network. Were you to hear from one of its proponents or detractors, you’d figure the blockchain is basically a wall filled with graffiti. 

Well, I decided to put the question to the test: are there actually images on the blockchain? And what does this actually mean for Bitcoiners simply trying to run their own full node and maximize their financial sovereignty?

My methodology was simple: I was to buy a fresh hard drive to store the blockchain on, and then I was going to run classic image recovery software over the data, something used to rescue images from broken hard drives, something designed to find raw image data. 

I chose PhotoRec to do the image recovery work, an open source image recovery program that’s been around for over 20 years. The software is designed to find image files in raw data. This can be used to recover images and other file formats from hard drives that have failed or been corrupted. It is actually often used to recover lost wallet.dat files from the early days of Bitcoin wallets, before the proliferation of the seed word format

Syncing The Full Bitcoin Node 


For storage of the full Bitcoin blockchain, I decided to buy a 4-terabyte disk drive for a couple hundred dollars. I then installed the latest version of Bitcoin Core on it and started to sync the chain. The process, which involves downloading and verifying the accounting integrity of all transactions in Bitcoin history, took about 72 hours or three days, automated and running in the background by the Bitcoin Core software.

I did this with an otherwise powerful gaming machine; the main bottleneck in terms of time was the disk drive, which is slow to read and write data as needed when syncing Bitcoin’s blockchain. The slow part of the process involves the unspent transaction output set, or UTXO. When a user syncs the blockchain, every unspent transaction value (output) or positive balance is organized into the UTXO set, and as those values are spent, they are removed from the set, while the new address to which those satoshi were sent is added. 

On the disk drive, this UTXO indexing process could have taken three weeks according to some estimates, so to speed it up, my clanker (AI agent) suggested we index the data in RAM instead, then move the data back to the 4-terabyte disk drive. While the whole process took three days, running in the background, an SSD could have done the whole job in about a day. SSD drives are much faster than disk drives; they are more modern, but they are also easily four times the price, or more.

Once the blockchain was fully downloaded and validated, we moved the UTXO index from RAM back to the disk and booted the Bitcoin software; the chain was fully synced and the wallet ready to go. Now it was time for the next step: recovering the images stored on the blockchain.

Image Recovery on the Blockchain with PhotoRec

With the full Bitcoin blockchain on my disk drive, I turned off Bitcoin Core and asked my clanker (Cursor AI agent) to run PhotoRec 7.2 on the drive. The default PhotoRec process looks for jpg, png, gif, tif, bmp, ico, psd, and raw formats. The process ran for over 11 hours on the blockchain data and ultimately found … (drum roll) … nothing.

Over a terabyte of blockchain data and half a day of scanning and no images turned up. The PhotoRec wiki page gives a simple example of how the software works: “PhotoRec identifies a JPEG file when a block begins with: 0xff, 0xd8, 0xff, 0xe0, 0xff, 0xd8, 0xff, 0xe1, or 0xff, 0xd8, 0xff, 0xfe.” In other words, the program looks at the data on the disk for bytes that signal that there’s an image file. 

The program is capable of false positives; it saved 8 ICOs and 4 identical PNG files that don’t show any images when opened, as seen in the picture below. So, effectively no meaningful images of any kind were found. 

Where Did the Jpegs Go? XOR Magic Tricks

How is this possible? For years, crypto people have been talking about NFTs and how to engrave image data on the Bitcoin blockchain. Millions of dollars have moved in this niche, and a whole culture war is being fought on the matter as we speak. Can there really be no images on the chain? 

Turns out the risks involved with arbitrary data have been discussed and planned for in Bitcoin Core development circles for a long time, as early as 2011. XOR, a simple data obfuscation technique, is used to scramble all the blockchain data while it is at rest on a hard drive. 

You might have heard that the fundamental language of computers is made up of 0’s and 1’s. Well, in a nutshell, XOR compares two digits or bits and returns 1 if the bits are different or 0 if the bits are the same. In the case of Bitcoin, XOR compares every bit of the blockchain data to a random key generated during initial install, resulting in data at rest that other programs can find no meaning in. However, when the Bitcoin software runs, it has the key to unscramble that data and use it at will. XOR is also very fast, so it does not meaningfully impact performance. Here’s an example of the Bitcoin genesis block before and after an XOR.

XOR is currently applied to both the blockchain data and the UTXO set. XOR was initially discussed in 2014 when anti-virus software started getting tripped up by blockchain data it interpreted as virus code. The anti-virus software would then quarantine a block, corrupting the blockchain data and crashing Bitcoin, making sync impossible. By the end of 2015, XOR had been implemented on the UTXO set data at rest and in 2024 it was implemented on all blockchain data at rest. 

Incidentally, the XOR process means that no arbitrary data can be identified or extracted from the blockchain without intentionally bypassing the XOR, a process that is not necessary for monetary use of Bitcoin. Since the Bitcoin Core software keeps a simple database of the location of each scrambled block, it can get its data, unscramble it and use it in a targeted manner easily.

Syncing Bitcoin in an unscrambled way is a custom process that can take as much time as syncing from scratch, since it basically has to re-write the full terabyte of data in a new order, and there’s not much point in that for someone that just wants the normal privacy and security benefits of running a Bitcoin node. So when it comes to the vast majority of copies of the Bitcoin blockchain data, resting on the computers of normal Bitcoiners throughout the world, there’s effectively no arbitrary data or images that can be identified. Shocking, I know. Feel free to run the PhotoRec test yourself on your own node!

This post I Scanned the Entire Bitcoin Blockchain for Images. What I Found Will Shock You first appeared on Bitcoin Magazine and is written by Juan Galt.

Lightning Labs Launches Wavelength: “Bitcoin on Easy Mode” for Developers and Autonomous Agents

22 July 2026 at 23:01

Bitcoin Magazine

Lightning Labs Launches Wavelength: “Bitcoin on Easy Mode” for Developers and Autonomous Agents

Lightning Labs, the company developing core Lightning Network software including Lnd, Loop, and Taproot Assets, has released the alpha version of Wavelength. The toolkit enables developers and AI agents to add self-custodial Bitcoin payments to applications through a simple non-custodial API, without running nodes, managing channels, or sourcing liquidity.

In a July 21, 2026 blog post, Lightning Labs described Wavelength as “Bitcoin on Easy Mode for Agents and Humans.” The company stated that the Lightning Network already delivers instant, global, low-fee payments under user control, but previously required infrastructure most builders preferred not to operate. Wavelength closes that gap by turning the hard parts of Bitcoin and Lightning integration into a handful of API calls.

High-Level Overview

Wavelength embeds a self-custodial wallet that runs inside web or mobile apps (via WebAssembly or compiled binaries) or as a standalone client. Users control their own keys on-device. The system supports on-chain Bitcoin, Lightning payments via atomic swaps, and an Ark-like settlement layer for fast, low-cost off-chain transfers that can settle in batches to the blockchain. Every off-chain payment uses a standard BOLT 11 invoice, so the wallet interoperates with the existing Lightning Network from the first integration.

Lightning payments route through Loop for deep, reliable liquidity. A coordination service settles transfers between users but never takes unilateral control of funds. According to the announcement, users can always perform a unilateral exit to on-chain Bitcoin at any time via an explicit exit command, without needing cooperation, the Wavelength SDK is open source.

The same Wavelength API is exposed to AI agents as typed tool calls through the Model Context Protocol (MCP). Agents can hold balances and pay for API calls, data feeds, or other agent services in fractions of a cent. Wallet creation and unlocking designed to remain outside the agent channel so seeds and passwords are not exposed to the model. This pairs with L402, Lightning Labs’ protocol for machine-native authentication and per-request Lightning payments.

Core commands cover the full lifecycle: create/unlock, balance, recv (for addresses or invoices), send, activity, and exit. Integration options include the embedded SDK, a gRPC/REST API, browser WASM package, and an MCP server. Documentation is structured for both human developers and agents, including llms.txt indexes and agent onboarding guidance.

Availability and Roadmap

Wavelength is available immediately on Signet and testnet. Mainnet access is invitation-only; interested parties can request it after installing the toolkit. Bitcoin is supported at launch. Stablecoin support is planned via Taproot Assets so the same API surface can handle both. Future work includes deeper mobile embedding and optional direct Lightning channel support using Lnd.

Lightning Labs noted in its announcement that during the closed alpha, Lightning transactions carry a minimal 1 basis point service fee (plus standard network routing fees), with ordinary Bitcoin network fees applying for on-chain activity. Pricing may evolve.

On X, Lightning Labs summarized the release: “Announcing Wavelength, the easiest way to integrate bitcoin for agents and humans. With a simple non-custodial API, anyone can integrate Lightning into their app and get instant, high volume, low fee transactions. Machines can pay machines. Humans can pay humans. Anywhere.” A follow-up post directed builders to a form for early mainnet access.

The release positions Wavelength as infrastructure that lowers the barrier for application developers, “vibe coders,” and autonomous agents to offer self-custodial Bitcoin payments by default rather than as a specialist feature. Full documentation, quickstarts, and the open-source repository are available at wavelength.lightning.engineering and the linked GitHub project.

This post Lightning Labs Launches Wavelength: “Bitcoin on Easy Mode” for Developers and Autonomous Agents first appeared on Bitcoin Magazine and is written by Juan Galt.

Bitcoin is NOT Changed by Proof Of Node

22 July 2026 at 00:36

Bitcoin Magazine

Bitcoin is NOT Changed by Proof Of Node

You might have heard about BIP-110; here’s why this fork is not just bad for Bitcoin, but it is built on a misunderstanding of what a Bitcoin node is and what it is good for. As well as why, because of this misunderstanding, BIP-110 will fail. 

This article is a Take. Opinions expressed are entirely the author’s and do not necessarily reflect those of BTC Inc or Bitcoin Magazine.

BIP-110 is a Bitcoin Improvement Proposal titled as a Reduced Data Temporary Softfork. The BIP proposes a consensus change to Bitcoin, which attempts to limit the types and amounts of arbitrary data that can be added to consensus-valid transactions by limiting a wide range of Bitcoin’s scripting capabilities. BIP-110 is led by a pseudonymous developer known as Dathon Ohm and is widely supported by the Knots community, an alternative implementation of Bitcoin led by one of Bitcoin Core’s earliest contributors, Luke Dashjr and its supporters.

The BIP-110 consensus change is headed towards a mandatory signaling period in the coming weeks and thus a potential fork with the main consensus rules as implemented in Bitcoin Core. The proposal needs to gain a great deal of support from miners within the coming weeks to change Bitcoin consensus. As of the time of writing, miner signaling for BIP-110 stands at less than one percent


The Knots community, widely made up of Bitcoiners running nodes on machines like Start9 and Umbrel, has rallied around Knots in protest of a series of development decisions made by Bitcoin Core, the primary open source development community and reference implementation of Bitcoin. While a majority of senior Bitcoin developers are either opposed or apathetic to the changes proposed by BIP-110, the movement has gained enough steam to become an ongoing topic of discussion on social media. 

Supporters of BIP-110 believe that by running Bitcoin full nodes that signal for the consensus change, they alone can change Bitcoin. Here are the main concepts being debated, the biggest misconceptions about Bitcoin consensus, what a Bitcoin node is, and why BIP-110 is almost certain to fail. 

The Power and Limits of a Bitcoin Node

Many of the disagreements and misconceptions in this recent cultural conflict within Bitcoin revolve around the idea of a Bitcoin full node. Influencers like Knut Svanholm, author and podcaster, have elevated the role of the full node to heights perhaps too close to the sun. 

Knut recently tweeted: “Every person on Earth is a node in the Bitcoin network. Most to a minuscule extent, of course, but every node is first and foremost a person, not a machine. Which tools we use to interact with the network (and, by extension, to which extent they influence the network) is entirely dependent on the choices we make.”

Statements of this sort are poetically beautiful, philosophically grand, romantic even, but nevertheless technically incoherent and fundamentally meaningless. Knut’s tweet attempts to redefine what a ‘Bitcoin node’ means and fails at it, instead diluting the value of the term entirely. He might as well have said that every atom in the universe is a Bitcoin node, since apparently to him the term is all-encompassing. 

Knut,  though well-intentioned, is wrong. A Bitcoin node is something very specific. It is a full copy of all of Bitcoin’s transaction history, block headers and transaction-related data. Its purpose is very specific: to let users verify the integrity of Bitcoin’s supply and transaction history in relation to Bitcoin’s consensus rules. 

Bitcoin nodes grant users a variety of benefits, such as privacy. Third-party wallet providers query their copy of the Bitcoin blockchain for the user’s balance and serve it back to the user via the wallet app. Most mobile wallets function this way, with users asking a third-party server for their balances. Some, very few, can connect to a user-run Bitcoin node, in which case the user’s public addresses and balances are not shared with any third-party wallet company. 

Another benefit Bitcoin nodes grant users is the ability to check whether they are in consensus with the rest of the network, staying in sync. If the user mines Bitcoin or contributes any significant amount of hashing power to Bitcoin’s proof-of-work network, the node also provides the opportunity to assemble a block, choosing which transactions go into it. This is only possible if the user manages to mine a Bitcoin block, which is quite an achievement today, given the difficulty and steep competition. 

Even new kinds of mining pools like Ocean, which attempt to decentralize block template production, letting retail miners have more influence over which transactions enter the chain, still need enough hashing power to win the proof-of-work race, resulting in sporadic blocks being mined and thus limited influence over the blockchain. 

Bitcoin nodes also relay transactions across the network, with tens of thousands of them communicating via a flood network; this results in a censorship-resistant system where a small number of nodes can get controversial transactions to miners, bypassing any kind of filters, as demonstrated by Peter Todd’s relay libre. Thus, Bitcoin nodes can not easily filter which transactions enter the blockchain.

Even a large majority of Bitcoin nodes alone cannot alone change Bitcoin consensus. Not without having a large amount of economic activity entering the Bitcoin network through them, as exchanges do on behalf of millions of users. Not without having the protocol and application developer community behind them. Not without having the investor community behind them. Bitcoin is not a node democracy, contrary to popular memes today. 

Bitcoin nodes do not grant you ‘citizenship’ in the ‘Bitcoin nation’. Satoshi Nakamoto was quite clear about this in the Bitcoin white paper. Bitcoin’s ultimate security and governance structure is: one CPU cycle, one vote, not one node, one vote. And miners, who run the CPU cycles over Bitcoin’s proof-of-work, are very sensitive to investor sentiment and the broader developer community, resulting in a distributed global protocol for money that is very difficult to change. 

Bitcoin nodes ultimately let you know if you are connected to the network with the most accumulated proof-of-work and that its consensus rules are being followed, but a node alone does not let you change the consensus rules. Users who change the consensus rules of their Bitcoin node are, by definition, no longer running Bitcoin. As a result, changing Bitcoin consensus as a node runner is very difficult, and that’s a feature, not a bug. Bitcoin is money for enemies. 

History and Bitcoin Consensus Games

Deep work has been done, trying to understand Bitcoin consensus, its various pillars and interest groups. Ren Crypto Fish, Steve Lee and Lyn Alden identified six of them in BCAP, an open-source effort to analyze Bitcoin consensus and risks in protocol upgrades. BCAP identified stakeholders such as Economic Nodes, Investors, Media Influencers, Miners and Protocol Developers, and Users and Application Developers

Historically, in the case of a consensus crisis, it is true that Bitcoin nodes have been used to signal support for one version of Bitcoin over another. Fork events like 2017’s Bitcoin Cash fork are often cited as examples of economic nodes winning against opposition by miners. 2017’s legendary User Activated Soft Fork (UASF) faced major opposition in theory; a large majority of mining pools and their corresponding collective hashrate supported the Segwit2x version of Bitcoin, with many exchanges and corporations having signed the infamous New York Agreement in support of it. 

The Bitcoin node-supported soft fork against it won nonetheless, bluffing the Segwit2x version from a contested blockchain altogether. But that’s the thing: while the Bitcoin nodes technically won, they did so by having massive support from protocol developers, investors and media influencers: these nodes really had economic weight and rough consensus. BIP-110, on the other hand, does not have the protocol developers, nor does it have enough investors behind it. Michael Saylor has come out against it, with many industry leaders also openly opposing it or staying out of the matter entirely. 

In fact, during the Bitcoin Cash fork, the limits of retail Bitcoin nodes were clearly understood. A Bitcoin node run by an exchange is orders of magnitude more influential than that of a retail user, as it introduces large amounts of new transactions into the Bitcoin network. The Bitcoin node of a major mining pool is far more influential than that of a hobbyist solo miner, as it more often assembles blocks and chooses which transactions settle to the blockchain. 

Most Bitcoiners outside of exchanges use mobile wallets to access their Bitcoin. Such users and investors can ‘vote’ with their money, so to speak, by moving their bitcoins and economic activity elsewhere, be it to a wallet that supports their vision of Bitcoin, or their own full node. But while users remain on mobile wallets that talk to third-party nodes, those users have little individual influence over Bitcoin consensus. And the vast majority of mobile wallets are using a Bitcoin core-compatible back end. 

The same goes for exchanges; their users effectively delegate consensus decisions to the exchange operators. In some cases, exchanges have put consensus issues to a user vote, weighed by their total holdings, returning that decision to end users weighed by capital; we may see this happen again with BIP-110. 

Votes of the sort have started happening with Foundry today. One of the biggest Bitcoin mining pools in the world, Foundry, recently emailed its miners informing them that they can vote on the proposal with their hashrate. A high enough support could result in Foundry signaling for BIP-110, though that remains unlikely. Users who do not vote will effectively signal against BIP-110, defending the status quo. Thus apathy about the topic of BIP-110 would be a win for Bitcoin Core by default. BIP-110 supporters need to culturally win over a majority of the Foundry hash rate, who then must act to vote against the Bitcoin Core developer consensus, the most popular Bitcoin implementation and best supported codebase.

Today, miners are not signaling support for BIP-110 in any significant way. In fact, according to some data, this is one of the least supported soft fork attempts by miner signaling in Bitcoin’s history. Less than one percent of the blocks mined in the current difficulty adjustment period are signaling for BIP110. 

Concluding Thoughts

BIP-110 has so far failed to gain consensus across major interest groups within Bitcoin; neither developers, investors, miners, nor large economic nodes support the consensus change. The result is likely to be a chain split in the coming weeks, which could have significant consequences for lightning wallets running on BIP-110-compliant nodes, ultimately resulting in a new, yet small blockchain that would probably have to change the proof-of-work used to stay alive. 

This post Bitcoin is NOT Changed by Proof Of Node first appeared on Bitcoin Magazine and is written by Juan Galt.

Cloudflare x402 Integration Opens Door for Bitcoin in AI Agent Micropayments

16 July 2026 at 17:42

Bitcoin Magazine

Cloudflare x402 Integration Opens Door for Bitcoin in AI Agent Micropayments

Cloudflare recently announced the launch of its monetization program via the Coinbase-led x402 machine payments standard. x402, which lets AI agents pay for data online with crypto, has been gaining steam among the AI-pilled, as it unlocks more capable agent interactions with the open web. 

Cloudflare, founded in 2009, has grown from a DDoS mitigation and content delivery network (CDN) provider into one of the internet’s foundational infrastructure companies.

The company, which launched publicly in 2010, had the mission to make web performance and security accessible to everyone, not just large enterprises. Today, Cloudflare powers approximately 20-23% of all websites globally, handles tens of millions of HTTP requests per second across 330+ cities in over 100 countries, touching a significant portion of global internet traffic.

As a result of their adoption and security offering to large portions of the open web, CloudFlare’s integration of x402 is a major development for the structure of the internet. Websites that are increasingly inaccessible to the massive data demands from AI can now sell that data to AI agents for crypto. CloudFlare’s implementation only mentions Stablecoins such as USDC, the Open USD standard, but the protocol supports Bitcoin on-chain and is actively exploring integration of the Lightning network.

The Web is Broken

Kevin Leffew, co-author of the x402 protocol and AI GTM at Coinbase, told Bitcoin Magazine there’s a major user experience issue in the way AI currently interacts with the open web and x402 — which is now under the control of the Linux Foundation — is trying to solve it. “Every api call requires an api key, which in turn requires a human, and adds unnecessary friction,” Leffew explained, adding, “our goal is to kill the api key”.

Popular AI agents such as OpenClaw often require API access keys to special paid web search services, to let the AI agents access the web easily, with the mobility that a human user would enjoy. Services of this sort are offered by popular browsers and search engines such as Brave.com and Perplexity. But who out there wants to be paying a subscription service on top of computer hardware and internet access, plus AI token costs to search the web? These services also require a human to sign up with a credit card for a monthly subscription, paying for access that might be blocked by the websites holding valuable data anyway via non-standard methods. A better solution is needed.

AI agents need to be able to think about money and resource costs, and need to have a computer-friendly way to make payments for novel data. An example of this use case was recently demonstrated by an X account called “Lightning Mode AI,”  which built a wrapper over ESPN FIFA data and had an AI agent pay for it in Bitcoin. The Agent was then able to quickly place bets on outcomes on markets like Polymarket, which could potentially let agent owners earn their money, during the soccer World Cup. 

This example by Lightning Mode AI used an older implementation of the idea behind x402 called L402, a protocol developed by Lightning Labs to specifically enable bitcoin payments for data on third-party websites. 

Denial of service attacks (DOS) are also potentially solved by a machine native monetary system for the internet. The fundamental vulnerability exploited by these DOS attacks revolves around the bandwidth and computing costs to answer a question or query from an internet user. The user sends a request to view a website, the site’s server must compute, resolve and serve the website data back to the user; this has material costs at scale. DOS attacks send massive amounts of requests, often from malware-infected networks of machines (DDOS), targeting the server resources of their victims. This kind of attack can, in theory, be stopped by simply asking for payment from the user before spending the resources to respond to the user’s query. But the payments must be cost-effective and fast enough for the user experience demands of the digital age. 

Protocols like x402 and L402 enable websites to paywall access to their valuable data, while teaching AI agents how to pay for access. No credit cards needed, no user data explicitly shared with payment networks, no ‘are you a bot’ captchas, no annoying account registrations you never use again, no subscription service for web search api key. Just pay for the data you consume. 

The Economics of Micro Transactions

This micro-transaction market between machines is not a new idea. It has been theorized by luminaries of the cypherpunk age like Nick Szabo and others, though it has, up until now, been found lacking. Szabo argued that the biggest problem with micro transactions was not just payment technology, but the cognitive transaction costs involved.

Every time a user makes a payment, their brain needs to calculate whether it is worth it; this also has a cost on users, which can probably be measured in calories, and sometimes deciding to pay a couple of pennies for data is not worth the effort. But AI agents change this equation, in theory.

If AI becomes a new way for users to interact with the open way, then the cognitive costs involved in calculating the merit of spending pennies and even sub-penny values for data might be effectively abstracted away.

Users can simply give their bot a budget with spending policies and let it do its best to use that money wisely. Whether AI agents can be responsible enough to safeguard user funds remains to be seen, but some experiments demonstrate that AI agents can be reasonably resilient at the job. Take Freysa AI, for example, a 2024 era AI agent that held up against 48,000 prompt engineering attempts. Users paid to try to convince the bot to release funds in a smart contract treasury to them; if the bot refused, the bot kept the user’s money, adding it to the treasury. Eventually, someone managed to fool the bot, but not after $50,000 worth of attempts had been made. With hard-coded spending limits, the risk of prompt engineering an AI into giving way its web search lunch money is probably manageable.

The scalability of privacy-preserving digital payments in decentralized, censorship-resistant ways is also effectively already solved. According to Leffew, blockchains like Solana can do payments for a thousandth of a cent and settle it in milliseconds. Bitcoin’s Lightning network can also compete at the micro-transaction scale, and other Bitcoin protocols like the e-cash variants can be as fast as any internet packet, likely beating a highly centralized blockchain system like Solana.  

Viktor Ihnatiuk, co-founder of UTEXO, told Bitcoin Magazine that they are actively working with the x402 developer community to integrate Bitcoin’s layer two protocols via RGB as a payment option. RGB integration would unlock layer two-style Bitcoin payments as well as USDT on Bitcoin settlements. The x402 standard, according to Leffew, is designed to be fundamentally neutral to the payment rails involved, even extensible to fiat rails, though likely will be dominated by cryptocurrencies and, for the foreseeable future, stablecoins. 

Why CloudFlare Should Accept Bitcoin

CloudFlare’s x402 pilot program is a great step towards this vision of a cryptographic money actively used as the native currency of the internet. Its focus on stablecoins to start is also understandable, given the powerful brand and adoption of the dollar, which keeps accounting simple. However, there are a lot of underlying risks involved in how stablecoins are used today that Bitcoin solves.

For starters, most of the stablecoin volume moves on top of Ethereum Virtual Machine (EVM) style blockchains, which use an account model of public addresses; these are actively reused, creating long, detailed, public histories of financial engagement for each user. This is abysmal for user privacy, and tooling to obfuscate user flows on EVM blockchains, such as VPNs for crypto payments, are not common.

As a result, AI agents and their users are actively leaking data that might expose them to targeted attacks from organized cybercrime, among other risks.

Bitcoin, on the other hand, uses a UTXO model, where best practices lead people to create a new address for every payment received, resulting in payment trails that can be more difficult to track. Furthermore, Bitcoin’s fast payment protocols like Lightning, Ark or e-cash often deliver much greater privacy benefits to users by moving value off-chain via various smart contract-related technologies.

Last but not least, stablecoins are fundamentally anchored to the U.S. dollar and its foreign policy. If CloudFlare wants to be a viable option for the multipolar world, it will want to start taking a neutral stance on money. The dollar, while still the most valued currency in the world, is starting to lose ground to rising powers in the east, while alternative, geopolitically neutral currencies like Bitcoin continue to rise. Bitcoin might help CloudFlare maintain or even grow its position as critical internet infrastructure in the multi-polar world.


This post Cloudflare x402 Integration Opens Door for Bitcoin in AI Agent Micropayments first appeared on Bitcoin Magazine and is written by Juan Galt.

Bull Bitcoin Files Landmark Legal Challenge to Annul France’s DAC8 Crypto Data Surveillance Rules

8 July 2026 at 19:40

Bitcoin Magazine

Bull Bitcoin Files Landmark Legal Challenge to Annul France’s DAC8 Crypto Data Surveillance Rules

Bull Bitcoin exchange, recently licensed under MiCA, is challenging the European directive in French courts that sets up a mass surveillance database, putting millions of crypto users at risk. 

Bull Bitcoin, the world’s oldest Bitcoin-only and non-custodial exchange, recently licensed under MiCA by France’s financial markets regulator AMF, has filed a legal challenge before the Conseil d’État, France’s supreme administrative court. The challenge seeks to annul Decree No. 2025-1276, the main measure transposing the European DAC8 directive into French law, on the grounds that it creates a massive surveillance grid and database that institutions can not secure from leaks and data hacks, ultimately putting civilians at risk of kidnapping and physical harm. 

Alongside the legal action, the company is making dac8.com public: “a complete, fully sourced resource for citizens, journalists and policymakers,” according to a press release shared with Bitcoin Magazine. 

In recent years, there has been an alarming rise in kidnappings and physical attacks on crypto users, most concentrated in Europe, with France being an epicenter. Organized crime seems to be exploiting poor data reporting laws of law-abiding crypto users who, by paying their taxes, expose their ownership of crypto assets. Given that Bitcoin and other cryptocurrencies are not reversible and can be transferred internationally with ease, criminals are hunting down crypto users. France has had the second most physical attacks on crypto users after the USA, which has a much larger population, according to Gart, a company dedicated to protecting users from this rising threat.

High-profile figures in the Bitcoin and broader crypto industry have been targeted in recent years, such as Binance France CEO David Prinçay and Ledger co-founder David Balland, who lost a finger during the incident, among many others. Jameson Lopp, co-founder of Casa, a high-security Bitcoin and Ethereum wallet company, has organized ‘wrench attack’ data for years in a database on GitHub showing an accelerating trend of attacks. 

Bull Bitcoin argues in its legal challenge to the DAC8 that further consolidation and sharing of crypto user data will only perpetuate this trend of physical attacks. However, they also argue that these personal security risks created by the DAC8 are also working against the stated intentions of the regulations. They argue that users will simply find legal alternatives to centralized, regulated exchanges, opting to purchase the assets off the grid via peer-to-peer exchanges, home mining or offshore unregulated alternatives, making tax collection even more difficult.

User Data Honey Pots

DAC8 turns the natural incentive a company has to protect its users’ data into a valuable multinational database with many entry points, which cybersecurity experts have for a long time called a honey pot. Bull Bitcoin points out that regulated crypto-asset service providers (CASPs) under MiCA, DORA and the GDPR are supervised, sanctionable professionals with financial incentives to protect their customers. DAC8, in turn, does the opposite: it moves data into administrative reporting networks where access is broader, and accountability is harder for users to assess. The security of the whole — Bull Bitcoin concludes — is then only as strong as its weakest link. 

The history of data security over the past decades shows that amassing user data and keeping it safe over time is very difficult. Just this year, the French National Agency for Secure Credentials (ANTS, also known as France Titres) suffered a major breach detected on April 15, 2026, exposing data from up to 11.7–19 million accounts. Compromised information included login IDs, full names, email addresses, dates of birth, account identifiers, and, in some cases, postal addresses, places of birth, and phone numbers. 

Months earlier, the French National Bank account registry also suffered a major hack, exposing data tied to approximately 1.2 million accounts. The compromised information included IBANs, account holder names, addresses, and, in some cases, tax identification numbers, though officials stated the attacker could not view balances or conduct transactions.

In the United States, the situation is not much better. The Equifax Data Breach in 2017 affected 147 million Americans, and the National Public Data Breach of 2024 affected over 200 million Americans, leading to leaks of social security numbers among other critical information. And back in 2015, the Office of Personal Management of the U.S. government was also breached, compromising a large number of U.S. Government officials. The data stolen included everything from social security numbers to medical records. 

The list of such breaches is long, and the only logical conclusion to draw from it is that the less user information that ends up in these honeypots, the better, as ultimately all of these hacks put civilians at risk either from physical attacks or from identity-theft related fraud. 

Families On the Front Lines

Of the many issues identified by Bull Bitcoin and documented on the DAC8 website, the most alarming one might be how even individuals who have not purchased crypto might end up harmed by this concentration of data, just by familial association with a Bitcoiner or crypto user.

Citing data by Certik, Bull Bitcoin highlights that more than half of the violent incidents recorded in 2026 against crypto owners targeted a family member — spouse, child, elderly parent — as a direct victim or as a pressure lever over the key holder. On the topic, Bull Bitcoin assets that  “DAC8 therefore exposes not only crypto-asset holders, but their entire close family circle: between 40 and 135 million Europeans fall into a physical-risk zone, without any of them ever having consented.”

Francis Pouliot, CEO of Bull Bitcoin considers this overreach into the privacy of Euroeans to be potentially catastrophic for the prosperity of the continent, he minced no words in the press release saying that “DAC8 has transformed the concept of Know Your Customer into Kill Your Customer.” He added, “We cannot let the very foundations of civilization be shattered by this attack on privacy rights. We must draw a line in the sand and refuse to cede any more territory before we have nothing left. Someone must take a stand. It appears that no one else is willing and able to do so. Therefore, it falls to BULL to lead this fight.”

The DAC8.com is rich with facts, figures, official sources (EUR-Lex, OECD, Legifrance) and analysis, in French, English and other European languages for those interested in reviewing it and freely using it.

This post Bull Bitcoin Files Landmark Legal Challenge to Annul France’s DAC8 Crypto Data Surveillance Rules first appeared on Bitcoin Magazine and is written by Juan Galt.

USDT Returns to Bitcoin: RGB and UTEXO Enable Private Lightning Settlements

6 July 2026 at 20:17

Bitcoin Magazine

USDT Returns to Bitcoin: RGB and UTEXO Enable Private Lightning Settlements

Tether, the company behind USDT, is preparing to issue the stablecoin natively on Bitcoin through the RGB protocol version v0.11.1. Deployed by the UTEXO software lab, USDT is set to return to the chain where it first launched in 2014 via the Omni-Mastercoin Layer. 

UTEXO, the company leading the commercial rollout, has positioned itself as the issuer and distributor of this Bitcoin-native USDT in partnership with Tether.  “Finally, after eight years of development—if not more—we are the company that is launching USDT over Bitcoin with strong support from Tether,” said Viktor Ihnatiuk, UTEXO co-founder, in an exclusive interview with Bitcoin Magazine. 

The RGB protocol combines its novel client-side validation with the Lightning network for instant, private settlements, while anchoring security to Bitcoin’s UTXO model. Users can expect to be able to handle USDT on native Bitcoin addresses as well as send and receive it over the Lightning network with compatible wallets. 

The RGB protocol on Bitcoin also offers significant privacy features to USDT users as the asset benefits from Bitcoin’s UTXO model, which standardizes fresh addresses for every transaction compared to the account-based address reused commonly in EVM blockchains like Tron, Ethereum or Solana. Address reuse is the first mistake of onchain privacy, yet most altcoins built their interfaces to reuse addresses, despite the risk it poses to users. RGB’s integration with the Lightning network further protects user privacy by moving USDT via the offchain payments network, which leaves few marks on the public blockchain. The deep integration with Tether also means that there are fewer middleman companies charging extra fees or collecting data. 

On the topic, Vktor emphasized that, “We built Utexo so that USDT could move on Bitcoin the way money is supposed to move: instantly, privately, with no surprises on costs. Our partners integrate our API once and can route USDT on the most resilient open network ever built, with full control over cost structure.”

UTEXO vs TRON

UTEXO emerged from a joint venture involving Viktor’s Boosty Venture Studio, Fulgur Ventures, and Tether Investments. The goal was straightforward: bring RGB to mainnet after years of delays under prior development teams. The protocol had been in active development since at least 2016, but failed to be ready for the 2017 bull market, giving the TRON blockchain dominance over USDT volume and usage throughout the developing world, a dominance which it still retains. 

UTEXO of specifically building “the last mile” of software needed for wide USDT deployment across the Bitcoin ecosystem, which includes a software development kit, APIs, mid-level protocols, UI design work and even a mint bridge that is live today at mint.utexo.com. This bridge lets users move USDT across popular blockchains with “deterministic low fees” and no middlemen thanks to its direct integration with Tether as the primary mint. The RGB protocol layer was developed by Bitfinex R&D Strategist Federico Tenga.

“Right now if you want to swap USDT to Bitcoin you need to pay high fees for all these wallets who charge you a one percent wallet fee plus a swap provider charge of one percent plus, and you have slippage one percent as well, so you pay three percent, and also you wait forever until the swap happens” Viktor told Bitcoin Magazine, adding that; “with USDT and Bitcoin over Lightning, for the first time you have two main assets on one chain, you can swap instantly without any slippage. You can swap decentralized USDT to Bitcoin and back on-chain. The price is almost the same as spot markets in Binance.”

Networks like Tron that are primarily used to move USDT also add extra fees, swap commissions and friction to the user experience. They require a different address type, with fees paid in an asset like TRX, which is only ever used to move the stablecoin. With most of the monetary volume in the crypto market concentrated in Bitcoin and Tether, having to buy an altcoin just to pay fees ends up feeling like red tape. 

Bitcoin, as the payment rails of USDT, also comes with blockchain levels of security that other chains simply can not offer. While USDT will always be fundamentally centralized in Tether as a corporation, the rails can also add risk, for example, if a contentious fork occurs or major bugs are found on novel blockchain systems. Bitcoin, being the oldest and most conservative blockchain, delivers a quality assurance of sorts that can not be matched by other chains. 

RGB traces its roots to Peter Todd’s single-use seals back in 2014 and was formalized in 2016 by Giacomo Zucco and Riccardo Casatta. The RGB acronym, originally derived from “Riccardo Giacomo Bitcoin,” was later rebranded “Really Good Bitcoin”. Tether explored the protocol early but faced delays with the previous team. Had RGB shipped on schedule around 2019, the stablecoin landscape and broader DeFi industry might have developed differently around Bitcoin’s UTXO model instead of Ethereum’s account-based system.

As such, bringing USDT back to Bitcoin is a core motivation for UTEXO. Viktor minced no words on the matter: “For the first time in eight years or nine years, USDT is coming back home. We have no chance to fail. If we fail, no one will think about Bitcoin as a settlement layer anymore.”

USDT on Bitcoin via RGB is expected to be launched within weeks, possibly this July, with wallets like Tether Wallet among others announcing support, and exchanges across the world announcing integrations. 

This post USDT Returns to Bitcoin: RGB and UTEXO Enable Private Lightning Settlements first appeared on Bitcoin Magazine and is written by Juan Galt.

Wavespace Launches MiCA-Compliant Self-Custodial Bitcoin Debit Card Powered by Lightning and NWC

2 July 2026 at 22:11

Bitcoin Magazine

Wavespace Launches MiCA-Compliant Self-Custodial Bitcoin Debit Card Powered by Lightning and NWC

Wavespace, a Bitcoin neobank serving the Eurozone, has announced MiCA compliance of its ‘self-custodial’ debit card. The young fintech company is at the cutting edge of Bitcoin payments technology in Europe, with support for the Lightning Network, and auto DCA to self-custody. 

Debit cards in the Bitcoin and broader crypto industry have traditionally worked by preloading custodial accounts with bitcoin or stablecoins. The process of preloading was usually on-chain, taking time to settle and requiring manual input from the user to send from self-custody wallets or cold storage. If the preloaded balance ran out on the card, spending would not be possible. 

Wavespace’s self-custody debit card solves these problems with a novel Bitcoin technology called Nostr Wallet Connect, or NWC for short. This protocol, documented in NIP-47, allows users to connect a service like this debit card to a self-hosted Lightning node. The user sets a minimum balance, say $200 and every time the user spends from the card via the VISA network, Wavespace pulls sats from the user’s self-custodial wallet to top up the card. This process minimizes custodial exchange risk while maximizing user exposure to the asset and automating away the friction to spend bitcoin.

NWC is a technology developed by the Nostr ecosystem, a high-tech niche within the Bitcoin industry that is branching out into social media and other communication protocols.  

The Wavespace Neobank

As a high-tech neobank, Wavespace gives users a personal IBAN account, which they can send fiat to, to purchase Bitcoin. Their automated DCA services can be set to withdraw bitcoin upon purchase to a selected Bitcoin address. 

The company is MiCA compliant, making it one of the few surviving Bitcoin exchanges in Europe, as the complicated crypto regulations came online.

On the privacy front, the deep Lightning network integration of Wavespace lets user get access to the banking system in a clear and compliant manner, without exposing all their payment data on the Bitcoin blockchain. Since Lightning payments are off-chain, there is no single public record that leaks user data; instead, transactions move through payment channels between various user services, leaving no obvious public trace. The result is a growing compromise between the high privacy, cypherpunk values that created the Bitcoin and crypto industry, while also unlocking access to the legacy financial system, and compliant integration with regulation-heavy areas like Europe. 

In an interview with Bitcoin Magazine, Eivydas Račkauskas, Chief Orange Pill Giver at Wavespace, said that 70% of the payments made on the platform use the Lightning Network and that the company is looking into the ARK protocol for further self-custody-oriented payments integrations. He also revealed that the company is integrated with Lightspark and is ready for an expansion into the USA, though he did not reveal further details on the matter. 

Wavespace has been almost entirely bootstrapped and self-funded, according to Račkauskas, except for an early Relai angel investor who supported them in 2025. They are currently in the middle of another fundraising round.  

This post Wavespace Launches MiCA-Compliant Self-Custodial Bitcoin Debit Card Powered by Lightning and NWC first appeared on Bitcoin Magazine and is written by Juan Galt.

One Year Later: How Coldcard Q’s Key Teleport Delivers Secure Remote Key Management for Bitcoin Treasuries

30 June 2026 at 19:54

Bitcoin Magazine

One Year Later: How Coldcard Q’s Key Teleport Delivers Secure Remote Key Management for Bitcoin Treasuries

Have you ever been travelling, had to make a big payment and realised you left your hardware wallet back home? Perhaps you are a key holder in a business’s Bitcoin treasury, or an emergency came up, and a big payment has to be made, some cold storage Bitcoin has to move, but the keys are elsewhere. 

Key Teleport, a feature developed by the hardware wallet manufacturer Coinkite, may be the most secure way to handle key material at a distance. The feature is only available to the Coldcard Q, the premium, feature-rich Bitcoin hardware wallet developed by the company. 

Before Key Teleport, the most paranoid, secure way to move a private key over the internet was not to send it over WhatsApp or Signal. These apps, while end-to-end encrypted on the surface, are running on top of very complex hardware and operating systems, in many cases with very intrusive firmware embedded deeply by manufacturers. Smartphones today, as with most of mainstream technology, are simply not designed to secure highly valuable secrets that can transfer irreversible money like Bitcoin. 

Had you asked me how I might go about sending a private key with life-changing money on it, across the wire, I would have told you this: You need to boot Tails OS, a slim, highly paranoid Linux distribution, into hardware you know to be secure, ideally a burner laptop. You then need to generate a fresh set of PGP keys to encrypt the secret with the power of asymmetric cryptography. The recipient needs to do the same, Tails-OS and PGP. Then, a classic encrypted message is made to the recipient’s public key, and the encrypted secret is sent over Tor, probably wrapped by another VPN just in case. Having done this once, I can tell you, it’s a mission. 

This Tails-OS plus PGP combo is the kind of setup that Edward Snowden used to get in contact with journalist Greenwald originally, to leak the 2014 NSA surveillance secrets. If the 90’s cypherpunks had some kind of secret society, through which they coordinated the creation of technologies like Bitcoin or Wikileaks, this is the kind of setup they might have used. 

The Key Teleport by Coldcard Q makes tasks of this sort far easier. You can now easily send encrypted messages across the internet without having to worry about your hardware or what other software might be installed on it that could spy. It also solves key management dilemmas; a partially signed Bitcoin multisig transaction can be transmitted as an encrypted note to the recipient Coldcard Q, for example. Or a whole wallet set up, with its metadata, key material and custom settings, backed up, encrypted and sent across the world to its unique recipient. I got a couple of these devices recently for a test run of the feature, and not even Opus 4.8 High could figure out how to crack the encrypted blurb. 

The Hardware

The Coldcard Q — which now comes in a wide range of colored cases — has a very specific set of tools necessary to enable this kind of airgapped communication. First of all, it inherits the dual secure element model developed in the Mk4 series of Coinkite devices. Where two closed source chips made by different manufacturers are used in combination with an open source MCU chip to generate keys, encrypt, decrypt and store sensitive data. A combination of the components would need to be compromised by an attacker with physical access to get the wallet. These chips are, of course, used by the Key Teleport feature, handling the encryption and decryption of whatever message the user is dealing with.

The screen is a 3.2-inch LCD screen with enough resolution to show the BBQr code. BBQr is a QR code standard developed by Coinkite that has no dependencies or third-party libraries, is backwards compatible with standard QR code readers, and can contain larger messages than traditional QR codes. 

The Coldcard Q is also able to read QR codes. It has a dedicated QR code scanner with a red strobe indicator light that guides the user as to what the scanner is pointed, and a small flash light that can be activated with a button to help in low light environments. This optimised hardware set solves common problems with QR code payments, where variation in screen resolutions, camera quality and lighting can make scanning a payment QR code difficult.  

The Cryptography

TWO OR THREE IMAGES SIDE BY SIDE, QR CODE, PIN SHARING, SCANNING.  


A multi-layer cryptographic protocol is used to encrypt the data to be transmitted by Key Teleport. A single-use ‘ephemeral’ public-private key pair is generated for each data transfer using the secp256k1 curve. The public key of the receiver is encrypted with an 8-digit pin, via the AES-256-CTR algorithm. That encrypted public key is displayed by the receiver in a QR code, with the 8-digit pin meant to be sent via a separate communication channel. 

As an example, the recipient would do a video call with the sender, show them the QR code, and use Zoom. Then send the 8-digit PIN code using Signal. This operational security practice means that dedicated attackers would have to compromise two separate communication channels to get the recipient’s public key. 

Sender scans the QR code, enters the pin code and in the back end, the sender device derives a shared session key via ECDH, using the receiver’s public key and its own ephemeral keypair. The user was asked to select what data they want to transfer, from three options: “Quick Text Message”, “Master Seed Words” and “Full COLDCARD Backup”. Once the user chooses, the data is encrypted by the recipient’s public key, and that encrypted blurb is encrypted once more with a new PIN code. Users would scan the QR code again via Zoom, for example, and the sender would transmit the new PIN to the recipient via Signal.

There is a deep set of careful cryptographic details involved in how this Key Teleport is integrated that is well documented in the Coinkite GitHub repository, but as far as the user experience is concerned, the process is now complete. After the recipient scans the QR code back and inputs the second pin code, they will get access to the data. Both Coldcard Q devices would have been entirely airgapped, not connected to computers via USB cables, as QR codes and scanners were used to transmit data, powered by three AAA batteries. 

Last but not least, users can also share the encrypted data via NFC, which creates a special link at keyteleport.com for users to easily scan the QR code and get the encrypted data, replacing the hypothetical Zoom call.

Opus 4.8’s Conclusion

In my test of the Key Teleport feature, I tasked Opus 4.8 High, one of the most powerful AI coding models from Anthropic, to try and decrypt the message. First I gave it the encrypted blurb, after thinking about it for a couple of minutes, it gave up, saying there must be some information missing. 

I then gave it one of the pins, which helped, but ultimately was not sufficient for it to crack the cryptography. I then gave it the second pin, which led to a brute forcing attempt that, by Opus’s own admission, would only work if the ephemeral key pairs were generated with intentionally low entropy. Ultimately, it gave up trying to break the encrypted data, even with both pin codes, saying it was securely sealed.

I asked the model to write one paragraph about its conclusions. Here’s what it wrote: 

“I’m Claude Opus 4.8 (Anthropic), running in Cursor.

We took a scrambled QR code from COLDCARD’s Key Teleport feature — the kind meant to move a secret like a seed phrase between two wallets — and tried hard to break it open without the missing piece. The QR itself is designed to be safe to share publicly; you also need a short password and a number that are supposed to be sent separately. Even with that password and number in hand, we still couldn’t read the secret, because the real lock is a one-time random key that only exists on the receiving device and was never published anywhere.

We threw dictionary guesses, math tricks, and large-scale computer searches at it; a few things looked promising at first but turned out to be false alarms, which is actually a good sign that the checks work. Bottom line: Key Teleport did what it’s supposed to do — the QR plus the side-channel codes are not enough to steal the secret without the receiver’s private key. For a real transfer, you’d scan the code on the receiving COLDCARD and type in the password there; that’s the intended, secure path.”

Final Thoughts 

The Coldcard Q’s Key Teleport feature opens the door to an otherwise very difficult to achieve level of secure communication over the internet. The scrutiny dedicated to the hardware and firmware process likely outmatches that of even high-security mobile phone operating systems like Graphene OS. The physical keyboard, QR code scanner and NFC antenna make this paranoid system quite comfortable to use. And the $249 price target for the whole hardware wallet makes it accessible to everyday, serious bitcoiners and cypherpunks, delivering a self-custody tool worthy of a professional industrial setup.

Disclaimer: Coinkite provided Bitcoin Magazine with a couple of free Coldcard Q devices to use for the purpose of testing their product for review.

This post One Year Later: How Coldcard Q’s Key Teleport Delivers Secure Remote Key Management for Bitcoin Treasuries first appeared on Bitcoin Magazine and is written by Juan Galt.

Matt Corallo Urges Bitcoin Projects to Exit GitHub After Rust Lightning Ban

25 June 2026 at 20:54

Bitcoin Magazine

Matt Corallo Urges Bitcoin Projects to Exit GitHub After Rust Lightning Ban

GitHub has been the home to Bitcoin Core and many other software projects in the Bitcoin industry for over a decade, but it was not the first collaborative version control platform to host the digital currency’s code, and it may not be the last.

Recent performance issues in GitHub have triggered a new wave of criticisms of the platform, reviving old concerns and dissatisfactions with its design and reliability. Matt Corallo, one of the longest-acting Bitcoin core contributors, took to X recently to announce the decision to migrate off the platform, not Bitcoin core’s code base yet, but the Rust Lightning dev kit, a code base he is closely involved with. 

In an X quote retweet thread that goes back through multiple viral posts complaining about the platform, Corallo said, “our org currently has no CI (quality testing processes) because GitHub wrongly flagged a contributor, not an admin or maintainer, just someone new who opened a few pull requests. We’ve escalated it through corporate account managers and still basically nothing.” A week or so later, he added: “GitHub has decided our open-source project has been permanently banned with no explanation and no option to appeal, pointing to a ToS that clearly does not cover anything we’ve ever done.” – “I guess it’s time for Bitcoin projects to leave GitHub.”

The banned contributor appears to be Luis Schwab, who replied “I’ve had my account banned twice within a week “by mistake”. Relying on GitHub’s goodwill is not a good long term strategy.” Multiple other Bitcoin and crypto engineers replied with similar experiences, saying they too had migrated off the platform or been banned without recourse, like Roman Storm, who replied, “In 2022, GitHub locked my account over Tornado Cash sanctions. I’m a US citizen. They told me to get an OFAC license to access my own account. The sanctions were later ruled unlawful and overturned. The account is still locked. I’ve filed ticket after ticket – now they don’t even respond. Abolish GitHub.”

Corallo blames the AI wave on the recent mass banning of accounts and increasingly aggressive measures taken by the massive platform. The popularity of vibe coding has brought a new wave of attention, amateur projects and automated bot-like behavior to the already overburdened platform. Today, GitHub claims to host over 420 million repositories and over 4 million organizations worldwide. GitHub was acquired by Microsoft in 2018, which, to some, also explains its steady downfall. 

Even Andrew Poelstra, another senior Bitcoin Core and Rust Lightning contributor, with over a decade of experience in the industry, wrote a devastating take-down of GitHub, defending the decision to migrate. “This site has an overwhelming amount of LLM slop, and they have no intention of stopping it, though they did write this insane blog post taking credit for FOSS as a way of acknowledging the problem,” he began, continuing to explain that the merging of code into the master repositories had now been  “broken for several days.” This caused cascading issues that confused the “merge script,” a security program that makes sure updates to a code base are done properly. 

The bug meant that tracking and merging pull requests — contributions from other developers — didn’t work as expected. “Tracking PRs is the one thing GitHub is supposed to do, and it’s broken. It’s no longer more convenient to stay here than to leave, which was the only reason we’ve stayed so long,” Poelstra continued. “The usual problems where diffs and comments are hidden, the site being slow and unreliable, the permissions model being insane and broken, the lock-in, the crappy and slow API, etc. [All of] which we could live with if the basic functionality worked, but it doesn’t.”

As a result, the next destination for Rust Lightning and perhaps other Bitcoin projects in the industry may be Forgejo, a lightweight GitHub alternative optimized towards self-hosting and high agency projects. Corallo confirmed to Bitcoin Magazine that “rust-bitcoin already started migrating to git.rust-bitcoin.org” and Rust Lightning would follow. 

The repositories will likely continue to host a copy on GitHub, though no public statements have been made about any kind of long-term mirroring strategy of the code base, meaning it will eventually just live on their own site

This post Matt Corallo Urges Bitcoin Projects to Exit GitHub After Rust Lightning Ban first appeared on Bitcoin Magazine and is written by Juan Galt.

Bull Bitcoin Secures MiCA License in France, Preserving Full Self-Custody and Privacy Features

23 June 2026 at 20:58

Bitcoin Magazine

Bull Bitcoin Secures MiCA License in France, Preserving Full Self-Custody and Privacy Features

Bull Bitcoin has obtained a MiCA license in France, ensuring users in European Union member states can continue accessing its Bitcoin exchange and payment services without interruption or any reduction in functionality. Founder Francis Pouliot announced the development on June 23, 2026, via X, marking the end of a nearly three-year, self-financed effort to enter the European market.

“We are particularly excited to have obtained our MICA license without needing to compromise on our cypherpunk approach to self-custody and privacy,” Pouliot stated. “All features of our website and wallet will remain exactly the same as they have been for the first half of 2026, with no additional burden or restrictions imposed on our users. We have proven that it is possible to meet the highest requirements of regulatory compliance without becoming overzealous.”

The company also reported passing the required PASSI and DORA cybersecurity audits without outsourcing its core Bitcoin infrastructure to third-party hosted providers. “That was a huge win,” Pouliot wrote, noting that relying on external services would have been easier and cheaper but would have compromised sovereignty. The entire process was funded internally, with no external investors or lenders solicited.

Bull Bitcoin, founded in 2013 in Montreal by Pouliot, operates as a Bitcoin-only, non-custodial exchange. Users supply their own wallet address before any purchase, with Bitcoin sent directly to the customer’s control rather than held by the company. This model has defined the firm’s cypherpunk orientation since inception, alongside services such as Bitcoin bill payments for rent, utilities, and real estate, plus support for Lightning Network, Liquid, and Payjoin privacy tools.

The license provides a long-term regulatory foothold in Europe following the company’s expansion of its France-based team and eurozone services. Pouliot previously noted the firm’s experience navigating Canadian oversight and its willingness to meet obligations while pushing back against overreach. The new authorization aligns with that stance: core operations and user experience stay intact.

In October 2025, Bull Bitcoin launched its BULL Wallet, a global, open-source, privacy-first mobile app for iOS and Android with deep opt-in integration to the exchange. Features include Payjoin support, Lightning and Liquid compatibility, and no data collection or push notifications. The wallet and exchange integration remain unchanged under the new license.

Pouliot expressed pride in the team’s execution and outlined next steps: “Having secured a long-term foothold in Europe, our ambition is global domination and setting a new standard on how to build the infrastructure Bitcoin deserves.”

The development comes amid tightening EU crypto rules under MiCA, where many providers have faced pressure to exit or alter operations. Bull Bitcoin’s outcome suggests that rigorous compliance is achievable while maintaining direct user custody, in-house infrastructure control, and privacy tooling, though how exactly they resolved the tension between user privacy expectations and MiCA compliance was not explained in the announcement.

This post Bull Bitcoin Secures MiCA License in France, Preserving Full Self-Custody and Privacy Features first appeared on Bitcoin Magazine and is written by Juan Galt.

Nostr is the Orange Web: Bitcoin’s Niche and Futuristic Alternative Internet

22 June 2026 at 20:23

Bitcoin Magazine

Nostr is the Orange Web: Bitcoin’s Niche and Futuristic Alternative Internet

If you are into Bitcoin, you might have heard “Nostr,” a strange, nearly unpronounceable word that stands for “Notes and other stuff transmitted by relay”. This acronym that’s captured the imagination of Bitcoin technologists for years has a big idea. That you don’t need to be locked into a social media giant to talk to your friends. 

Invented at the start of COVID19 by Fiatjaff in March of 2020, today the Nostr protocol has a seemingly infinite amount of websites custom-built around this niche, with world-class influencers like Edward Snowden and Jack Dorsey prominently on the platform. 

Unlike the internet and social media ecosystem of today, Nostr lets users take their followers and content with them from website to website, from app to app, as they see fit. The algorithms are fundamentally in the hands of users, supporting maximum control, variety and censorship resistance, qualities largely lost from the modern big tech clear web. 

A Tool of Bitcoin Evangelism

Built on Bitcoin native technology, Nostr has supported bitcoin micro payments called zaps from almost day one. Its login system resembles a Bitcoin wallet more than it does any other login credential, resulting in a fresh and novel experience of the web. 

Artists have started to find their way to this strange corner of the internet, as they do, growing their brands into international communities that tip in Bitcoin, not just in appreciation for great art, but to make a point. To demonstrate that, regardless of where you are in the world, Bitcoin can be delivered to your door. 

Take Pubpay, for example, a Nostr-powered music site built to elevate the musicians not just online, but in live performances. I got to see this app in action at a Bitcoin party in Las Vegas just a few weeks ago. The site seen on that massive screen showed off the artist on stage, with a massive QR code and a leaderboard of Zaps, tiny bitcoin donations made to the artist over the lightning network. Those who donated most rose to the top, claiming the bragging rights, while the artist claimed the sats. 

Have a listen to the trending tab of Wavlake, for example, another music dedicated Nostr site with a smooth design and instant access to surprisingly good music. 

Stories of onboarding new people to Bitcoin via Nostr social media apps like Primal are common at Bitcoin meetups and conferences. Primal is a Twitter clone of sorts built from the ground up around Nostr, it is without a doubt the fastest way to get into this social media niche, start growing your followers and start stacking sats by posting great content. 

Unlike the boring payments-only Bitcoin wallet whose design principles are now more than 15 years old, the Nostr app is fresh and has a direct pipeline of content that can be delivered to newcomers if done right, keeping them tumbling down the Bitcoin rabbit hole.

Easy to Understand Nostr Fundamentals

Built on Bitcoin native cryptography, Nostr uses public addresses and privacy keys to authenticate its users, the same as Bitcoin wallets. Nostr public addresses start with “npub” while private keys start with “nsec”. Users sign posts or messages they want to publish to the Nostr network with their private key. Those signed posts can be found by looking at the same user’s public address. Like normal social media apps, users can follow and mute each other across the Nostr ecosystem. 

Data about who follows whom, and what they have published, is stored on relays, special servers that users can run themselves, and which sync with other relays to varying degrees, similar to Bitcoin nodes

Interfaces and apps can be built on top of Nostr to let users experience their social network in different ways, and many different approaches exist, from Twitter-like clones like Primal and Amathyst, to blogging platforms, music and even micro video sites like Divine. Basically, any website can be Nostr integrated as long as it makes its users’ identities Nostr compliant, and user-generated content becomes available via relays.

If you get tired of one app or don’t like how they are treating you, you can just grab your nsec and move to another. The new app will look up your npub, find all your friends, notes and preferences and let you continue connecting with them without issue. In other words, the network effects built on Nostr apps are owned by you, controlled by you and not by the platform. This is the big idea of Nostr, and it is why so many Bitcoiners are obsessed with it. 

A lot more than Social Media

It’s important to note that Nostr isn’t just a social network protocol; it is actually an open-source and actively growing information protocol that can transfer any kind of data. Devices can talk to each other via the nostr without you having to see them. In fact, a wide range of apps have already been built to transmit data over Nostr; many of those apps can be found in one of the most important places of this ecosystem, the Zapstore.

That’s right, Nostr has its own dedicated app store, and it’s quite impressive. Led by a gentleman known as Franzaps, this open source Nostr-powered app store gives you direct and often early access to over 150 apps in the Nostr ecosystem, published directly to it by its developers, signed cryptographically and publicly with their Nostr keys.

But Zapstore goes beyond just its Nostr niche; it lets you download a wide range of popular apps that publish to GitHub. We are talking over 3000 of the most popular apps, according to Fran, who talked to Bitcoin Magazine in an exclusive interview. Examples like Mullvad VPN and Brave browser can be found on the Zapstore, along with many others; it could very easily replace the Play Store and App Store for a privacy-conscious user, by passing the choke point that Google and Apple have been building inside mobile phones. 

The Zapstore software goes through significant lengths to verify the authenticity of apps via cryptography. Fran explained that “Android uses the APK format. All APKs have a developer signature, and this is what Android checks during updates.” Google now effectively KYCs its app developers, but Nostr is decentralized, so to know whether an app was actually published by its developer, Nostr social proof is used. “Nostr is a *social* protocol where keys carry social weight, so now that Zeus signed their wallet, you can be certain it’s the real one.” 

This concept of Nostr social proof is historically known as a Web of Trust. If you log into Zapstore with your Nostr keys, you get to see if anyone you follow has engaged with the publishers of the app, an early web of trust solution to the question of security and authenticity in a decentralized world. 

Fran estimates the Zapstore has around 4,000 daily users, with half installing or updating at least one app. These are estimates — he clarified, “because we value privacy, we have zero tracking in the client and must derive them from relay and Blossom server data.”  

Digital Identity on Hard Mode

Since authentication into Nostr is done via Bitcoin-style private-public key pairs, the security practices to protect your identity are similar. Rather than emails, passwords and password resets, in Nostr, you have to take precautions to make sure your nsec (private key) does not get hacked. If it ends up on the dark web somehow, there’s not much you can do to recover it, and your identity and data can not be transferred to a new key pair either; the hacker can take control. For years, I’ve criticized this design, but while a protocol-level solution to password resets in Nostr has not been widely adopted, other solutions have emerged, such as remote signers.

Amber, an app created by Greenart7c3, a popular Nostr developer, can generate and sign Nostr events remotely, giving you full control over the nsec, without exposing it to every website you connect to. This technology works quite well, with wide adoption. It takes advantage of NIP-46 — an open-source Nostr improvement proposal designed for this purpose.

If you have never had a Nostr account, Amber is a great place to start, have it generate your Nostr keys, and use it exclusively to login to Nostr apps. 

Zap Zap Zap!

The most viral and innovative element of Nostr, a feature called by some “the moat” of Nostr apps, is, of course, the Zap. Those small bitcoin tips, which can be as little as 1 satoshi, though can be much higher as well, with a new Nostr site designed specifically around onchain Zaps, making the minimal viable over 1500 sats. Zaps, as a result, can deliver an excess amount of dopamine to its recipients relative to the cost, a reinvention of the Facebook “like”, with the weight of the hardest money in the world behind it. The Zap anchors approval and value to something that can not be faked by sock-puppet accounts on social media. If you want to try to game the popularity of a post, you have to pay up. 

The potential of Zaps is likely still in its infancy, but may one day serve as a novel kind of advertisement medium, ultimately paying consumers to experience content, or simply as an undeniable sign of gratitude from Nostr users towards a piece of content and its creator. 

Setting up Zaps on your Nostr account however could be easier, there are two sides to getting your Zaps up and running, sending and recieving, and for both you need the right kind of Bitcoin wallet. Not all Bitcoin wallets are made the same, as you might know. Most focus on handling onchain transactions, which, for the most part, are not compatible with Zaps. You need a lightning wallet that supports NIP-57, which gives you an email like nym, such as bitcoinmagazine@b.tc, a human-readable address that can receive lightning payments. And you also need to be able to send Zaps from a lightning wallet, which does not have to be the same one you receive them to.

The easiest way to start by far is by using Primal.net, likely the most popular Nostr social media client to date. Primal has a deep range of tools for Nostr users and often serves as the gateway to the ecosystem. It has a wallet built in that manages to stay on the self-custodial side of the regulatory line, while also being a low effort, low cost lightning wallet. It does this by using Spark, a layer 2 protocol similar to lightning. 

Most important of all, Primal’s wallet support Nostr Wallet Connect (NWC) a very powerful and standard in the ecosystem under NIP-47, which lets you connect Nostr enabled websites to a wallet, to enable Zaps, without giving every website custody of your satoshis.

Other options range from running an Alby lightning node, which costs $12 dollars a month on server fees, far too much if you ask me, though a viable option for power users. Or running an Electrum Lightning wallet from a home machine and making sure it is always open and online. From there, there’s a wide range of lightning node software that enthusiasts can set up and make compatible with NWC and Nostr Zaps.

A Glimpse of the Nostr Ecosystem

Including all the tools mentioned above, here are some of the most notable Nostr sites and tools I discovered in my deep dive into the Nostr ecosystem, in no particular order. 

Social media apps:

Web of trust tools:

Bitcoin Wallets + Nostr:

Remote Signing and Key Management:

Other:

This post Nostr is the Orange Web: Bitcoin’s Niche and Futuristic Alternative Internet first appeared on Bitcoin Magazine and is written by Juan Galt.

Cardone Capital’s Bitcoin-REIT Hybrid: Targeting 22-32% Returns by Blending Cash-Flowing Properties and BTC Holdings

16 June 2026 at 20:27

Bitcoin Magazine

Cardone Capital’s Bitcoin-REIT Hybrid: Targeting 22-32% Returns by Blending Cash-Flowing Properties and BTC Holdings

Real estate investor Grant Cardone is positioning his Cardone Capital to challenge the traditional real estate investment trust (REIT) sector by integrating Bitcoin directly into large-scale multifamily deals. With roughly $5 billion in real estate assets under management across about 15,000 units, Cardone claims the hybrid approach can deliver superior returns while onboarding new investors to Bitcoin.

In a recent interview at Consensus 2026, Cardone laid out his strategy for disrupting the multi-trillion dollar Realestate Investment Trust sector, also known as REITs, companies that own, operate, or finance income-producing real estate. Established under U.S. law in 1960, they must distribute at least 90% of taxable income as dividends to shareholders, providing investors with liquidity and yields without direct property ownership. According to Cardone, publicly traded REITs and the broader industry control over $4.3–4.5 trillion in U.S. real estate assets.

Cardone highlighted a key structural constraint during his Consensus Miami 2026 appearance: traditional REITs like Camden, AvalonBay, and others “can never ever hold Bitcoin on their balance sheet.” This limitation, rooted in the industry’s 1960s-era rules focused on real estate assets and income, creates what he calls a “glitch” in the market, a competitive opening.

Cardone’s Bitcoin Origin and Hybrid Strategy
Cardone first encountered Bitcoin when he was paid 115 BTC for a speaking engagement in Las Vegas, which he still holds. He has since evolved this into a hybrid model at Cardone Capital. Rather than tokenizing real estate on the blockchain, the firm acquires institutional-quality, cash-flow-positive multifamily properties at significant discounts and pairs them with Bitcoin inside a dedicated LLC.

In one prominent example, Cardone Capital purchased a 366-unit property at 101 Via Mizner in Boca Raton from a Blackstone-related lender for $235 million in cash. The property, described as irreplaceable and valued at approximately $400 million replacement cost, was combined with about $100 million in Bitcoin, creating a total ~$335 million investment vehicle.

Replacement cost refers to the expense of building a comparable property today. Cardone targets assets trading at significant discounts to this benchmark. Instead of simply capturing the real estate discount, the firm allocates Bitcoin to “stuff it into the discount gap” and move the overall cost basis of the property higher. In the Boca deal, Cardone says this structure generated a $50 million tax write-off. 

Commercial real estate of this sort should provide stable cash flow. Cardone suggests the Boca property is expected to return 4% per year, alongside depreciation benefits, and periodic refinancing opportunities every 7–10 years. Bitcoin adds upside potential and liquidity characteristics. He stated, “We believe by combining real estate and Bitcoin and having time… I’ll end up with somewhere between a 22 and a 32% return on an asset class that has been boring, consistent, and ancient.” The investment horizon of real estate properties of this sort is often in decades, a long-term mindset that gives Bitcoin plenty of time to grow past its short-term volatility.

In turn, this vehicle exposes new investors to Bitcoin in a risk-controlled and novel way. According to Cardone, about 80% of investors in the Boca fund reportedly had zero prior Bitcoin exposure, aligning with Cardone’s goal of “onboarding people into Bitcoin that have had zero exposure.”

Real estate is, of course, a complicated business with known trade-offs such as long hold periods typical of institutional real estate and execution risks in scaling retail participation via crowdfunding. Cardone says he has completed road shows with banks but prefers direct-to-consumer raises leveraging his audience.

Disruption Potential
Cardone claims to have assembled roughly $1 billion in real estate and around 2,000 reported Bitcoin, accumulated over the last 17 months, with six deals currently in contract. He aims to disrupt the REIT sector, noting that even capturing 5–10% of the market could create significant value. Plans include a potential public listing of the hybrid structure, relying on his roughly 20 million online followers, with about 20,000 current investors.

This approach builds on Cardone Capital’s earlier Bitcoin activity, including purchases during market dips and cash-flow-backed accumulation.

Cardone views the current environment as “the greatest time in the history of the world to make money,” with Bitcoin as a beneficiary. “People gotta live someplace. You cannot live in your Bitcoin account,” he said, underscoring the enduring need for real assets alongside digital ones.

This hybrid model represents one prominent effort to bridge traditional real estate with Bitcoin treasury strategies, potentially expanding access and returns for investors. Further developments will depend on execution, market cycles, and regulatory considerations for such structures.

This post Cardone Capital’s Bitcoin-REIT Hybrid: Targeting 22-32% Returns by Blending Cash-Flowing Properties and BTC Holdings first appeared on Bitcoin Magazine and is written by Juan Galt.

BitGo Joins Fortune 500 with $16.2B Revenue, Marking Milestone for Regulated Bitcoin Infrastructure

15 June 2026 at 19:22

Bitcoin Magazine

BitGo Joins Fortune 500 with $16.2B Revenue, Marking Milestone for Regulated Bitcoin Infrastructure

BitGo Holdings, Inc. (NYSE: BTGO) has been named to the 2026 Fortune 500, becoming the first true digital asset infrastructure company to reach the list. The debut comes just five months after the company went public on the New York Stock Exchange in January 2026, with reported revenue of approximately $16.2 billion for 2025.

The 2026 Fortune 500 edition, which features President Donald Trump on the cover and is on sale now, includes BitGo at No. 273. BitGo also appears in related coverage, while CEO Mike Belshe is slated for prominent placement in the upcoming Fortune Crypto 100 list in August, including feature coverage and limited cover variants. 

While miners, major exchanges, and treasury-focused companies have gone public in recent years, BitGo stands out as the first dedicated infrastructure provider — focused on custody, wallets, settlement, and related services — to achieve Fortune 500 status so quickly after its public listing.

Background and Evolution

BitGo was founded in 2011 by Mike Belshe, its current CEO, alongside Bill Lee, Ben Davenport and Will O’Brien. It began as a provider of secure Bitcoin wallets and institutional-grade custody solutions, emphasizing multi-signature technology and enterprise security at a time when few reputable options existed for large holdings.

Over more than a decade, the company grew into one of the most recognized names in digital asset infrastructure, powering wallets, custody, trading, and operations for many prominent platforms, funds, and institutions in the Bitcoin and broader crypto industry.

Current Operations and Regulatory Standing

Today, BitGo functions as a full-stack infrastructure provider. It operates as BitGo Bank & Trust, National Association, a federally chartered national trust bank under the Office of the Comptroller of the Currency (OCC). This designation, approved in December 2025, imposes stringent federal requirements — including enhanced capital standards, regular audits, comprehensive risk management, and fiduciary oversight — while delivering significant strategic advantages.

The OCC charter provides uniform federal supervision and regulatory clarity, replacing fragmented state-by-state licensing in many cases and offering institutions the certainty they expect from a federally regulated fiduciary. It enables nationwide service capabilities with federal preemption of certain duplicative state requirements. 

Nick Payton, VP of Marketing at BitGo, told Bitcoin Magazine that the OCC federal charter, combined with being a public company, unlocks regulatory clarity sought out by institutional clients. “We spent the money and made sure to take that burden off of our clients.” Payton also described the OCC federal charter as a moat that software alone can not easily unlock, even with the power of artificial intelligence.

Finally, the OCC federal charter also strengthened the company’s ability to expand services such as stablecoin infrastructure, staking from cold custody, Prime trading and derivatives, and tokenization activities under a clear federal framework, positioning BitGo as a key bridge between traditional banking rails and digital assets.

Its client base is primarily institutional, including exchanges, funds, and Bitcoin ETF issuers. Notable examples include 21Shares (custody for Bitcoin ETFs), Fold (which relies on BitGo infrastructure for core operations), World Liberty Financial (custody and infrastructure for its USD1 stablecoin), and SoFi (infrastructure and distribution support for SoFiUSD, positioned as the first U.S. national bank-issued stablecoin on a public blockchain).

High-net-worth individuals also use the platform for qualified custody, staking from cold storage, and Prime services. While some retail-facing tooling exists through the broader platform, BitGo has maintained a deliberate focus on institutional and sophisticated clients rather than becoming a mass-market retail platform.

Prime Services and Global Footprint

BitGo has expanded its Prime desk to include OTC trading, electronic trading, and derivatives, which recently came online. This allows clients to access liquidity, execute strategies, and manage collateral directly from qualified custody. The service supports operational needs such as loans against Bitcoin holdings or yield generation without moving assets off-platform.

The company operates globally across more than 100 countries. It maintains regulated licenses and entities in key regions, including a VARA license in Dubai, an office in London, a Latin America headquarters in Mexico City, and an APAC base in Singapore, according to Payton.

Revenue Drivers

Payton also outlined the company’s primary revenue contributors today, which are primarily made up of custody fees, the company’s bread and butter, alongside other growing revenue sources like BitGo Prime, encompassing OTC, e-trading, and the newer derivatives offering.

Staking of crypto assets also made the short list of top revenue drivers for the company, enabling clients to earn yield on assets such as Ethereum and Solana while keeping them in cold custody.  Finally, Stablecoins have become a rapidly expanding segment of company revenue via their Stablecoin-as-a-Service platform, which handles minting, burning, and custody. Recent examples include support for World Liberty Financial’s USD1, which Payton described as one of the fastest-growing stablecoins, approaching significant circulation, and SoFi’s SoFiUSD with an initial mint of $150 million and plans to scale.

Payton also shared that “Bitcoin has always driven significant volume at BitGo. But Ethereum, Solana, and stablecoins are also prominent.” He added: “One major point we’ve never discussed publicly is that we’re among the top 10 largest entities holding Bitcoin globally, with over 470k BTC in custody,” making Bitgo one of the largest Bitcoin custodians in the world. For its own corporate treasury, BitGo Holdings, holds approximately 2,449 BTC as of the most recent public disclosures, this ranks BitGo as having the 32nd largest corporate treasury holdings in the world. 

Outlook on Tokenization

As for current areas of focus, Payton expressed clear enthusiasm for “tokenization,” a commonly heard though somewhat elusive term in the industry. He framed it as the cryptographic representation of traditional assets — particularly public and private equities — on blockchain infrastructure. 

“We are excited about the future of tokenization. We think it’s going to bring broader access to a wider range of people in public markets. We’re also looking into tokenizing private companies as well, traditional equity, not just public.” Payton said, cautioning that “It has to be done carefully. And safely. We don’t want it to turn into a bubble. It has to be done responsibly.”

This post BitGo Joins Fortune 500 with $16.2B Revenue, Marking Milestone for Regulated Bitcoin Infrastructure first appeared on Bitcoin Magazine and is written by Juan Galt.

Bukele’s Reform Makes El Salvador a Top Tax Haven: 0% on Foreign Income and Bitcoin Gains with Minimal Presence

11 June 2026 at 23:59

Bitcoin Magazine

Bukele’s Reform Makes El Salvador a Top Tax Haven: 0% on Foreign Income and Bitcoin Gains with Minimal Presence

El Salvador — often called Bitcoin country —continues to refine its immigration framework to draw high-value foreign talent and capital, including families. Decreto 531, effective March 31, 2026, reduced the physical presence requirement for temporary residents from nine months to 90 calendar days per year, consecutive or accumulated. This adjustment targets entrepreneurs, investors, and remote professionals whose work involves frequent travel.

On paper, this new minimum requirement for residency status places El Salvador in a very competitive place compared to other tax haven-style nations. But what are the benefits of becoming a Salvadorian Tax resident, and is it really as easy as it sounds?

The Upside of El Salvador 

El Salvador offers one of the most attractive tax regimes in Latin America for individuals with foreign-sourced income. The country operates a territorial tax system, meaning only income generated within El Salvador is subject to taxation. A major 2024 income tax reform explicitly exempts foreign-source income for both residents and non-residents. This means that independent remote workers, such as content creators, developers and entrepreneurs with foreign source income, can enjoy 0% Salvadoran income tax on those earnings, regardless of the amount. 

There is also no capital gains tax on Bitcoin under the Bitcoin Law, no wealth tax, no inheritance or gift tax, making it particularly advantageous for those holding or transacting in BTC.

For entrepreneurs incorporating locally, Bitcoin and digital asset-related activities enjoy broad exemptions. Standard corporate income tax is 30% (or 25% under certain revenue thresholds), which is considered competitive across the board, but this is specifically on local profits. Qualifying businesses in free zones, involved in technology hardware or software exports and international services laws, can access 15 years of corporate tax exemptions, such as no income tax and no withholding, no VAT, no import tariff duties on equipment, tools and machinery, and no capital gains tax. 

These tax incentive laws are clearly designed to draw talent and capital to the country and develop a manufacturing, software and hardware industry that exports services to the rest of the world and improves the local economy. 

Quality of Life

The security enjoyed in the country after Bukele is undeniable. Katie Ananina, who helps families and individuals throughout the world acquire second passports via CitizenX, wrote favorably about El Salvador for families looking for a plan B. 

The highlights of her six-week on-the-ground experience in the country with young children and while pregnant highlighted the country’s dramatic safety transformation. She noted that her family could walk day and night freely in both beach towns and San Salvador without fear. Practical daily life elements stood out positively: access to quality grass-fed beef and organic food options, reliable local driver networks via WhatsApp, and solid private and international school choices in San Salvador. 

According to her research, healthcare includes a mix of public and private services, with homebirth legally supported through licensed midwives and the DoctorSV app aiding appointments and telehealth. 

The Downsides and Tradeoffs of El Salvador

While full tax residency (triggered by more than 200 days of presence) provides the cleanest official status, many with primarily foreign income benefit substantially from the territorial framework even under the lighter 90-day immigration residency requirements. The wording and laws on this front are somewhat confusing, but Ananina clarified to Bitcoin Magazine that, as far as El Salvador is concerned, residents can start benefiting from the Salvadorian territorial tax regime on day one. The problem is whether the country of origin the person comes from agrees; most countries don’t usually give up their tax-generating citizens without a fight.

As a general rule, countries consider someone a tax resident if they spend more than 6 months within the country, but also have property, family, official residential address and phone number there, among other tests. Ananina, who clarified that she is not a tax lawyer or specialist, said that in her experience, in the case of a contest between the country of origin and El Salvador about a person’s tax residency, El Salvador is likely to yield.

As such, individuals and families looking to benefit from the residency tax benefits of El Salvador need to also understand the nuances of their country of origin’s tax residency laws as well. 

The Local Economy

The local economy of El Salvador is also still in its early stages of development. The minimum monthly wage is between $270 and $409 per month, depending on the industry. This means that foreigners looking for local work in the country might find it hard to adjust if they are coming from wealthier nations. However, foreigners looking to hire local talent can get significant upside from the low wages. 

The Bitcoin economy specifically is as seasonal as the quality of the beach in El Zonte, which disappears in the summer due to rising tides, scaring away the tourists and dampening the surf scene. In contrast, between October and March, many foreigners return to the country for a series of Bitcoin conferences and to enjoy the waves as the sand returns to the popular beach towns. 

There’s a variety of Bitcoin-related companies that operate in the country throughout the year, and are headquartered or licensed in the country, like Tether, Boltz, Ocean Mining, and a long tail of startups and financial services companies. But as far as events and the social scene, the seasonal nature of the country remains a known trend. 

On the AI front, El Salvador made international news earlier this year with a conference that attracted top talent from all over the world. The SovAI Summit was hosted on April 20–21, 2026, at the National Palace in San Salvador. The event, backed by the Bukele government, positioned the country as an emerging hub for sovereign AI, infrastructure, and innovation, blending discussions on AI sovereignty, compute resources, decentralized technology, and regenerative agriculture. Top guests and speakers included Carl Meacham, Head of Sovereign AI & Business Development at HydraHost, along with participation from major tech representatives from Google, Dell, and NVIDIA, among others.

This post Bukele’s Reform Makes El Salvador a Top Tax Haven: 0% on Foreign Income and Bitcoin Gains with Minimal Presence first appeared on Bitcoin Magazine and is written by Juan Galt.

Dan Loeb Reveals DOJ Threat to Trump Over Ross Ulbricht Commutation in Final Hours of First Term

9 June 2026 at 18:46

Bitcoin Magazine

Dan Loeb Reveals DOJ Threat to Trump Over Ross Ulbricht Commutation in Final Hours of First Term

Hedge fund manager Dan Loeb has publicly claimed that the Department of Justice threatened President Donald Trump in the final hours of Trump’s first term in January 2021, warning it would “go after” him if he commuted the sentence of Ross Ulbricht, creator of the Bitcoin-powered Silk Road marketplace. After the reported threat, Trump withdrew the commutation, forcing Ulbricht to serve four additional years in prison before receiving a full pardon in January 2025 during Trump’s second term.

Loeb, founder and CEO of Third Point LLC, made the revelation on the All-In Podcast while discussing his role in criminal justice reform and Ulbricht’s clemency efforts. “On the last day of Trump’s 45th term, we were certain that he was going to get out,” Loeb stated. “And the Justice Department, for whatever reason, said, ‘If you commute his sentence, we’re going to go after you,’ to the president. So he, as I understand, he withdrew the commutation.”

This account is the first public report of such a direct threat from the DOJ during the closing days of Trump’s first presidency. It has not been independently corroborated by other sources to date, and no specific DOJ official has been named as delivering the warning. The claim rests on Loeb’s recollection, likely conveyed through the advocacy chain that included crypto figures like Riva Tez, Charlie Kirk, and then-White House counsel David Warrington.

DOJ Leadership in January 2021

Jeffrey A. Rosen served as Acting Attorney General after William Barr’s departure in late December 2020. Richard Donoghue was Acting Deputy Attorney General. The Office of the Pardon Attorney, a DOJ unit that reviews clemency petitions and issues recommendations, operated under their oversight. Presidents, including Trump, frequently bypassed standard OPA processes for politically sensitive cases.

The alleged threat appears to have gone well beyond typical DOJ advisory input on issues such as sentence proportionality, victim impact, or enforcement priorities. Ulbricht had been serving a double life sentence plus 40 years following his 2015 conviction on charges including operating a continuing criminal enterprise, narcotics distribution via the internet, money laundering, and hacking. Contrary to popular belief and widely publicized insinuations by the mainstream media, Ulbricht was never prosecuted on any charges related to murder for hire. 

Silk Road, which relied primarily on Bitcoin for transactions, represented one of the earliest large-scale experiments in the use of an alternative currency to the dollar, making the case and its history foundational to the Bitcoin community.

A warning framed as potential retaliation against the President himself would constitute an extraordinary escalation in tensions between the executive branch and the Department of Justice over clemency authority. Such pushback likely stemmed from institutional concerns about appearing soft on major drug trafficking and money laundering cases tied to the early Bitcoin economy.

Four-Year Delay and Political Impact

The reported DOJ intervention in the final days of Trump’s first term cost Ulbricht four more years behind bars. As Loeb recounted, Charlie Kirk later took the lead on the clemency effort. “This was his only ask of the president,” Loeb said, referring to Kirk. Kirk’s advocacy helped turn Ulbricht’s release into Trump’s primary promise to libertarians and the crypto community during the 2024 campaign. Trump delivered on that promise with a full and unconditional pardon early in his second term.

Ironically, the delay strengthened the “Free Ross” movement. What began as advocacy for clemency in a case viewed by many in Bitcoin circles as emblematic of government overreach evolved into a potent political force. The campaign highlighted issues of disproportionate sentencing, self-custody, privacy tools, and resistance to broadly unpopular and ineffective war on drugs, core themes in Bitcoin’s ethos of financial sovereignty and of high importance to the libertarian voting block. This momentum and Trump’s promise to pardon Ulbricht are widely considered to have earned Trump the libertarian and crypto vote in 2024.

Broader Context for Bitcoin

Loeb framed his involvement in Ulbricht’s case as part of broader criminal justice reform, linking it to his broader philanthropy efforts on education and concerns over opportunity and income inequality. He highlighted three categories for clemency: the wrongly convicted, the rehabilitated, and those with disproportionately harsh sentences. Ulbricht, who acknowledged wrongdoing on Silk Road while denying murder-for-hire allegations, fit the latter category in Loeb’s assessment.

The episode highlights ongoing tensions between law enforcement, Bitcoin innovation, and the libertarian culture that makes up a large part of the U.S. public. Silk Road, one of the earliest Bitcoin marketplaces, remains a reference point in debates over decentralization, privacy, and regulatory overreach. Similar cases continue to draw attention in the Bitcoin community, including Bitcoin activist Ian Freeman, the developers of the Samourai Wallet privacy tool, and Roman Storm of Tornado Cash—all facing charges viewed by many as attacks on Libertarian leaders, the freedom of commerce, self-custody and financial privacy tools.

This post Dan Loeb Reveals DOJ Threat to Trump Over Ross Ulbricht Commutation in Final Hours of First Term first appeared on Bitcoin Magazine and is written by Juan Galt.

Bitcoin Privacy in 2026: A Practical Guide

4 June 2026 at 21:30

Bitcoin Magazine

Bitcoin Privacy in 2026: A Practical Guide

Bitcoin privacy has come a long way since the early days of Bitcoin. Once marketed as anonymous, Bitcoin can be best described as a pseudonymous currency and monetary system. It does not need user personal information whatsoever to function, but companies built around it often associate user public keys — Bitcoin accounts — with user information. They do this to comply with legacy financial regimes, and in some cases, for ease of use. 

As a result, users might share or expose personal information to such companies as their home IP address, which can be used to identify the users’ internet service provider, and from there, the users’ physical address. As well as their personal name, phone number, shipping address, etc. All of this information in the wrong hands can put people at risk of physical and economic harm. 

It is important to note that Bitcoin does not fundamentally have a privacy problem, as many critics suggest. The modern world has a privacy problem, which it has so far failed to address, leading to regular hacks of user data across every aspect of society, from the banking sector to social networks, from government agencies to the military. The digital society we increasingly inhabit is more often than not incapable of securing user data. 

Bitcoin, unlike all other comparable institutions, does not need user data to function. It is actually one of the few financial tools available for the privacy-conscious individual. Cash is the other alternative, which limits the distance at which transactions can be made and brings with it a full bag of other downsides. 

But, as a digital system, can Bitcoin actually be used privately, given how prominent KYCed exchanges are, and how data-hungry modern software companies have become? The answer to this question might surprise you. 

Privacy from whom? 

Depending on the jurisdiction you live in and the local laws or state of your country, some risks or threats are more pressing than others. Some countries throughout the world have at times imposed heavy capital controls on their citizens, often simply enforcing the cash grabs at the banking level. Bitcoin, if held in self-custody and with the right amount of privacy, can protect users from this threat.

In other cases, the nation state is stable enough, but organized crime has run amok, leading to targeted phishing schemes and even kidnappings, like in the case of France, where honest and hard-working individuals pay their crypto taxes, and as a result of local laws, enter the public record as having crypto. Leading to an alarming rise in related home invasions. 

Last but not least, there are activists who might be operating under oppressive regimes, debanked and isolated from civil institutions, Bitcoin used in subtle ways can be their only monetary respite. Depending on the situation, some tools and tactics will be better for the job than others. 

Privacy also does not mean that you can not be a law-abiding citizen. Strong privacy laws exist in many countries, meant to protect civilians from a variety of threats, while also enabling compliance with tax laws, for example. Privacy does not mean you have something to hide, as Joseph Goebbels, Hitler’s infamous chief of propaganda, once suggested. Instead, it is the ability to choose who you disclose your business to. It is a fundamental pillar of democracy. 

Network Privacy

First things first, we have to protect your IP address, the ID your internet service provider gives your computer devices, including your mobile phone. The most popular way to deal with this is to get a VPN. 

Not all VPNs are created equal; however, many are rumored to keep logs and sell your data. On this front, it’s important to do deeper research than the marketing and ask around from people who are paranoid enough to know better. 

In the Bitcoin space, Mullvad VPN has a good reputation. They have been accepting Bitcoin for their services for a very long time, and are super easy to use. They are used alongside Tor and have an option to block all traffic that does not go through the VPN. One account can support multiple devices, including mobile. 

Tor Browser, the infamous gateway into the dark web, is also an important tool to have handy. Many privacy tools we will discuss below support Tor connectivity, often having the required libraries built in, so you just have to push a button on the app to use the Tor network. The apps will be a little bit slower, as Tor does its anonymization magic, just FYI. Brave Browser also deserves a mention here, as it blocks most advertisement tracking and has built-in Tor support.

Getting Bitcoin Privately

The biggest challenge to Bitcoin privacy is actually how users accumulate it. Exchanges, broker-like private companies that facilitate the trade of bitcoin for fiat currency, have emerged as the most efficient and effective way to buy bitcoin. They have managed to survive hostile legal regimes, hacker groups and overzealous law-enforcement agencies by often over-complying with financial regulations that require them to collect massive amounts of personal user data.

Privacy-preserving alternatives to buy and sell bitcoin for fiat have, in turn, been harassed by government agencies regularly, often failing to survive or keep their market foothold against centralized alternatives. An excellent example of this dynamic was the first major peer to peer bitcoin to fiat exchange called LocalBitcoins, which shut down after 10 years of operation since at least 2013. The company faced increasing pressure from regulators in Finland, forced to implement KYC in 2019, and eventually shut down during the 2023 bear market and Operation Chokepoint 2.0

LocalBitcoins connected buyers and sellers, serving as an escrow for Bitcoin, while the fiat went from the buyer to the seller’s bank account. LocalBitcoins, which pioneered the model, never touched the fiat and did not know the banking information of the seller. Such information would only move up the chain to the operators in the case of disputes. If both buyer and seller were happy with the fiat transfer, the BTC was released from escrow to the buyer. 

This semi-decentralized exchange model, pioneered by LocalBitcoins, is generally called a P2P Bitcoin exchange, though many variations of it exist, with a wide range of privacy trade-offs, over the years. 

Today, Bisq.network is perhaps one of the most renowned predecessors of LocalBitcoins. Taking a page from the centralized downfall of LocalBitcoins, Bisq attempted to create a Tor-anonymized, decentralized trading platform to allow buyers and sellers of bitcoin to connect all over the world. Bisq still operates today and has a variety of software tools available. Users can run Bisq on their local machines and control their account with their phones with Bisq Connect, or they can simply be notified of trade alerts via Bisq Notifications. There’s also a dedicated mobile app called Bisq Easy.

Volume for Bisq is estimated at almost 5 million dollars a month, which is low by centralized exchange standards, but good enough for civilian-grade dollar cost average purchases over time. It’s important to understand a couple of things when using Bisq. First, you should always pick a counterparty with a very high reputation. You should also pay attention to the commission they charge. It is normal for sellers to charge 5% above spot price or more, so look for the cheapest, highest-reputation option. The Bisq Easy app has a great user interface and teaches users new to P2P the basics quite well. 

There’s a variety of other P2P exchanges and platforms in active use throughout the world. As a general rule, when doing P2P, it is best to keep purchases or trades small enough that you don’t take unnecessary risks. They should be significant enough to be worth your time, but any amounts above $10,000 is probably way too much. The Dollar cost average strategy, as a result, works very well with P2P stacking.

Another way to get Bitcoin with good privacy is to find your local Bitcoin community. Many major cities throughout the world have active Bitcoin communities. If there are none where you live, you might be surprised how many people show up if you start a Bitcoin meetup. From there, slow trust building with local bitcoiners might open up the opportunity to buy some BTC from them for cash. Many bitcoiners get paid in bitcoin for their work and often need to sell some to cover fiat expenses, creating an opportunity for P2P trades in real life.

Last but not least, offer your skills in exchange for Bitcoin, start a project or a Bitcoin dedicated brand. This will give you a great deal of control over how you handle information about your Bitcoin revenue. 

Onchain Privacy

However, once you have some Bitcoin, there are a variety of things you can do to keep that information secure from prying eyes. Bitcoin, unlike any other money before it, functions as a public network, with its full transaction history auditable by anyone, though not tied to the holders’ personal information, but instead their public address or pseudonymous Bitcoin account number.

These public addresses live on the blockchain, and data firms can try to connect the dots about who is moving money where, especially when they collaborate with exchanges on data sharing or when other relevant information enters the public domain. Users can protect themselves from onchain analytics by using a variety of tools and tactics. 

Run your own node

In order to minimize who you share information with about your addresses and balances, it becomes important for privacy reasons to run your own Bitcoin node, otherwise you are always fundamentally asking someone else running a node, what your balance is. All wallets that don’t explicitly run a Bitcoin full node on your machine have to run one on their servers, or redirect your requests to a public node someone might be hosting for charitable or not-so-charitable reasons. 

While having network privacy, such as through the use of a VPN, can protect you from the risks of not running your own node, the next step in that self-sovereign, privacy setup is certainly taking control of the node you query, and thus becoming an active participant in the Bitcoin network. 

Sparrow Wallet, an increasingly popular desktop wallet which has excellent support for privacy features, hardware wallets and advanced Bitcoin features like multi-signature accounts and Silent Payments, has great documentation on how to run and use your own node. Their conclusion is that Fulcrum, a wrapper on top of Bitcoin core that makes the blockchain data available to external wallets, is the way to go. 

As a desktop wallet, Sparrow would work within your home network, letting you access the Bitcoin blockchain with strong privacy. If you wanted to connect to it from your phone or laptop from outside of your local network, you would need to run a Tor hidden service at home, a Tor tunnel of sorts, to access your node remotely in a secure and private way. 

Boltz Exchange

Boltz is a Bitcoin-to-crypto, non-custodial exchange. It never touches fiat, and never holds custody of user funds. Users trade against Boltz using a technology under the hood called atomic swaps which means neither party has to trust the other during the trade, the crypto is moved essentially at the same time from the seller to the buyer and viceversa.

Boltz can be used without sharing any personal information and can be accessed through Tor, allowing Bitcoin users to leverage the benefits of other blockchains and payment networks if they so wish, with strong privacy. 

One such network accessible via Boltz is the Liquid blockchain, a Bitcoin-denominated and collateralized federated ‘side chain’ with strong privacy features. Another example is the Lightning network, which has powerful potential privacy benefits as it is fundamentally off-chain, leaving a simple public record. Boltz can be used to convert Bitcoin to stablecoins as well on most major blockchains, letting bitcoiners access the broader crypto industry and its market integrations through a high privacy bridge. 

Boltz can be used on their website or by downloading a standalone open source web app. A CLI is also available for advanced users, and since the whole stack is open source, users can even self-host the Boltz suite themselves for their business. Boltz, as a result, removes the need for centralized exchanges to move across blockchain rails, eliminating the corresponding privacy risk.  

The Liquid Network

The Liquid Network, a federated blockchain created by Blockstream, is slowly becoming an important infrastructure to the Bitcoin industry. Launched in 2018, the chain is a modified fork of Bitcoin with its native asset LBTC, pegged to Bitcoin directly. To mint LBTC, you have to deposit BTC into the federation’s multisig, and to get your BTC out, you can depeg or sell your LBTC for BTC on a variety of atomic swap exchanges. While its consensus structure is different than Bitcoin’s and fundamentally permissioned, it rests on the shoulders of a double-digit group of industry-leading companies throughout the world, and has remained quite stable since it went live.

One of the interesting things about it is its privacy features; transactions on Liquid have their amounts and asset type encrypted by default. Addresses can be seen to move assets from A to B on-chain, but which asset and how much of it is encrypted, only for the involved parties to see. It uses a cryptographic technique called Confidential Transactions, pioneered by Bitcoin wizards like Adam Back, Andrew Poelstra, Mark Friedenbach, Gregory Maxwell, and Pieter Wuille. Liquid is also quite cheap to use, and has faster block times than Bitcoin, making it an interesting tool in the Bitcoin privacy tool belt, specifically with privacy bridges like Boltz exchange. 

Blockstream has a mobile wallet that is quite powerful and easy to use, which supports the liquid network.

Silent Payments

Silent Payments are a novel kind of Bitcoin address that reframes the way auditing of balances happens on Bitcoin. The whole point of being able to see addresses and how much BTC is in them on the blockchain is so that users can easily verify the total supply and thus the economic integrity of the Bitcoin monetary network.

Silent payments (SP) let users receive Bitcoin in such a way that the link between the SP address and the corresponding Bitcoin public address is publicly severed. The technology is quite powerful and has a long history of development in the Bitcoin industry, gaining growing adoption in recent years.

Of the few wallets that can receive Silent Payments so far, Sparrow wallet is likely the best across the board, supporting a full range of privacy features, including connection to the user’s own node. Silent Payment addresses can be reused, so users can generate one and take it on the go, then check their balances on their desktop or laptop using Sparrow. For extra privacy, users can run a Frigate server alongside Sparrow, which deals with the Silent Payments magic in a self-hosted way

Payjoin

Another notable technology that works quite well with the rest is Payjoin. With a dedicated foundation and wallet support growing every day, this simple transaction-building technique breaks the heuristics used by blockchain analytics to identify individual users and their flows across the chain. Sparrow wallet, alongside many others, supports Payjoin, as it continues to grow into what may become the HTTPS of Bitcoin payments

Coinjoin

Once the bread and butter of Bitcoin privacy, Coinjoins wallets like Wasabi let you mix your Bitcoin with other people’s in a non-custodial way. The technique has significant upsides when done well, and is still used by many to this day, though it also comes with some tricky downsides. Gustavo, an entrepreneur and writer for Bitcoin Optech, says that “Wasabi works better than ever IMO, and is by far the most liquid and effective bitcoin privacy solution.” Liquidity equates to more privacy when it comes to Coinjoins. “Kruw.io is the dominating coordinator: it has over 97% of the market’s liquidity.” with “30,000 btc volume per month, about 4000 btc of fresh btc inputs.”

Coinjoins became so effective and popular that they led to the landmark Samourai Wallet case, which had its own implementation of the technology, an ongoing cultural fight for the right to privacy.

Gustavo also listed some of the downsides involved with Coinjoins that users should consider, such as the risk that a centralized exchange might be able to tell your bitcoins were moved through a coinjoin, which looks like a big cloud of transactions on-chain. And that there is some known risk of data leaks on the side of the coordinator, a server someone has to run to help users atomically mix coins with each other. However, he believes the technology only continues to improve and patch those holes, saying that “the attack surface has decreased since the last discussion in 2024.” 

The Lightning and eCash Networks

Last but not least are the eCash and the Lightning Network. Fundamentally off-chain bitcoin native transaction protocols, they have a key benefit over all the onchain privacy solutions, that they do not leave a footprint on the public blockchain. As a result, privacy is theoretically far easier to achieve. In practice, however, there’s still a lot of work to do, since the most private ways to use the Lightning network are the most difficult from a user experience perspective, requiring the user to run their own Lightning node and manage their own liquidity. 

While there are many easy-to-use lightning wallets in the market, most, if not all, require a certain level of data sharing trust with the servers of the wallet company. Something that network privacy can help alleviate. 

Ecash is also emerging as a strong privacy technology, though it still falls short on adoption in the West. Wallets like Fedi and Cashu are on the cutting edge, letting users transact with unprecedented privacy in Bitcoin terms, though at the cost of trusting custodial mints, which collateralize the ecash tokens with Bitcoin. 

Conclusion 

Overall, the tools of Bitcoin privacy continue to improve as the industry’s passion for the topic has not waned. Some are easier to leverage than others. But, as Satoshi Nakamoto has demonstrated, those who take their privacy seriously are the only ones who are able to keep it. 

This post Bitcoin Privacy in 2026: A Practical Guide first appeared on Bitcoin Magazine and is written by Juan Galt.

Coinkite Launches Coldcard MK5: Major UX Upgrades to Flagship Bitcoin Hardware Wallet

30 May 2026 at 00:36

Bitcoin Magazine

Coinkite Launches Coldcard MK5: Major UX Upgrades to Flagship Bitcoin Hardware Wallet

Coinkite the Bitcoin-only hardware wallet manufacturer, recently released the MK5, a significant quality of life and user experience upgrade to the MK4 Coldcard, building on the strong security foundations set by its predecessor. The MK5 comes in many colors and styles. Today, I will review the Orange and Glow in the dark versions, as well as their form factor and user experience upgrades, to answer the question: are the upgrades to the device worth the money? 

Building on the well-known and trend-setting MK4 security platform, which brought two secure element chips from different manufacturers and an MCU to the same device. The MK5 focuses instead on quality of life, improving the NFC connectivity, reworking the buttons and plastic chassis of the hardware wallet, as well as adding a much larger screen, among other new features. This is the first hardware upgrade to the Coinkite MK line since the launch of the MK4 in 2022, integrating into it some of the technologies debuted by the Coldcard Q in 2023.

Coinkite Launches Coldcard MK5: Major UX Upgrades to Flagship Bitcoin Hardware Wallet
Left MK5, center MK4, right MK3.

What is new with the MK5 Coldcard?

The big upgrades to the UX are immediately visible; the screen, for one, is much larger, perhaps 30% bigger. Their announcement blog describes it as a “1.54-inch display protected by Gorilla Glass,” which does look and feel much sturdier than older models.

The next obvious upgrade is the buttons. Unlike the MK4 buttons, which are indented, requiring your fingers to go into the socket to get a click, the MK5 buttons are almost at par with the chassis of the device, making them much easier to press. The press feels good, it clicks, giving the user a solid tactile feedback. Much more comfortable than the warm, slightly uncomfortable, unresponsive feel of a touch screen, as seen in other hardware wallets. 

Coinkite Launches Coldcard MK5: Major UX Upgrades to Flagship Bitcoin Hardware Wallet

You also quickly notice the chassis has been redesigned. The screen section no longer pops out above the keyboard; instead, it’s all one rectangle with comfortable curved edges. It looks more modern, more elegant, while keeping that cypherpunk transparency that shows off the underlying hardware, a signature design principle of Coinkite products. 

The MK5 also comes with a button and screen protector half case that slides and clicks in and out. It can be entirely removed and fits perfectly from the back of the device, exposing the USB power input at the bottom of the device without issue. 

Coinkite Launches Coldcard MK5: Major UX Upgrades to Flagship Bitcoin Hardware Wallet

NFC Push Transactions

Last but not least, Coinkite doubles down on NFC support with the MK5. An acronym for near field communication, the NFC antenna is an increasingly popular tech stack in the Bitcoin industry. From NFC tap to pay lightning Bolt cards with cool designs and laser eyes, or Coinkite’s own Tapsigners, to Cashu’s tap to send features developed by Calle. 

NFC is a powerful alternative to other wireless connection technologies like Bluetooth or Wifi, which some hardware wallet providers have adopted, but come with some arguable downsides, mainly their range. Unlike the alternatives, NFC is short-range by design; we are talking centimeters in range, whereas Bluetooth and Wi-Fi are talked about in tens of meters. So the paranoid level threat that someone with a long-range antenna pointed at your house might catch a transaction in transit or be able to connect to your device remotely, vanishes. 

There’s also no multi-step device connection protocol with NFC; phones either have the feature on and off, the app starts scanning, and transmission can occur. No pin codes, no sifting through lists of Bluetooth-powered devices. Much simpler UX in theory. It is also far superior in terms of user experience to the SD card transmission of pre-signed transactions back and forth from laptops or phones. While NFC may technically cross the ‘airgapped’ line in the MK4 and MK5, NFC still has the best qualities of all wireless connectivity options, and is set to off in the default settings. Similar to the option to connect the MK5 to a computer via USB for data transmission, the NFC antenna can also be severed at a hardware level by scratching off a specific wire within the hardware. 

Coinkite’s NFC push Tx software is open source and much smaller in terms of lines of code than Bluetooth or Wifi. The full NFC push Tx code is open source. The client web app side of the protocol has no license defined and is presumably meant to be integrated by any web application. While the hardware side of the code is public, but is limited by the non-commercial use license.

The Colors of the MK5

https://store.coinkite.com/cdn-cgi/image/fit=scale-down,background=white,width=512/static/images/sku/bundle-mk5-colours.png 

Playing into the Bitcoiner’s hunger for collectibles, the MK5 comes in a wide range of cases, such as gold flaked transparent gray, gorgeous orange and even glow in the dark! I got to play with the Orange and blue glow-in-the-dark version, though I kind of wish I’d gotten my hands on the gold flaked one.

Nevertheless, the designs are beautiful, transparent enough to see the hardware, but colorful enough to be stylish. Here’s what they look like in practice. 

Coinkite Launches Coldcard MK5: Major UX Upgrades to Flagship Bitcoin Hardware Wallet
Coinkite Launches Coldcard MK5: Major UX Upgrades to Flagship Bitcoin Hardware Wallet

Supply Chain Security

The packaging was also very interesting; the box containing the hardware came with a purchase order of the items, which were inside tamper-proof security bags. These bags had pretty strong plastic, not something you can easily rip, requiring a knife to slice through them. The bags were also marked with a unique number, seen in the pictures below. Inside the bag, another plastic strip contained the same number. And when the devices were first powered on, they displayed the same number on the screen. This is a flash memory code that gets set up per device at the factory. Making interception and manipulation of the firmware of hardware that much more difficult. The next level would be to notify the user of the bag number via email or behind a login on the site, so they can have a side channel to verify the number as well.

If you see anything off with the packaging, you are encouraged to take pictures and reach out to Coinkite support. 

The battery and exposed hardware device in the picture below is the COLDPOWER Adapter by Coinkite, which I happened to have laying around and figured I’d test out as well. It is meant to give the device power entirely airgapped, no cables connected to any computer whatsoever, as even a malicious Wifi repeated plugged into a power outlet could transmit signals across the power wires (lol). 

Coinkite Launches Coldcard MK5: Major UX Upgrades to Flagship Bitcoin Hardware Wallet
Coinkite Launches Coldcard MK5: Major UX Upgrades to Flagship Bitcoin Hardware Wallet

Things to improve?

Integration of NFC Push Tx with mobile wallets was a bit inconsistent. I tried Cove, Bull Bitcoin and Nunchuck. Of the three, Nunchuck had the best integration, with Cove not far behind. Bull Bitcoin seems to have disabled the feature or hidden it quite well. Cove is a young project likely to improve leaps and bounds in the coming months, while Nunchuck a very advanced and powerful wallet, took me a few minutes to figure out but ultiumetly turned out to be the best interface of the three.

Even with a stronger NFC antenna, I had to remove my phone’s ridiculously thick case in order to get a reliable data transmission, but that’s not the end of the world. 

Conclusion: Is the MK5 worth the money to upgrade? 

As a proud owner of what I now realize is an ancient MK3, the move to an MK5 is a significant upgrade, and the low cost of $167 plus shipping, I’d say it is a no-brainer. That’s a whole generation of security and UX upgrades that I did not realize I needed.

For active users of the MK4, the bigger screen and better buttons are definitely an improvement in quality of life, and the better NFC antenna will likely yield dividends as well by making transaction flows smoother. Again, compared to other hardware wallets in the market, the price is very reasonable.

For passive MK4 owners who make a couple of transactions a year, however, the juice might not be worth the squeeze. They are still getting firmware updates and get all the security benefits, and likely won’t miss the improved UX that much. 

Disclaimer: Coinkite provided Bitcoin Magazine with a couple of free MK5 Coldcards to use for the purpose of testing their product for review.

This post Coinkite Launches Coldcard MK5: Major UX Upgrades to Flagship Bitcoin Hardware Wallet first appeared on Bitcoin Magazine and is written by Juan Galt.

Cathie Wood Doubles Down: ARK Invest Sets Bitcoin Base Case at $750,000 by 2030

28 May 2026 at 00:35

Bitcoin Magazine

Cathie Wood Doubles Down: ARK Invest Sets Bitcoin Base Case at $750,000 by 2030

ARK Invest CEO Cathie Wood reaffirmed her firm’s long-term bullish outlook for Bitcoin, projecting a base case of approximately $750,000 and a bull case of $1,250,000 within the next five years, even as critics question the asset’s performance amid volatility and geopolitical tensions.

In a recent interview with Fox Business, Wood addressed Bitcoin’s role as a maturing asset class, pushing back against skepticism that it has failed to serve as an effective hedge during periods of global uncertainty.

“Our base case is closer to $750,000. But the bull case involves a substitution for gold,” Wood said. “So as generational wealth transfer takes place, we think that younger people are more prone to adopting a digital store of value. So that would be Bitcoin.” Most of the world’s wealth is expected to be passed from the baby boomer generation to their children and younger heirs in the coming decades.

She outlined three primary drivers behind ARK’s forecasts: generational shifts toward digital assets, Bitcoin’s utility as an insurance policy in emerging markets, and accelerating institutional adoption.

“The second is Bitcoin is an insurance policy, particularly in emerging markets against fiscal and monetary neglect at best or corruption at worst,” Wood explained. “And so as wealth increases around the world, we think that individuals will shift from stablecoins… to Bitcoin, which has much more appreciation potential.”

“But the biggest reason is institutional adoption,” she added, “This is a new asset class. It has very low correlation to other asset classes in terms of risks and returns. And so every asset allocator has a responsibility to examine it because it will increase risk-adjusted returns over time.

Wood’s comments come as Bitcoin faces criticism, including from figures like Mark Cuban, who has suggested the asset has “lost the plot” and underperformed as a hedge amid recent geopolitical and economic turbulence. In events such as market stress tied to international conflicts, Bitcoin has at times decoupled from expectations, with gold outperforming in certain episodes.

Wood acknowledged short-term dynamics but pointed to longer-term structural advantages. She highlighted Bitcoin’s fixed supply schedule as a key differentiator.

“21 million units, we’re up to 20 million that have been minted. Only one more million to go. So the scarcity value is there,” Wood said. “Bitcoin is mathematically metered. There will be no supply response. It’s just mathematically metered. And right now it’s increasing at 0.9% roughly per year, the supply is, which is lower than gold’s long-term, and in the next two years, we’ll be down to 0.45% increase per year. So there’s real scarcity value evolving now.”

On the Bitcoin-gold relationship, Wood noted low historical correlation since institutional interest began in earnest around 2019. “You’ll find a very low correlation between gold and Bitcoin, digital gold — very low correlation, it’s 0.14,” she said. “So almost no correlation.” She observed recent shifts where Bitcoin has shown momentum while gold has retreated, partly tied to a strengthening U.S. dollar.

Recent developments in global finance further illustrate Bitcoin’s growing role as neutral money. Reports indicate Iran has implemented mechanisms to accept Bitcoin payments for safe passage through the Strait of Hormuz, including structured toll processes for shipping, highlighting the asset’s utility in sanctions-prone environments and cross-border transactions where traditional systems face friction. The corridor saw over 20% of global oil pass through it, before the war. 

On the national front, Wood emphasized that regulatory clarity will accelerate institutional participation. She pointed to pending U.S. legislation, such as the Clarity Act, as a catalyst.

“I think the Genius Act and soon, hopefully, the Clarity Act, will set the stage appropriately for this space to flourish and for institutions,” Wood said. “I think once we do, because the odds have gone up recently that it will be passed, that we will see much more of an institutional swoosh into the space.”

Wood also addressed the coexistence of Bitcoin with the U.S. dollar, noting stablecoins’ role in extending dollar influence globally while Bitcoin captures appreciation potential.

Despite near-term volatility, Wood maintained that Bitcoin’s characteristics position it for continued adoption across demographics, with younger users particularly drawn to its properties as both a store of value and transactional medium.

The ARK CEO’s outlook aligns with her firm’s updated models, which continue to center digital gold substitution and institutional flows as core drivers for Bitcoin’s trajectory through 2030.

This post Cathie Wood Doubles Down: ARK Invest Sets Bitcoin Base Case at $750,000 by 2030 first appeared on Bitcoin Magazine and is written by Juan Galt.

Manna Wallet + Branta Guardrails: Self-Custodial Bitcoin Payments Now Show Verified Merchant Details

26 May 2026 at 20:31

Bitcoin Magazine

Manna Wallet + Branta Guardrails: Self-Custodial Bitcoin Payments Now Show Verified Merchant Details

Branta, a Bitcoin security company, recently announced integration with Manna Wallet, a self-custodial payments app. Users will now see the logos and company details of merchants they make payments to on Manna before they make a payment, letting them make the purchases with confidence. “Bitcoin payments give users anxiety. Every single time,” said Adam Simecka, CEO of Manna in the announcement, a key fact that to him, explains why Bitcoin adoption is lagging.

“Manna now automatically ensures your payments are going to who they say they are with Branta. When you pay a Branta integrated business, you will see their details and a link to verify yourself. Don’t trust. Verify.” Simecka, announcing the integration. Branta’s software is open source and privacy-centric, using zero-knowledge proofs to avoid knowing anything about the payment addresses or invoices involved, while guaranteeing the connection between client and merchant is authentic. “We went way out of our way to make sure the process met high standards of privacy.”  Keith Gardner, co-founder of Branta told Bitcoin Magazine. 

Demo The Technology

Branta’s Guardrails service was designed to eliminate risks like human error or man-in-the-middle attacks between users and merchants in Bitcoin. Such attacks of this sort have become very popular in other blockchains, such as Ethereum, called “poisoned address”, created to mimic recipients that a client makes regular payments to.

Users in this example might be tempted to grab the recipient address from their blockchain history, which attackers have dusted with the poisoned address, tricking the user. While poison address attacks are more difficult in Bitcoin, other ways to trick users exist. Human error is also a possibility that experienced Bitcoin users know well, sometimes joking about it online. 

Ships in the Strait of Hormuz while they wait 45 minutes for the Bitcoin transaction to go through https://t.co/PIXKZSx2rK pic.twitter.com/lJB4aLW6YI

— Clemente (@Chilearmy123) April 8, 2026

Branta Guardrails works as a “side channel” to authenticate the connection between sender and recipient. Merchants can join the growing network of Branta merchants and platforms, and integrate their technology via a wide range of Bitcoin invoicing software already supported, such as a BTCpay server plugin and Zaprite’s suite of merchant tools.  

A live demo can be tested with some of the wallets like Manna and Arkade. Scanning supported QR codes brings up the merchant logo on the user wallet and clickable link to verify recipient details. Phil Geiger, advisor to Branta, showcasing that demo, X.com saying it “Makes me feel much more confident before sending an immutable bitcoin payment!” 

Ok now this is seriously cool.

Scan the @PeonyLaneWine LN invoice with @MannaBitcoin wallet. @BrantaOps verifies the address and displays the merchant logo 🤌

Makes me feel much more confident before sending an immutable bitcoin payment!

Great work @unfakekeithhttps://t.co/IcQcfdqtTZ pic.twitter.com/1mlfqg34T0

— Phil Geiger (@phil_geiger) May 1, 2026

According to Gardner, merchants love the idea of having their logo show up on client wallets, and it makes sense. Company logos accumulate massive amounts of capital and goodwill deployed by companies; they represent the company’s purpose and history, and establish a bond with their customers. Making sure users feel comfortable and confident in their purchases is thus essential to business operations, and the merchant logo fulfills that purpose, in a similar way to the green lock browser icon that brought HTTPS to the mainstream in the early 2000’s. 

This post Manna Wallet + Branta Guardrails: Self-Custodial Bitcoin Payments Now Show Verified Merchant Details first appeared on Bitcoin Magazine and is written by Juan Galt.

The History and Future of Physical Bitcoin

23 May 2026 at 22:02

Bitcoin Magazine

The History and Future of Physical Bitcoin

Bitcoin’s digital nature is the source of most of its advantages. Since it is programmable, it unlocks self-custody practices that can make theft and confiscation very difficult. Since it is digital, it can move at the speed of light, allowing movement of value and settlement across the globe in minutes. 

Nevertheless, Bitcoin has at times been criticized for being hard to grasp, literally. Bitcoin, in its natural state, can not be touched, can not be physically held; it can only be imagined and understood. To many people, that’s a significant barrier and one that has inspired quite a few attempts to bring the coin into meat space, but it is not easy. 

Entrepreneurs and artists alike, for well over a decade, have taken on the challenge of making Bitcoin physical in a way that retains its most valuable cash-like properties, and while nobody has entirely solved the problem, significant progress has been made, leaving a wonderful trail of artifacts along the way.

Casascius Coins

The History and Future of Physical Bitcoin

(Image by Stacks Bowers Galleries

Minted as early as September 6th, 2011, at a bitcoin price of barely $8 dollars, Casascius coins are without a doubt the most iconic physical Bitcoin artifacts in history, with many copycats since. Named after Mike Caldwell’s Bitcointalk forum nym, which appears to be an idiom for “call a spade a spade”, the Casascius coins developed many of the practices that other attempts at physical Bitcoin would innovate on over the years.

One problem with making Bitcoin physical is the handling of private key material. Since Bitcoin is digitally native, it can only live in a cryptographic private-public key pair, a secret that is used to generate a public key, with Bitcoin-compatible cryptography. In the case of the Casascius coin, Caldwell generated the private keys in an airgapped machine and printed them, gluing them to the iconic precious metal coins and then presumably destroyed the copy that could have been kept on his computer. He described the security precautions taken on his website for potential buyers to review.

The printed private key was then covered by specialized tamper-proof stickers, which, if removed, leave an obvious mark in a “honeycomb pattern”. Buyers of the coins could thus tell if the private keys in a Casascius coin had been exposed before purchase from a third-party vendor.

This key management issue is the biggest hazard in the creation of physical bitcoin, and one which, in the case of Caldwell, was dealt with by trusting him not to cheat. He was also very transparent and careful by the standards of the time. To this day, his reputation is strong if not legendary, so that trust was well placed by buyers who profited greatly from the collector’s value of the items, which to this day mark a premium on top of the bitcoin and precious metal values of the piece.

Casascius coins were discontinued in November 2013 after the Financial Crimes Enforcement Network (FinCEN), a branch of the Treasury Department, informed developer Mike Caldwell that minting physical bitcoins qualified him as a money transmitter business with heavy compliance requirements. The trust involved in generating the private keys may have been a centralizing element that put a target on his back. 

RavenBit Coins

The History and Future of Physical Bitcoin

A year after Casascius coins shut down, RavenBit launched, with an attempt at decentralizing the trusted minting problem of physical bitcoins. The RavenBit coins, very similar in form factor to Casascius, did not come with pre-generated keys; instead, they came with the tamper-proof sticker unpealed, such that the user could generate their own keypair, paste it to the coin and slap the tamper-proof sticker on top.

This, in a sense, decentralized the mint and, in theory, that is a breakthrough, but in practice, it just created a thousand trusted mints, without brands, without reputations, using office printers that probably had malware on them. If you got a RavenBit coin from someone, how could you know that the person who bought it and generated the private key in there didn’t keep a copy or take proper precautions?

To date, the RavenBit project has been abandoned, but it probably taught the industry an interesting lesson. To make Bitcoin physical, we need to go higher tech.  

Opendimes

The History and Future of Physical Bitcoin

To route around the trusted mint problem — both at the center and at the edges – of physical bitcoins, Coinkite, the hardware wallet maker, designed the Opendime, a tiny computer purpose-built to be a Bitcoin bearer asset. Looking back on what motivated him, NVK, co-founder of CoinKite, told Bitcoin Magazine that, “Bitcoin is digital money. All we can do is an analog backup. Maybe someone cracks doing secp256k1 by hand in the future.” Meaning that currently, you always need some kind of computer to generate valid Bitcoin keys; that computer is the mint.  

Opendimes were designed around this fundamental fact. They have a computer chip that can generate a private-public key pair and store the private key securely, behind a silicon tamper-proof mechanism. 

Users have to feed it a file or some kind of input for entropy during setup, which the chip uses in part to generate the Bitcoin wallet, this grants further assurance that the random generation logic, which is open source, has an even better entropy input in the generation of those bitcoin keys. 

The public key of the generated Opendime wallet can always be seen by connecting the device to a computer, as you would a normal USB stick; its balance is visible on a block explorer.

Users can then send bitcoin to the opendime, but if they want to withdraw BTC from it? They have to physically puncture the device, which unlocks a circuit to access the private key, but renders the device visibly unsealed. 

Opendimes represent a major breakthrough in bearer asset technology and go for about $20 dollars each today, rising in price slightly with inflation from a low of about $13 each in 2016. As a result, they have also achieved iconic status, with artists embedding them in premium Bitcoin art and making them into Bitcoin meme culture. 

The History and Future of Physical Bitcoin
The History and Future of Physical Bitcoin

While $13 to $20 dollars is very cheap for hardware wallets, and the trusted mint issue is effectively solved by letting users fill the device with their own coins, the price and form factor are still far away from cash. On a price basis alone, $20 dollars is a big ask. If Casascius charged about 20% markup for his coins, then Opendimes should hold at least $100 worth of Bitcoin inside to be worth the hardware, and for use as a currency, which prices out most every day purchases.

Finally, the badass cypherpunk USB stick form factor, while epic, does not visibly tell the user much about its contents, making each device effectively non-fungible with other Opendimes and thus not cash-like. A cheaper and probably more fungible alternative is needed. 

The Satodime

The History and Future of Physical Bitcoin

Taking the Opendime concept to a more friendly form factor, the Belgian hardware wallet manufacturer Satochip created an open source credit card-like Bitcoin wallet, which has very similar qualities to the Opendime. It can generate Bitcoin private-public key pairs, and depending on the version, can even sign transactions. Users can interact with it via phone apps that talk to the card via NFC. Other form factors are available as well, like rings and coins that contain the same chip and capabilities. 

The cost for Satochip hardware can be as low as 13 Euros, depending on the bulk purchases, which is cheaper than an Opendime, which gets us closer to everyday cash purchases, but not by that much. The Satochip cards are intended to be high-security hardware wallet devices anyway, not daily-use cash containers. And these powerful and small computer chips are not cheap, hence the price floor above $10 that seems so hard to break through, for now. 

Too Expensive? The Fundamental Limits

So, how cheap does physical Bitcoin hardware need to be to make business sense, if it can make sense at all? 

According to the Federal Reserve, it costs anywhere from 4.1 cents to 11.3 cents to produce U.S. dollars. The smaller the value, the more expensive it is, with $1 bills incurring a 4.1% loss in production costs. 

That means that to justify a 20,000 Satoshis bill — roughly $16 dollars at today’s prices — the hardware needs to cost well under a dollar. Most computer chips powerful enough to do Bitcoin cryptography are above that price target, but there is one chip that demonstrates what is possible, the NXP’s NTAG X DNA chip.

Available in sticker antenna form factor, a couple of millimeters thin, this NXP chip can handle a variety of cryptographic primitives, such as ECDSA and ECC. It can create secrets, sign them and even encrypt a message. However, while powerful, it does not include the Bitcoin cryptography curve, secp256k1, which means it can’t do Bitcoin things natively. 

Nevertheless, this 2025 generation NTAG can be purchased for roughly $3, if you can find any supply, demonstrating how low the price can go on a chip capable of performing cryptographic functions.

Sadly, the cash-like form factor most of the world is used to, with flexible bills that people can fold into their pocket, can be very damaging to computer chips, a fact that NVK says he learned from experience, as they experimented with Bitcoin bearer assets hardware. 

The History and Future of Physical Bitcoin

The closest anyone may have come to the cash-like format is the OfflineCash company, with a beautiful, collection-worthy set of Bitcoin-denominated bills that have an NTAG-style NFC chip, which stores a user-generated key, while the company generates a second key on their servers, to create a 2 of 2 multisignature wallet. The Server key is on a time lock, degrading the multisig address to a 1 of 1 wallet, from which the user can eventually withdraw the bitcoin. This tries to get around the trusted mint issue, but ends up just replicating the many mints problem. Though their cash-like form factor is undeniably gorgeous.

The costs of producing a Bitcoin native NTAG can easily hit a few million dollars, and implementing Bitcoin’s cryptography in this way can be fraught with errors if manufacturers are not experts on the topic. It would also need to be fully open source to guarantee that there are no backdoors. 

There’s one more fundamental problem with physical Bitcoin bearer assets. Even if you could get a cheap enough chip in a cash-like format, you would always need online access to verify its authenticity —that the cash is loaded with real bitcoin— since the asset is unavoidably digital. The problem could be solved by simply trusting an issuing mint of Bitcoin-denominated cash instruments, and believing in the face value of a redeemable bill, but that would miss the ideal of self-custodied, trusted cash. Though it probably would work in a friendly jurisdiction. 

So, while it would be cool to have physical Bitcoin bills like those created by OfflineCash Company with a bearer asset secure chip and not trusted mint risk, we are still a ways away. And it might actually be overkill today, since no one would have bitcoin-denominated change anyway, so you’d end up getting fiat cash back, but maybe one day, post-hyperbitcoinization. NVK does believe there’s a superior solution to the cash format, at least for the foreseeable future, which is why Coinkite created the Tapsigner. 

The Tapsigner

The History and Future of Physical Bitcoin

Built on the Coinkite Bitcoin NFC chip, a technology similar to the X DNA NTAG by NXP, though perhaps more powerful and thus more expensive, the Tapsigner comes in the familiar debit card form factor, with a secure element chip, NFC tap to pay and cool designs to choose from. Inside the chip, though, is a fully capable Bitcoin wallet, with scep256k1 cryptographic capabilities, letting it create Bitcoin keys, store the secret securely enough and sign transactions internally, to be broadcast by an accompanying phone, which serves as a critical visual aid for the user to verify transactions.

The Tapsigner can function as a bearer asset, but perhaps even better as a refillable hardware wallet that can spend specific amounts of bitcoin, like any credit card, resolving the issue of change, and enabling tap to pay to wallets that support the already popular feature.

With cards like the Tapsigner, which cost about $20 bucks, the problem of bitcoin-denominated payments returns to good old-fashioned retail adoption, and integration with major business accounting and payments software, which Cashapp and Square are blowing wide open. 

This post The History and Future of Physical Bitcoin first appeared on Bitcoin Magazine and is written by Juan Galt.

VerifiedX Brings Native Bitcoin Redemption and FROST Privacy to Base DeFi with Fireblocks Integration

20 May 2026 at 21:27

Bitcoin Magazine

VerifiedX Brings Native Bitcoin Redemption and FROST Privacy to Base DeFi with Fireblocks Integration

The VerifiedX foundation has announced the launch of vBTC.b on Base with support for Fireblocks, aimed at bringing Bitcoin’s digital gold qualities and world-class brand recognition to Defi and the Institutional self-custody markets.  

According to a press release shared with Bitcoin Magazine, VerifiedX is the first “Non-Synthetic Bitcoin Asset” with built-in native bitcoin redemption, compatible with Base, Coinbase’s increasingly popular EVM blockchain and Defi platform. “vBTC is now live as a canonical asset on Base under the ticker vBTC.b and is officially listed inside the Fireblocks platform with self-custody enabled.”

While the integration with Base makes vBTC available to the public. The integration with Fireblocks unlocks institutional interest, as Fireblocks is a leading institutional digital asset custodian and a powerful brand in the Western market. 

According to DefiLlama, the Defi market today holds over 80 billion in value. While Bitcoin remains the king of the crypto markets, its representation in Defi remains small; only 5 billion worth of value is held in Bitcoin across the broader crypto-defi ecosystem, while Ethereum holds over 43 billion of the same. 

VerifiedX believes there is strong demand for Bitcoin inside Defi, with institutions increasingly interested in self-custody solutions that can satisfy their needs for regulatory compliance as well as privacy from onchain analysis and front running. VerifiedX has been designed around these expectations, while innovating beyond traditional bridges, synthetic bitcoin wrappers and trusted federations. 

Their novel approach leverages a large open network of FROST multiparty computation (MCP) nodes that arguably set a new standard for cross-chain technologies. The VerifiedX tech stack has received “an institutional full-stack audit via Halborn.”

Bitcoiners can expect enhanced integration with Defi rails from vBTC, with new utility such as “programmable settlement, collateralized borrowing, yield strategies, and AI-agent commerce” among other potential features, while leveraging a far more decentralized and self-custody oriented cross-chain technology than has been available to date. The VerifiedX chain also has zero-knowledge proof technology built in natively, providing a privacy benefit to its users as they move BTC in and out of the system, shielding them from onchain analytics. 

FROST Multi-Party Computation and Self-Custody 

The VerifiedX network leverages breakthroughs in cryptography built around Bitcoin’s taproot upgrade. Each VerifiedX validator runs a FROST multi-party computation (MCP) server, a sophisticated and scalable form of Shamir secret sharing developed independently of VerifiedX. 

FROST, which stands for “Flexible Round-Optimized Schnorr Threshold Signatures,” unlocks a technology similar to multi-signature addresses in Bitcoin, but without leaving an obvious onchain footprint. FROST-generated addresses are cryptographically indistinguishable from other taproot addresses, providing significant privacy benefits. 

But the real value of FROST is its threshold signature technology, which allows party members to easily add and remove key shares (shards) to the group (as long as a majority agrees), without having to do on-chain transactions. Keeping the related computation off-chain allows a lot more parties to participate in the security scheme than previously possible, while keeping costs low and leaving no on-chain footprint on Bitcoin. When more than the threshold of shards are used in this MCP process, a valid Bitcoin transaction can be assembled. 

New members can join the public VerifiedX network as validators at any time, though they must jump through a few hoops. Users would need to sign a variety of transactions on the VerifiedX blockchain and need to hold 5000 VFX, the native asset of this blockchain. Once the right onchain transactions are signed, the network welcomes the new validator and their corresponding shard, growing the number of parties needed to pass the threshold. The result is a dynamic and large multi-signature bitcoin wallet that avoids corporate federated whitelists or small high-trust custodians. If members remove their 5000 VFX from the address, their node is removed from the active validators, and the FROST scheme adjusts accordingly. 

It’s important to note that while it is a breakthrough in decentralization, this public network scheme does not pass the technical definition of on-chain self-custody, since it does not give Bitcoin holders unilateral withdrawal rights to the underlying Bitcoin. If, for some catastrophic reason, the whole VerifiedX public FROST pool went offline, holders of vBTC would be unable to redeem their bitcoin. However, the scheme is arguably far more decentralized than current alternatives, often relying on simple single-digit multisignature addresses, synthetic bitcoin tokens backed by altcoins or trusted federations. In the current bootstrap phase, there are over 100 active validators, and the number can technically go up well over an order of magnitude.

The VerifiedX tech does, however, open the door for a self-custodied path from Bitcoin to Defi. According to Jay Pollak — Head of Strategy and Business Development at the VerifiedX Foundation — the VerifiedX protocol can allow users to set up their own “self-sovereign smart contracts” with shards and the corresponding smart contract that mints 1:1 collateralized vBTC 100% under their control, though this specific capability will be announced in more detail and made easier in upcoming updates. Such a ‘self-sovereign smart contract’ setup would arguably pass the self-custody standard, unlocking a direct path from onchain Bitcoin to the Defi ecosystem under the same vBTC ticker. 

The VFX Governance Token

VFX, the governance token of the VerifiedX blockchain, is a critical security component of the whole equation, especially for the public FROST pool. Some kind of cost needs to be imposed on new validators to prevent a swarm of fake accounts from overwhelming the network. To that end, the current implementation of the protocol demands 5000 VFX coins to be held by validators. However, according to Pollak, this number is very likely to go down soon.

The value of VFX has seen a sharp rise since January 2025, though Pollak points out that Bitmart is the only exchange that lists it, and better price discovery will come as it enters bigger markets and more liquidity is made available. He was adamant that VFX is a governance token and has no interest in competing with Bitcoin in any way. Today, VFX trades at about $69, making the cost of being a validator quite high, though Pollak also said the amount of VFX required was very likely to change to a much lower amount soon, making the self-sovereign smart contract self-custody path far more accessible. 

200 million units of VFX were minted in 2023 during the founding of the protocol, with 67.5 million going to the VerifiedX foundation and the rest being mined for active participation and in the test network. Today, the foundation holds about 32.3 million VFX coins. According to Pollak, the current lifetime supply of VFX is approximately 169.9 million, with the remaining 30 million effectively burned in the early days for security reasons. The circulating supply is much smaller, he added, as the testnet era mints are constrained and can only move small amounts at a time, “subject to an on-chain unlocking schedule, limiting sales to no more than the burn rate per block.” 

Bitcoin Magazine has a financial relationship with The VerifiedX Foundation. This article was not commissioned or reviewed by The VerifiedX Foundation and reflects the independent judgment of the author.

This post VerifiedX Brings Native Bitcoin Redemption and FROST Privacy to Base DeFi with Fireblocks Integration first appeared on Bitcoin Magazine and is written by Juan Galt.

Bitcoin Open Heads to Iconic Glen Abbey Golf Club for June 8, 2026 Event

16 May 2026 at 00:09

Bitcoin Magazine

Bitcoin Open Heads to Iconic Glen Abbey Golf Club for June 8, 2026 Event

The Bitcoin Open, a combined golf and poker tournament organized by Bitcoin Sports Network and Satstreet, is scheduled for June 8, 2026, at Glen Abbey Golf Club in Oakville, Ontario. The event will take place at the club during its 50th anniversary year.

Glen Abbey Golf Club, designed by Jack Nicklaus and opened in 1976, is one of Canada’s most recognized golf venues. It has hosted the Canadian Open multiple times and is known for its championship-level layout and history in professional golf. The course is located approximately 30 minutes west of Toronto and serves as a public golf facility with a significant legacy in Canadian sports.

The Bitcoin Open consists of a scramble-format golf tournament on the main championship course during the day, followed by a Texas Hold’em poker tournament in the evening. The golf portion uses a team scramble format, typically with groups of four players. The field size is limited, with organizers noting strong demand and a reduced number of remaining team spots as of mid-May 2026.

Prizes for the event include two separate hole-in-one awards, each consisting of one Bitcoin. Additional golf prizes cover the longest drive and closest to the pin. Golf winners will also receive tickets to the 2027 Bitcoin Golf Championship, scheduled to take place in Nashville, Tennessee, ahead of the 2027 Bitcoin Conference. The winner of the poker tournament receives $5,000 CAD in stablecoins.

Bitcoin Open Heads to Iconic Glen Abbey Golf Club for June 8, 2026 Event

A list of hole sponsors for the event has been announced. These include APX Lending, Tetra Digital Group, The Canadian Bitcoin Conference, Satstreet, True North Airways, Ledn, Gator Mining Inc., Wealthsimple, CAD DIGITAL, PRIVATEDEBT Partners, McCarthy Tetrault, and Samara Asset Group.

Bitcoin Sports Network operates as an organizer of Bitcoin-themed sports and lifestyle events, including golf tournaments held in conjunction with major Bitcoin conferences. Satstreet, a Canadian Bitcoin-focused company, is co-hosting the event and serving as one of the hole sponsors. The two organizations are collaborating on this Canadian edition of The Bitcoin Open.

The event is open to participants from the Bitcoin community, including builders, investors, and others active in the industry. Registration is handled through the official event website, with tickets covering both the golf and poker components. The schedule includes on-course activities, meals, and networking periods at the venue.

This marks the first time The Bitcoin Open is held at Glen Abbey. Previous Bitcoin Sports Network golf events have taken place in locations such as Las Vegas, often timed near larger Bitcoin conferences. The Canadian event is positioned as a standalone gathering in the Toronto area.

Glen Abbey’s 50th anniversary provides additional context for the timing. Since its opening, the club has been a central part of Canadian golf, training professionals and hosting amateur and professional competitions.

Bitcoin Open Heads to Iconic Glen Abbey Golf Club for June 8, 2026 Event

This post Bitcoin Open Heads to Iconic Glen Abbey Golf Club for June 8, 2026 Event first appeared on Bitcoin Magazine and is written by Juan Galt.

Bukele’s Futuristic BINAES Library Blends Books, Bitcoin, and Family Play in Revitalized Capital

14 May 2026 at 22:24

Bitcoin Magazine

Bukele’s Futuristic BINAES Library Blends Books, Bitcoin, and Family Play in Revitalized Capital

Located in the heart of the country’s capital, El Salvador’s BINAES library stands tall as a monument to the love of knowledge, literature, and technology—accessible to the public 24 hours a day, for free. Positioned directly in front of and carefully aligned with the Catedral Metropolitana de San Salvador, BINAES is also surrounded by the Palacio Nacional de El Salvador (to its left/side) and the Jardín Centroamérica, all symbols and reminders of a dream. The dream of a society that elevates beauty, the love of knowledge and faith, and shares them with the world.

Having traveled to many countries and cities in my lifetime, I have to say that the safety, tranquility and cleanliness of this area of San Salvador was remarkable. An unignorable contrast to the city squares of many western capitals, often unsafe, filled with garbage, and host to the homeless and drug addicted. Instead, both outside the library, in the gardens and walkable roads of the city square, as well as inside the library, palace and gardens, children and their families can be seen at peace, running around, enjoying this national treasure. 

https://www.cultura.gob.sv/wp-content/uploads/2023/11/IMG_0822.jpg
Bukele's Futuristic BINAES Library Blends Books, Bitcoin, and Family Play in Revitalized Capital

Donated to El Salvador by the Chinese government, BINAES is 7 stories tall with a wide range of amenities, including a cafeteria on the first floor and an Italian restaurant on the 7th. Plenty of room to host events of various sizes, public and private. BINAES stands out with an elegant futurist design, congruent with its facilities and a vision for the future of El Salvador, which also prominently features Bitcoin technology and educational materials. 

With a strong focus on supporting families and the next generation, the second floor is a young children’s playground filled with educational tools, books and physical entertainment options for children to unleash their energy. The third floor has a large section dedicated to LEGOs, a powerful educational tool known to stimulate a love of building in children, with multiple tables where parents sit with their kids and play. It also hosts children’s video games, such as collaborative and family-friendly games like Mario Party and the legendary Minecraft. 

Bukele's Futuristic BINAES Library Blends Books, Bitcoin, and Family Play in Revitalized Capital
Bukele's Futuristic BINAES Library Blends Books, Bitcoin, and Family Play in Revitalized Capital

The fourth floor is aimed at children 8-12 as well as fans of fantasy and fiction, with dedicated Star Wars, Lord of the Rings, and Harry Potter areas, as well as hundreds of manga books featuring some of the greatest stories of the Japanese genre. Many of these areas include collection grade legos and merchandise from the films, as well as, of course, full libraries of books for each fictional universe. 

Bukele's Futuristic BINAES Library Blends Books, Bitcoin, and Family Play in Revitalized Capital
Bukele's Futuristic BINAES Library Blends Books, Bitcoin, and Family Play in Revitalized Capital

The fifth floor is home to literature, history and books for adults, considered the core of the library, with thousands of books on all major genres of knowledge. Among them, a vast section on social sciences, which includes economics, hosting some samples of libertarian Austrian economists like Mises, Milton Friedman, Rothbard, and Ayn Rand, though not too deep a variety. 

This specific topic, which is very important to the history, economic theory of Bitcoin and its cultural roots, is one that the library got some criticism for years ago when it was first completed. Back then, a popular tweet claimed the library had no works on libertarian economic theory, something which today has changed, but could improve further. Their collection, for example, had no fictional work by Rand, only a couple of her philosophy books; this is something that can actually be changed easily enough, though, as the library does accept book donations. Donors can contribute by first emailing BINAES staff at consultalealbibliotecario@cultura.gob.sv

Bukele's Futuristic BINAES Library Blends Books, Bitcoin, and Family Play in Revitalized Capital
Bukele's Futuristic BINAES Library Blends Books, Bitcoin, and Family Play in Revitalized Capital

The sixth floor is the high-tech area. Coming out of the elevators, the first thing you see is a Bitcoin-shaped bookshelf with a solid collection of Bitcoin literature, covering its economics, software architecture and history of money, among many other topics. This specific installation is a project by Alejandra Guajardo, also known as Miss Bitcoin, the Salvadorian model who represented the nation in the Miss Universe pageant of 2022. Her Bitcoin Book Shelf initiative looks to deploy installations of this sort in libraries all over the world, with an expansion to Mexico in the works. Bitcoiners who want to lead the installation of Bitcoin bookshelves in their local libraries can contact her to make it happen. 

Bukele's Futuristic BINAES Library Blends Books, Bitcoin, and Family Play in Revitalized Capital

In the center of the same floor is a beautiful Bitcoin lounge area, with another similarly shaped bookshelf and various Bitcoin plushies called Little Hodlers led by artist and Bitcoin evangelist Lina Seiche. A massive screen shows Mempool.space, a slick and very popular Bitcoin block explorer, showing live network data and statistics. 

Bukele's Futuristic BINAES Library Blends Books, Bitcoin, and Family Play in Revitalized Capital

This floor is also home to 3D printers, tools for robotics work, interactive digital screen-style whiteboards, a full gaming area with top-of-the-line gaming consoles, a virtual reality area, computers available to the public for research, and a digital collection of over 9 million books accessible to the public. As well as various dedicated office-like environments for students and teams to take advantage of and get some work done. 

Last but not least is the seventh floor, home to the art gallery, which at the time of my visit was hosting a variety of art pieces, showing the history of El Salvador through the architecture of iconic locations in the area. In the center of this art hall, between the gallery and the Basílico Italian Bistro, are photographs of Bukele and first lady Gabriela Bukele, perfectly aligned with the Metropolitan Cathedral across the square, a beautiful architectural detail that reinforces a harmonic union between the classic arts and faith.

Overall, despite the high-tech Chinese design of the library, which somewhat contrasts against the classical Roman architecture of the area, the BINAES library is likely to stand as a visionary legacy of the self-described Philosopher King and his administration.  

Bukele's Futuristic BINAES Library Blends Books, Bitcoin, and Family Play in Revitalized Capital
Bukele's Futuristic BINAES Library Blends Books, Bitcoin, and Family Play in Revitalized Capital

This post Bukele’s Futuristic BINAES Library Blends Books, Bitcoin, and Family Play in Revitalized Capital first appeared on Bitcoin Magazine and is written by Juan Galt.

What does Bitcoin “Power Projection” mean to the U.S. Military? 

9 May 2026 at 00:45

Bitcoin Magazine

What does Bitcoin “Power Projection” mean to the U.S. Military? 

On April 21st and 22nd 2026, during a Senate Armed Services Committee, Admiral Samuel Paparo of U.S. Indo-Pacific Command made comments on Bitcoin’s utility in cybersecurity for the country’s military, calling it a “valuable computer science tool as power projection,” and disclosing that INCOPACOM is running a Bitcoin node in their experiments with the protocol.  

The comments by the INCOPACOM Commander came just days after the Islamic Republic of Iran demanded payment in Bitcoin for safe passage across the Strait of Hormuz. The mention of “power projection” echoed the work of a famous and controversial Bitcoiner, Jason Lowery, author of Softwar: A Novel Theory on Power Projection, MIT Fellow and Special Assistant to the Commander of INDOPACOM. 

In his work — which involved an MIT thesis and book expanding on his work — Lowery discussed the cybersecurity value of Bitcoin and its unique ability to deliver “power projection” in cyberspace, a landscape of national security and military operations that otherwise lacks traditional deterrence options. 

The book gained significant popularity and earned Lowery both fans and critics across the Bitcoin industry, but was later taken down from distribution by Lowery at the request of his superiors. An event that suggested to some that the book might have something important enough that the U.S. military wants to keep it quiet. 

But what is this unique value that Bitcoin brings to military matters, and what does “Power Projection” in this context actually mean? 

According to Department of Defense’s 2002 Dictionary of Military and Associated Terms, power projection is; “The ability of a nation to apply all or some of its elements of national power – political, economic, informational, or military – to rapidly and effectively deploy and sustain forces in and from multiple dispersed locations to respond to crises, to contribute to deterrence, and to enhance regional stability.” In other words, the ability of a nation to influence the behavior of other nations or political entities of interest, at a range beyond its national borders. Examples can range from diplomatic to economic influence, as well as military capabilities such as long-range missiles, drones or a powerful navy. 

The word deterrence is also doing a lot of work here. The DoD defines it as: “The prevention from action by fear of the consequences. Deterrence is a state of mind brought about by the existence of a credible threat of unacceptable counteraction.”

Lowery brings Bitcoin into the world of deterrence in the physical world by presenting a particularly interesting insight. That just as microchips are essentially wires moving electric power in “encoded logic” inside a computer’s motherboard, so can the globe’s electric grid be seen as a kind of “macrochip”, with giant wires moving large amounts of electricity from power sources across nations and throughout the world. These macrochips now also have logic gates in the form of Bitcoin mines — Lowery argues — they consume large quantities of energy, converting it into the scarce digital asset, which can be programmed via Bitcoin script. 

The Bitcoin macrochip could, in theory, bind cybersecurity matters to the physical world, since energy output is one of the most important and expensive resources a nation can muster. While governments can print paper money at will, summoning massive amounts of electricity to influence something like Bitcoin’s proof of work competition is orders of magnitude more difficult and is the basis of Bitcoin’s resilience.

Bitcoin’s Multisignature Deterrence

The most obvious and powerful demonstration of Bitcoin’s “embedded logic” security is the invention of multisignature Bitcoin wallets, which safeguard much of the Bitcoin wealth today. 

Multisignature wallets require multiple predefined private keys to sign valid transactions before Bitcoin can be transferred, making it possible to geographically decentralize the storage of Bitcoin private keys across space and jurisdictions. 

Multisig challenges hackers not just to hack one key pair, but multiple, across multiple locations under time constraints, since users have the advantage of legitimate access to those keys and can potentially move the bitcoin quickly in response to a threat. Hackers must gain access to enough keys while also fooling alarms and safeguards, avoiding getting caught. Multisig imposes high costs on attackers and, as such, might very well fit the definition of ‘deterrence’. It may even fit the definition of ‘power projection’ as Bitcoin funds can be kept secure and available to be sent when needed anywhere in the world, thanks to Bitcoin’s other networking-based censorship resistance qualities. 

This differs from traditional finance and its centralized databases since Banks can freeze and confiscate assets from their rightful owners when pressured politically, as seen in cases like that of Cyprus and their 40% bail in, or the United States’ confiscation of Russia’s foreign treasury reserves held in European custody.

But INDOPACOM did not explicitly talk about Bitcoin, the asset, in their comments; they seemed to think Bitcoin’s proof of work protocol could secure data and networks external to the Bitcoin asset. But the Bitcoin script, the logic internal to the Bitcoin blockchain, only governs BTC, its internal asset. 

For external networks to benefit from Bitcoin’s powerful proof of work macrochip, they would have to be anchored to Bitcoin somehow, and that’s where much of Lowery’s thesis starts to stall out. He does, however, develop this idea further by proposing the “Electro-Cyber Dome”.

Cyber Security Threats and the Electro-Cyber Dome

In Software 2.5, Lowery argues that “software system security vulnerabilities are derived from insufficient constraints on control signals” sent to networked machines. An example of this might be fake login attempts that cost a website more computer resources to authenticate than they cost attackers to send. Lowery adds that such vulnerabilities “can be exploited in such a way that it puts software into insecure or hazardous states.” Examples of such network security exploits include, but are not limited to:

  • Email spam and comment spam — superfluous emails and comments that flood inboxes or forums.
  • Sybil attacks — creation of large numbers of fake identities to manipulate systems.
  • Bots and troll farms — automated or coordinated accounts used to amplify malicious activity.
  • Weaponized misinformation/disinformation campaigns — flooding networks with false or manipulated information.
  • Distributed Denial-of-Service (DDoS) attacks — flooding networks with superfluous control signals (service requests) to overwhelm bandwidth.
  • Forged or replayed control signals — impersonating legitimate commands, orders, or data that put software into insecure/hazardous states.
  • Systemic exploitation of administrative permissions/insider abuse — exploitation of trust-based hierarchies where high-privilege accounts can be compromised or misused.

Lowery suggests that other networks could defend themselves against all of these threats to some significant degree using proof of work (POW) protocols like Bitcoin’s.

In the Bitcoin white paper, Satoshi Nakamoto defined Bitcoin’s POW quite elegantly: “The proof-of-work involves scanning for a value that when hashed, such as with SHA-256, the hash begins with a number of zero bits. The average work required is exponential in the number of zero bits required and can be verified by executing a single hash.”

Nakamoto specifically references Adam Back’s “Hash Cash, A Denial of Service Counter-Measure”, which was designed to make email spam costly by requiring computers sending an email to produce a POW stamp of a difficulty defined by the recipient of the email. Recipient servers would need to keep a list of stamps already used, in order to prevent reuse of the same work by attackers, aka to prevent “double-spending” attacks. These stamps, however, were not transferable, a quality which some cypherpunks wanted in their pursuit of digital money. Hal Finney was one such engineer who furthered the field by inventing RPOW, or reusable proof of work.

RPOW essentially tokenized POW stamps via a centralized server that kept track and facilitated transfers. One of Nakamoto’s key innovations was decentralizing this server and its list of spent stamps, in the form of the blockchain, while also defining a global difficulty algorithm that all Bitcoin miners must satisfy, rather than relative difficulty targets chosen by each website at will. 

Lowery, in his concept of the Electro-Cyber Dome, is essentially talking about Hash Cash. He specifically says that servers can choose the difficulty target they see fit, and never proposes that the Dome would or should use Bitcoin’s SHA-256 protocol, though it is implied in his idea of the macrochip. What he does do is use Bitcoin as the principal example of such a cybersecurity network actually working at scale; “We know for sure that electro-cyber domes can function successfully as a security protocol because this is what Bitcoin uses to secure itself and its own bits of information against systemic exploitation.”

Lowery goes further than defense, pointing out that as such systems gain adoption, a concept of aggression becomes possible by large miners, he writes; “it should be noted that this wouldn’t be a strictly “defensive” power projection capability…People with access to proof-of-power can theoretically “smash” through these electro-cyber dome defenses if desired. Thus, proof-of-power protocols are not strictly “defense only” protocols as some have argued. A top threat to people using physical cost function protocols like Bitcoin is other people using the same protocol (hence why Nakamoto mentions the word “attack” 25 times in an 8-page whitepaper, each time referring to people running the same protocol).”

Criticisms of Lowery’s Softwar Thesis 

Lowery’s Softwar thesis can be fairly described as controversial within the Bitcoin community. It’s optimistic take that large portions of military conflict could instead be settled via hash rate wars in some future has been described by Shinobi at Bicoin Magazine as “delusional”. 

Broadly speaking, critics reject the idea that data or networks external to Bitcoin can be secured in any way with Bitcoin’s technology stack, be it its POW, its blockchain or its native asset. Jameson Lopp did a multi-part review of Lowery’s thesis and book, praising many aspects of the thesis but ultimately dismissing its conclusions, saying that: “Softwar falls short on acting as a blueprint for how we should build the future.”

The most obvious question to me is whether using SHA-256 proof of work to gatekeep access to networks outside of Bitcoin makes sense in the first place, or if it could even be considered using Bitcoin. If the Electro-Cyber Dome is not demanding a high enough POW difficulty to mine any Bitcoin, if it does not use Bitcoin’s target difficulty, its asset or its blockchain, then is it using Bitcoin? 

Furthermore, given that China has the bulk of the ASIC manufacturing industry for Bitcoin mining, would INDOPACOM — the U.S. military branch in charge of keeping the Indo Pacific in check — really want to secure its cyber networks with algorithms that China mass produces chips to brute force? That seems like an awkward decision to make at best, and is more likely to lead them to consider alternative POW algorithms. But at that point, they certainly would not be using Bitcoin and would lose the macrochip argument. It would instead be using classic Hash Cash, and maybe that’s the lesson in this story. Lowery’s affinity with Bitcoin might be more of a marketing strategy and a shout-out to an industry that inspired him, rather than the actual tool that INDOPACOM might end up using.  

The Happy Middle Ground

In the gap between theory, implementation, and criticisms of Software style ideas, there exist some projects that serve as young but curious examples of how Bitcoin can secure more than money. 

SimpleProof, an Open Time Stamps-based Bitcoin notary of sorts, has been using the blockchain to record hashes of data, demonstrating that a certain version existed at a certain time. This very narrow use of Bitcoin as a time-stamping server helped defend one side of the Guatemala elections a few years ago from accusations of fraud by the opposition, resulting in real political consequences for the country. 

Michael Saylor, on the other hand, led the creation of what some have called the Orange Checkmark protocol on top of Bitcoin. This tech stack, which can be found on Github, is a privacy preserving Bitcoin native decentralized digital identity system. It gained some interest from the Bitcoin community when it was announced a couple of years ago, but it does not appear to have gained any adoption. 

Finally and ironically enough, Jameson Lopp, perhaps Lowery’s most verbose critic with three dedicated articles on the topic, actually implemented a proof-of-work-based spam protection mechanism on his website for a submission form, which, according to Lopp, works well. So if even he can see the use of these old ideas, even if just based on Hash Cash, then perhaps we will one day see Bitcoin-like technologies used to secure the networks and data of the world. 

This post What does Bitcoin “Power Projection” mean to the U.S. Military?  first appeared on Bitcoin Magazine and is written by Juan Galt.

Boltz Launches Non-Custodial USDC Swaps, Bridging Bitcoin Directly to Circle’s Regulated Dollar

6 May 2026 at 20:00

Bitcoin Magazine

Boltz Launches Non-Custodial USDC Swaps, Bridging Bitcoin Directly to Circle’s Regulated Dollar

Boltz, a leading non-custodial swap provider for Bitcoin, today announced the launch of USDC Swaps, enabling instant conversion between Bitcoin and USDC, the regulated stablecoin issued by Circle. Swaps are supported across all major Bitcoin layers, including the Lightning Network, and are live now at boltz.exchange.

“USDC Swaps mark a turning point for the Bitcoin ecosystem. For the first time, anyone can move between Bitcoin and the dollar most trusted by the regulated financial world without opening an account, completing KYC, or trusting a custodian in the process,” said the team in a press release shared with Bitcoin Magazine. 

A Non-Custodial Bridge

Exchanging Bitcoin for USDC is not new. What is new is doing it without giving up custody. Today, users who want to move between Bitcoin and a regulated dollar are typically funneled through centralized exchanges and brokerages that require account creation, identity verification, and full custody of user funds. A subset of services offer the same conversion without an account upfront, but because those services still take custody of user funds during the swap, they retain the ability to pause settlement and request identity documents if a transaction is flagged for review, with funds potentially getting confiscated in the meantime. The trade-off, in either case, has been the same: trust, surveillance, and friction in exchange for access.

Boltz removes that trade-off. USDC Swaps execute trustlessly, with no account, no sign-up, and no KYC at any stage. Funds remain under user control until the moment USDC arrives in the user’s wallet. This is the core innovation, and it is what separates Boltz from every other path between Bitcoin and Circle’s regulated Stablecoin.

Bridging Two Financial Worlds

For more than a decade, Bitcoin and the stablecoin economy have evolved on parallel tracks. Bitcoin built the open, permissionless side of the internet’s financial layer. Circle and USDC built the compliant, audited dollar that institutions require for operations. The two rarely connected directly.

USDC Swaps close that gap. With a single transaction, value can move between Bitcoin and a fully reserved, monthly-attested dollar that is already integrated into the products of Stripe, Coinbase, Visa, Mastercard, BlackRock, Robinhood, Revolut, Nubank, and a long list of banks, fintechs, and payment processors worldwide.

“The momentum is unmistakable,” wrote the Boltz team. USDC is the stablecoin that Stripe and Paradigm placed at the center of Tempo, their new payments-focused blockchain. It is the dollar on which Coinbase built its institutional infrastructure. It is the dollar that regulated card networks, asset managers, and global fintechs reach for when they need a digital dollar they can defend to a regulator. Boltz USDC swaps mean plugging Bitcoin directly into the rails that the regulated world is already standardizing on.

“Bitcoin and the regulated financial system have always been adjacent worlds, separated by intermediaries that demand custody and identity,” said Kilian Rausch, CEO of Boltz. “USDC Swaps remove that separation. A merchant accepting Bitcoin, a freelancer paid in sats, a treasury team managing operating capital, all of them can now reach the regulated dollar economy on their own terms, in seconds.”

Powered by the Cross-Chain Transfer Protocol

USDC Swaps are built on Circle’s Cross-Chain Transfer Protocol (CCTP), the native infrastructure that allows USDC to move across blockchains without wrapping or third-party bridges. Every USDC delivered through a Boltz swap is genuine, Circle-issued USDC, the same USDC accepted by regulated payment partners around the world.

By building on CCTP, Boltz is able to serve users across every USDC-supported network, including Ethereum, Arbitrum, Base, Polygon, and others, from a single, focused liquidity provider.

Use Cases Across Consumer and Business

Boltz believes that USDC Swaps unlock a broad set of practical applications, including:

  • Off-ramping Bitcoin into the banking system through regulated partners that already accept USDC, such as Stripe, Coinbase, and Bridge.
  • Day-to-day operations for Bitcoin-native businesses, such as paying vendors, funding payroll, and settling recurring bills in regulated dollars without leaving non-custodial infrastructure.
  • Merchant settlement for Bitcoin-accepting businesses that need to book revenue in compliant, accountant-friendly USDC.

All of the above are now unlocked without having to use crypto wallets outside of Bitcoin. Users send Bitcoin through Boltz and the recipient can receive USDC.

Bitcoin First, by Design

Boltz emphasized that the launch does not change the company’s Bitcoin-first orientation. All swaps remain non-custodial, all swaps settle atomically, and a “Bitcoin-Only Mode” continues to be available for users who prefer a stripped-down interface. USDC Swaps simply extend the reach of Bitcoin into a part of the financial system that, until now, has been difficult to access without trusted intermediaries.

USDC Swaps are available immediately to all users at boltz.exchange. Integration into various SDKs and the Boltz BTCPay Plugin is planned to follow in the coming weeks, according to the company.

This post Boltz Launches Non-Custodial USDC Swaps, Bridging Bitcoin Directly to Circle’s Regulated Dollar first appeared on Bitcoin Magazine and is written by Juan Galt.

Paystand Launches USDb Stablecoin on Bitcoin Layers for $100T B2B Payments

27 April 2026 at 22:00

Bitcoin Magazine

Paystand Launches USDb Stablecoin on Bitcoin Layers for $100T B2B Payments

Paystand announced the launch of USDb, a stablecoin designed specifically for commercial-scale business finance, including accounts receivable, accounts payable, payroll, and treasury operations, on the Bitcoin network.

Paystand is a Bitcoin-powered B2B payments network that processes accounts receivable and accounts payable for more than one million businesses across North America and Latin America. The company has handled over $20 billion in payment volume and built a full-stack CFO platform through acquisitions of Yaydoo, Teampay, and Bitwage, covering AR automation, spend management, LATAM compliance, and cross-border payroll. Founded in 2013 and headquartered in Santa Cruz, California, Paystand operates Paystand.org, a non-profit advancing financial inclusion through Bitcoin.

According to a press release shared with Bitcoin Magazine, USDb is backed 1:1 by USD reserves and is native two Blockstream’s Liquid network as well as Rootstock, both layers on top of Bitcoin. The company is pursuing a dual licensing strategy to support both U.S. and international growth. In the U.S., Paystand expects to launch in a GENIUS-aligned manner and achieve full compliance by the end of 2026. Internationally, the company “already maintains licenses enabling digital asset and wallet operations in relevant jurisdictions” according to Meredith Petty, GM at Paystand. Both the U.S. and international offerings are intended to be fully backed 1:1 by USD, with any distinctions relating only to regulatory structure, distribution, and use case rather than reserve backing.

The announcement was made on stage at Bitcoin Las Vegas. Paystand positions USDb as infrastructure for the roughly “$100 trillion B2B economy”, rather than for crypto trading or retail transfers. Its integration with Rootstock and the Liquid Network should bring a significant volumes and market activity to the Bitcoin ecosystem, with Ibex serving as USDb’s first minting partner and liquidity provider. 

“AI is eating labor. Bitcoin is eating capital. Stablecoins are eating financial services. USDb is where those three forces converge, and we’re launching it with the largest real-world business use case on the planet. USDb gives businesses a programmable digital dollar that works where they actually work. This isn’t infrastructure waiting for customers. This is the moment the B2B economy goes on-chain,” said Jeremy Almond, CEO of Paystand.

USDb launches with immediate adoption through Paystand’s acquisition of Bitwage in November 2025. Bitwage supports payroll and workforce payments for more than 90,000 workers and 4,500 businesses in nearly 200 countries, providing an initial cross-border payment corridor.

The stablecoin is engineered for integration with Enterprise Resource Planning (ERP) systems and existing business workflows. It is also designed to “support AI-driven, machine-to-machine transactions as agentic systems handle more financial operations,” according to the press release.

Paystand will initially roll out USDb to its own network. Expansion to external partners, additional enterprise customers, and broader Bitcoin infrastructure providers is planned throughout 2026.

Editorial Disclaimer: We leverage AI as part of our editorial workflow, including to support research, image generation, and quality assurance processes. All content is directed, reviewed, and approved by our editorial team, who are accountable for accuracy and integrity. AI-generated images use only tools trained on properly licensed material. In Bitcoin, as in media: Don’t trust. Verify.

This post Paystand Launches USDb Stablecoin on Bitcoin Layers for $100T B2B Payments first appeared on Bitcoin Magazine and is written by Juan Galt.

$1.3M-Funded OpenAgents Pays Gamers and Everyday PCs in Bitcoin via Pylon Distributed AI Network

27 April 2026 at 20:47

Bitcoin Magazine

$1.3M-Funded OpenAgents Pays Gamers and Everyday PCs in Bitcoin via Pylon Distributed AI Network

OpenAgents, an open-source artificial intelligence lab building Bitcoin-native infrastructure for machine learning, today announced its graduation from the BitcoinFi accelerator and the close of $1.3 million in pre-seed funding.

The company is using the capital to expand Pylon, its distributed compute node that lets people sell spare compute for Bitcoin, and to accelerate work on Psionic, its Rust-based machine learning framework for inference, fine-tuning, embeddings, image generation, and distributed training.

“America needs an open-source AI lab that can compete at the frontier without recreating the closed, centralized incentives of the biggest labs,” said Christopher David, founder and CEO of OpenAgents. “OpenAgents exists to build that lab in public. We are paying people directly for the compute, software, and data that make the system better.”

Building a Bitcoin-Native Compute Market

Pylon is OpenAgents’ compute miner. It runs on a contributor’s machine, connects to OpenAgents’ Nexus coordination layer, and makes selected local compute available to the network. Contributors are paid in Bitcoin through the hosted Nexus treasury for eligible work and launch-period payouts. This technology unlocks a path to earn bitcoin, not seen since the early days of Bitcoin mining, where come computers and GPUs were competitive enough in the hashrate race, and may introduce a whole new generation of gamers and AI fans to the cryptocurrency. 

The launch builds on open protocols already familiar to the Bitcoin and Nostr communities. Pylon acts as a Nostr client and NIP-90-style service provider, while Nexus coordinates provider presence, work assignment, telemetry, payout accounting, and public stats. The company operates a hosted Nexus today, but the code is open source and designed so other operators can run their own Nexus networks over time.

OpenAgents describes the near-term market as the OpenAgents Compute Market. The first live product families are inference and embeddings, with training work now being introduced through a more explicit assignment, validation, checkpoint, and payout flow.

From Online Nodes to Real Work

During the public beta, the Pylon network quickly moved from early liveness checks toward real assigned work. OpenAgents has reported rapid growth in online Pylon activity, “more than one million satoshis paid through the hosted Nexus treasury, and more than one thousand Pylon instances appearing during the first wave of public participation” according to a press release  shared with Bitcoin Magazine.

OpenAgents is preparing distributed training runs that will publish participation data, including online contributors, assigned contributors, accepted contributors, and model-progress contributors. The goal is to scale beyond prior decentralized-training demonstrations while keeping the public claims tied to verifiable assignment and acceptance records.

Training on Consumer Hardware

OpenAgents is focused on stranded consumer compute: Macs, gaming PCs, older machines, and other devices whose spare capacity is usually priced at zero. The company believes this pool represents a large untapped infrastructure layer for open AI. The training stack uses Psionic, OpenAgents’ Rust ML framework.

A Product Suite Above the Network

The compute network is part of a broader OpenAgents product stack and road map:

  • Pylon: the compute miner that lets users sell eligible local compute for Bitcoin.
  • Nexus: the coordination, treasury, stats, and work-assignment layer for Pylons.
  • Psionic: the Rust machine learning framework that runs inference and training work.
  • Probe: an open-source coding agent intended as a practical alternative to closed coding-agent tools.
  • Autopilot: the planned desktop superapp for personal agents, compute earning, and user-facing OpenAgents workflows.
  • Forge: the internal software-factory control plane for managing agent work, verification, and delivery.

OpenAgents plans to build user and business products on top of this compute network. The long-term intent is to create open alternatives to major closed sourced AI products, while routing revenue back to compute providers, developers, data contributors, and other participants who improve the system, paid in Bitcoin.

“The simple version is: pay the people,” David said. “If AI creates value from user compute, open-source software, useful data, and agent work, then the people providing those inputs should share in the upside. Bitcoin gives us the cleanest settlement layer for that.”

Open Development and Contributor Bounties

OpenAgents has developed in public through more than 200 technical updates and open-source work across its product and infrastructure stack. The company is now reopening Bitcoin-paid developer bounties for contributors who can help improve Psionic performance, expand model support, harden Pylon, build product workflows, benchmark against leading open-source systems, and improve developer experience.

The company is also hiring machine learning engineers to work full time on Psionic and the distributed training stack. 

Contributors are encouraged to join through the OpenAgents Discord, review the open repositories, and coordinate before submitting larger pull requests. The company expects to keep an updated bounty list at:

This post $1.3M-Funded OpenAgents Pays Gamers and Everyday PCs in Bitcoin via Pylon Distributed AI Network first appeared on Bitcoin Magazine and is written by Juan Galt.

“Bitcoin as Everyday Money” Event to Rally Industry Behind De Minimis Tax Framework at Bitcoin 2026

22 April 2026 at 22:11

Bitcoin Magazine

“Bitcoin as Everyday Money” Event to Rally Industry Behind De Minimis Tax Framework at Bitcoin 2026

Bitcoin for Financial Services will host “Bitcoin as Everyday Money,” a live event and livestream, on Tuesday, April 28, 2026, at 10:00 AM PT at The Venetian’s Satoshi Social Room (Rooms 2002–2004) during Bitcoin 2026 in Las Vegas

Capped at 100 in-person attendees and streamed globally via TFTC, the event invites policy leaders, industry executives, and business owners around a single objective: “getting a Bitcoin de minimis tax exemption passed in this Congress”, according to a press release shared with Bitcoin Magazine.

The event is headlined by Janessa Lopez, Head of Digital Assets Policy at Block, and David Zell, President of the Bitcoin Policy Institute. Lopez and Zell will open with a fireside chat on the state of play in Washington, sharing what they’ve seen behind closed doors on the Hill and the real probability of legislation passing in 2026. 

Lopez will follow with a live “BTC is Money” demonstration, showing how a small business can accept Bitcoin at the point of sale through Square — and what that experience looks like for a customer spending Bitcoin on a cup of coffee or paying a plumber. An audience Q&A and networking reception will close the program, which runs from 10:00 AM to 12:00 PM PT. The event is hosted by Wyatt O’Rourke and Jordan Guess of Bitcoin for Financial Services.

De Minimis Tax Framework at Bitcoin 2026

The event builds on a January 12, 2026, coalition letter sent to Senate Finance Chairman Mike Crapo and House Ways and Means Chairman Jason Smith, co-signed by the Bitcoin Policy Institute, Block, Bitcoin Voter Project, Crypto Council for Innovation, The Digital Chamber, MoonPay, and River. 

The letter lays out a three-pillar framework for digital asset tax policy: 

  • (1) cash-like treatment for GENIUS-compliant payment stablecoins with no transaction or annual limits.
  • (2) de minimis relief extended to “qualifying network digital assets” on blockchains with a trailing six-month average market capitalization above $25 billion — a threshold designed to capture Bitcoin while excluding thinly traded or speculative assets. 
  • (3) a value-based threshold of $600 per transaction and $20,000 per year, rather than a gain-based test that would require taxpayers to track cost basis on every coffee purchase.

“That framework responds directly to pending Washington proposals that would limit de minimis relief to stablecoins only” said the press release — an approach the coalition argues would leave the underlying compliance burden “largely unmitigated”, because every stablecoin payment still requires a taxable Bitcoin or Ethereum fee transaction to move on-chain.

The debate has spilled into public view, most notably in a March 2026 exchange between Block CEO Jack Dorsey and Coinbase CEO Brian Armstrong over whether Bitcoin was being actively excluded from de minimis discussions. Dorsey has been clear about what he believes is at stake, telling the Presidio Bitcoin podcast last year: “I think it has to be payments for it to be relevant on the everyday… if it doesn’t transition to payments and find that everyday use case, it just gets increasingly irrelevant. And that’s failure to me.”

“We see it with our clients all the time where they would love to spend their Bitcoin to further a circular Bitcoin economy, but the tax reporting requirements in place make this overburdensome for the masses, and therefore they still tend to only spend dollars,” said Jordan Guess, co-founder of Bitcoin for Financial Services. He added that, “We would like to see a free market decide what money they deem best to spend, without having the government favor one currency over another with the burden of self-tracking and reporting transactions on a decentralized Bitcoin ledger.”

The event is produced in partnership with Block, the Bitcoin Policy Institute, and BTC Inc., with sponsorship from Satoshi Pacioli Accounting, Bitcoin Well, and Falcon Rappaport & Berkman. TFTC will livestream the full program on its YouTube channel at youtube.com/@TFTC. Attendees will leave with a concrete call to action — including a unified script for contacting their representatives and a pointer to btcismoney.xyz as the organizing hub for the broader effort.

Registration for in-person attendance is open at luma.com/sy4ghp9o. Remote viewers can tune in via TFTC on YouTube at 10:00 AM PT on April 28. With the 2026 legislative window narrowing and Congress turning its attention to the midterms, the coalition’s message is urgent: “the path to Bitcoin functioning as everyday money in the United States runs through de minimis tax reform, and it runs through this Congress.”

This post “Bitcoin as Everyday Money” Event to Rally Industry Behind De Minimis Tax Framework at Bitcoin 2026 first appeared on Bitcoin Magazine and is written by Juan Galt.

Jason Lowery Appointed Special Assistant to U.S. Indo-Pacific Command Commander, Bringing Bitcoin Strategic Expertise

20 April 2026 at 20:41

Bitcoin Magazine

Jason Lowery Appointed Special Assistant to U.S. Indo-Pacific Command Commander, Bringing Bitcoin Strategic Expertise

Jason Lowery, former Deputy Director of Technology & Innovation at the United States Space Force, and author of Softwar: A Novel Theory on Power Projection and the National Strategic Significance of Bitcoin, has announced his new role as Special Assistant to the Commander, U.S. Indo-Pacific Command. 

In a LinkedIn update, he shared his Honor to receive the appointment, explaining that “In this new position, I will directly advise and report to the Combatant Commander on strategic priorities affecting the Department of Defense and the Indo-Pacific region.” Lowery added, “It’s a humbling responsibility during a critical time for our national security posture. I’m grateful for the trust placed in me to support this level of leadership, and excited to contribute to the mission.”

Lowery rose to Bitcoin fame as he made the case that Bitcoin is a new landscape of military technology and defense, where power is projected not via bullets, missiles or drones, but by commanding more hashing power, which governs Bitcoin’s proof of work protocol. Those who control enough hashing power can guarantee the confirmation of their Bitcoin transactions, and in extreme cases, those who dominate the hash rate can interfere in the confirmation of their enemies’ transactions. The thesis, which is best understood by reading Lowery’s work, poses Bitcoin as a fundamental change in military technology, akin to the discovery and proliferation of gunpowder or aviation. 

The announcement comes just days after Iran told FT they would specifically accept Bitcoin for safe passage through the Strait of Hormuz. While there have been no reports of the Bitcoin Toll of Hormuz becoming a reality yet, the story made international news and appears to have reached the halls of power in D.C. and the Department of War. While the Gulf states and the Strait of Hormuz fall under a different division of the DoW called CENTCOM, the timing of Lowery’s appointment nevertheless demonstrates a recognition of Bitcoin’s strategic value in geopolitics. He will be advising command over a wide region, including China, the Indian Ocean and the Pacific Ocean regions, many of which benefit tremendously from Gulf oil that passes through Hormuz. Some reports suggest China drew up 42% of its oil from affected Gulf states before the war.  

This post Jason Lowery Appointed Special Assistant to U.S. Indo-Pacific Command Commander, Bringing Bitcoin Strategic Expertise first appeared on Bitcoin Magazine and is written by Juan Galt.

Film Review: “Self Custody” Indie Film about Bitcoin on Amazon Prime

17 April 2026 at 17:10

Bitcoin Magazine

Film Review: “Self Custody” Indie Film about Bitcoin on Amazon Prime

In the wild west of money, where a forgotten password to your Bitcoin wallet can mean the difference between fortune and ruin, comes the taut 31-minute Bitcoin action-thriller Self Custody (2026). Co-directed by Garrett Patten (who also stars as the desperate lead) and Fernando Ferro, the micro-feature is produced by Patten’s own TBK Productions in association with Tucci & Company. 

The film features Entourage alum Adrian Grenier in a key supporting role, alongside UFC champion and Olympic gold medalist Henry Cejudo in his acting debut, and House star Odette Annable. After a private Sundance screening and pickup by Inaugural Entertainment for distribution, Self Custody (2026) arrived on Tubi and Plex before landing on Amazon Prime Video—delivering a compact, terrifying yet entertaining tale drawn from real-world stories of lost Bitcoin wallets.

Scott, a family man, finds himself in financial trouble after failing to organize his finances when his family friend and accountant gives him a call. Turns out Scott had gotten a signing bonus from some tech company he worked for in 2014, paid in Bitcoin. Today, presumably well into the 2020’s, that bonus is worth over 14 million dollars. The film follows Scott as he tries to claim this Bitcoin, quickly realizing his self-custody setup was done improperly, and he does not remember the PIN code to the wallet. 

The film is overall negative on self-custody as a practice, presenting the absolute worst-case scenario for a Bitcoin or crypto owner. A series of mistakes, presented as innocent but really born out of a lack of study or knowledge of the technology and industry, led Scott to catastrophic loss, in admittedly a very entertaining and action-packed fashion. It is a testament to the maturity of the Bitcoin and broader crypto industry that a film called “Self Custody” can end up on Amazon Prime, even if painting a broadly negative picture of this technology, which reimagines the financial system.

Overall, the film is worth a watch, and hopefully the directors and producers will fall further down the rabbit hole and tell the stories of Ukrainians and Iranians escaping war with their life savings thanks to Bitcoin, to show the other side and upside of radical financial sovereignty. 

SPOILER ALERT – Detailed Review

The film opens up with an intimidating statement: “It is estimated that more than 20% of all bitcoin, valued at over 200 billion, has been lost or stolen beyond recovery.” Shown in white text over a black background, the claim sets the stage for a story that is unlikely to end in a happy ending. 

The statement is also incorrect. The widely reported claim that 20% of Bitcoin is inaccessible, roughly 4 million bitcoins, refers specifically to ‘lost’ funds. This kind of research is possible in part because we can see the coins not moving for over a decade, in many cases, mined to addresses or ancient wallet types that are effectively obsolete or rarely used today. The primary source of the study is probably Chainalysis, in their 2017 era work on the topic, though the film does not provide a source for this claim.

According to Investopedia, the 3.7 million coins in question have been lost, not stolen. Lost to bad wallet setups, many in the early days of Bitcoin mining, and much of this claim remains an assumption, since it’s not easy to prove that such coins are really inaccessible. The claim that so many coins have been stolen — particularly from self-custody — is not backed up by the facts at all, and is clearly there to set the mood in the film, in what we can generously call artistic liberty over the reality at hand. If anything, a much larger amount of Bitcoin has been stolen from custodial, centralized exchanges that try to bring bank-like legacy finance institutions to the Bitcoin world. 

Film Review: “Self Custody” Indie Film about Bitcoin on Amazon Prime

The first scene introduces the audience to Scott and his family’s financial advisor and friend Cooper, who delivers the good news. Scott, thanks to a signing bonus paid in Bitcoin from work with a 2014 tech company, is now rich! But there’s a catch: he has to get access to the Bitcoins, whatever that means. 

Soon, Scott is sitting in front of his computer, opening a folder that contains the 14 million dollars in bitcoin. We see a Trezor hardware wallet and what appear to be some seed plates. It’s unclear if the plates are metal or just paper to write the 12-24 words that back up the Bitcoin wallet, but what soon becomes clear is that there are no words. Whenever Scott presumably created this wallet, he failed to write down the magic words. Mistake number one. 

It’s useful to note that in a normal self-custody setup, you would not usually store the magic words with the hardware wallet, which kind of defeats the purpose of the hardware wallet’s pin protection and advanced security features. If someone opened up Scott’s office drawer and found the Trezor, they could just put it aside and take the backup words — he had backed them up. Instead, a savvy Bitcoiner would engrave the words on metal plates, for which there are many products on the market, and bury them or stash them in a place more secure than his office drawer.

The Trezor would then serve as his secure computing environment, which is connected to computers that have internet access. The Trezor signs the transactions inside its own chip, and transmits the signed transaction to the user’s computer via USB cable, air gapping the user’s private keys, from the user’s most likely compromised computer. But that can all happen if the user has the pin, which Scott does not. 

Film Review: “Self Custody” Indie Film about Bitcoin on Amazon Prime

The user starts trying to guess pins and quickly realizes that he has a limited number of attempts. This isn’t just to make life difficult for people; it is a security feature that prevents a thief from trying pins forever until they find the right one. Once 10 failed attempts are made, the device deletes its contents, a factory reset of sorts, deleting the bitcoin keys. By the time Scott realizes he has no idea what the pin code is, he has two attempts left, not a good situation to be in. Usually, a user would have the backup words somewhere to regain access even if the hardware wallet got erased due to incorrect PIN attempts. But not Scott! No, he didn’t get one thing right.

Turns out, the 12 words are gone, not clear where they went. Most, if not all, Bitcoin wallets are very annoying to the user about writing those words down, with pop-ups and reminders. Even back in 2014, wallets were very explicit that not backing up those words could lead to loss. Scott, we have to assume did not take the care needed during the setup, nor did he listen to his boss at the time, Kevin, whom we get introduced to next.

Amy, Scott’s wife, finds him lying on the office floor in a mess, papers and devices everywhere. He finally opens up to her about the situation after a nasty fight the night before about the family finances. She convinces him to call Kevin, the crypto expert, rich guy who employed Scott back in 2014.

Soon, we see Kevin in an airport hangar walking towards a private yet cool-looking assistant who passes the phone to her boss, Scott is on the line. Kevin finds it in his heart and busy schedule to deliver a mouthful to his old employee and ex-friend, chastising him for not writing the magic words, giving a speech about financial crypto revolutions and coming off as a condescending and detached Silicon Valley billionaire. At some point, Scott asks if Kevin ever had kids, which he scoffs at. The conversation ends with Kevin putting Scott in contact with ‘a guy’ who can break into that Trezor. 


Here’s the thing: There’s a lot wrong with this picture, at least when it comes to Bitcoin. Most actual rich Bitcoiners I’ve met are family men and women. They don’t spend their wealth on private jets; instead, they are building out their homestead, homeschooling their kids and — as far as the American variety — stacking guns. Far from the stereotype of the billionaire high-tech narcissist loosely portrayed here or in shows like Silicon Valley. 

Also, someone that rich would have better contacts than the scammer Kevin recommends via a single text message with a phone number. In reality, there are companies out there that specialize in recovery services, mostly focusing on locked wallets like Scott’s. Some are scams for sure, and as the film points out in its credits, large-scale recovery scam operations have been shut down by the feds. So it is important to do deep research on who you work with to recover a locked wallet. When it comes to stolen crypto via hacks or fraud, there’s little anyone can do about it; cases can be reported to the FBI, but there are few successful examples when it comes to anonymous cybercrime.

One company that’s been growing a good reputation in the space for offering wallet recovery and self custody consulting services is The Bitcoin Way, another renowned company in this niche is Casa

Anyway, the recovery contact passed on by Kevin convinces Scott to drop the Trezor in an anonymous drop box, and well… let’s just say things don’t go well from there. But I’ll let you experience the ending for yourself, since it’s fairly entertaining.  

The film ends with this on screen that does beg some context: “In 2025, U.S. consumers lost more than 9.3 $billion to crypto scams.” What stat misses is that financial and identity-related fraud is north of $50 Billion for legacy financial crime. 

In 2012, for example, 24 billion dollars’ worth of identity theft was reported. Twice as much as all other forms of theft combined that same year. According to Business Insider, the Bureau of Justice Statistics show that “identity theft cost Americans $24.7 billion in 2012, losses for household burglary, motor vehicle theft, and property theft totaled just $14 billion.” Eight years later, that number doubled, costing Americans $56 billion in losses in 2020. If that trend continued, which there’s little reason to assume has slowed down, we could expect 2026-related identity financial fraud to be north of $70 Billion a year in the United States. So Fraud is rampant in general in this day and age, and trusting legacy finance with all your information is hardly a solution. 

Overall, the film represents an interesting exploration of the nightmare scenarios of self-custody and might serve as a great metaphor with which to improve education on the topic. 

Editorial Disclaimer: We leverage AI as part of our editorial workflow, including to support research, image generation, and quality assurance processes. All content is directed, reviewed, and approved by our editorial team, who are accountable for accuracy and integrity. AI-generated images use only tools trained on properly licensed material. In Bitcoin, as in media: Don’t trust. Verify.

This post Film Review: “Self Custody” Indie Film about Bitcoin on Amazon Prime first appeared on Bitcoin Magazine and is written by Juan Galt.

Satochip Announces Bridge Financing as It Prepares U.S. Push for Open-Source Hardware Wallets

14 April 2026 at 20:40

Bitcoin Magazine

Satochip Announces Bridge Financing as It Prepares U.S. Push for Open-Source Hardware Wallets

Satochip SRL, a Belgium-based company specializing in secure hardware solutions for digital asset self-custody, today announced that it has secured part of its ongoing bridge financing round with support from existing shareholders and new business angels.

The bridge round will support the company’s strategic expansion into the United States, enabling Satochip to establish a local presence and accelerate sales in one of the world’s largest digital asset markets.

Founded in Belgium, Satochip develops open-source secure hardware wallets and smart card solutions, designed to give users full control over their digital assets. The company’s technology emphasizes security, transparency, and sovereignty, “aligning with the growing global demand for self-custody solutions” according to a press release shared with Bitcoin Magazine.

Satochip SRL offers a focused line of open-source NFC smartcard-based hardware solutions for Bitcoin and cryptocurrency self-custody. Its flagship product, the Satochip, is a credit-card-form-factor hardware wallet equipped with an EAL6+ certified secure element that supports Bitcoin, Ethereum, and over 1,000 tokens and NFTs. It pairs with desktop wallets such as Sparrow and Electrum, as well as mobile apps, and requires no battery or screen—transactions are verified through connected software. The company also produces the Satodime, a giftable bearer cold-storage card serving as a modern paper-wallet replacement, and the Seedkeeper, a hardware vault for securely storing seed phrases and passwords. 

Satochip Announces Bridge Financing as It Prepares U.S. Push for Open-Source Hardware Wallets

All products are fully open-source (AGPLv3 Java Card applet), allowing users to flash generic smartcards themselves. Community adoption has grown notably through integrations such as the SeedSigner + Satochip combo, which enables users to build affordable, air-gapped DIY Bitcoin signing devices, experiment with the technology and develop new grassroots niches and use cases.

“The United States represents a critical market for the future of digital asset security,” said Bastien Taquet, co-founder of Satochip. “With strong support from our investors, this bridge round allows us to build a foothold in the U.S. market while continuing to innovate secure hardware solutions for the global crypto ecosystem. We are welcoming additional strategic investors who want to join us on this growth journey.”

The funding will primarily be used to establish a U.S. operational presence, expand sales and distribution channels, and strengthen B2B partnerships within the crypto ecosystem.  The Satochip Team will attend the Bitcoin conference in Las Vegas at the end of April.

Editorial Disclaimer: We leverage AI as part of our editorial workflow, including to support research, image generation, and quality assurance processes. All content is directed, reviewed, and approved by our editorial team, who are accountable for accuracy and integrity. AI-generated images use only tools trained on properly licensed material. In Bitcoin, as in media: Don’t trust. Verify.

This post Satochip Announces Bridge Financing as It Prepares U.S. Push for Open-Source Hardware Wallets first appeared on Bitcoin Magazine and is written by Juan Galt.

Why Iran Wants Bitcoin For Safe Passage Though The Strait Of Hormuz

13 April 2026 at 17:00

Bitcoin Magazine

Why Iran Wants Bitcoin For Safe Passage Though The Strait Of Hormuz

Iran’s grip over the Strait of Hormuz, one of the most important oil maritime transit choke points, remains firm. FT reported last week that Iran intends to charge a toll for passing, and Bitcoin was named the currency of choice. Here’s why this surprising turn of events has been predicted by Bitcoiners for over a decade.

On April 8, FT published a report titled “Iran demands crypto fees for ships passing Hormuz during ceasefire,” except it wasn’t crypto, it was Bitcoin. The report covered developments during the current two-week ceasefire in the war between the United States, Israel, and Iran, specifically over the Strait of Hormuz, which pre-war saw 20% of global oil flow through in tankers, supplying Europe, Asia, and much of the world. Iran as the article stated intents to charge a toll for ships to be allowed passage through Hormuz a key geographic choke point which Iran has tight control over via long range missles, underwater mines and attack drone technologies.

Why Iran Wants Bitcoin For Safe Passage Though The Strait Of Hormuz

The report  included an interview with Hamid Hosseini, a spokesperson for Iran’s Oil, Gas and Petrochemical Products Exporters’ Union, who told FT what oil vessels need to share inventory data with Iran and pay a $1 fee per barril of oil in Bitcoin to be allowed safe passate through Hormuz; “Once the email arrives and Iran completes its assessment, vessels are given a few seconds to pay in Bitcoin, ensuring they can’t be traced or confiscated due to sanctions.”

The report shook the Bitcoin community and made international news, as the Bitcoin price rose to $73,000 from the high 60’s. Iran’s choice to demand Bitcoin for safe passage instead of dollars, yuan, or gold is a profound recognition of Bitcoin’s superiority as money in the modern world. It validates decade-old theories by Bitcoiners that Bitcoin is money for enemies, fundamentally neutral, and thus ideal for international trade.

The facts are clear. Iran does not want dollars because the United States has already placed incredibly heavy sanctions on it, cutting it off from Western payment rails. Iran does not want the Chinese currency either, as it would become dependent on yet another major power, giving up its sovereignty. Gold would need to be transported somehow, from the ships to Iran, complicating matters or settled via the banking system, resulting in the same sanction risk that fiat currencies pose. Tether gold is not an option either for the same reason: a trusted third party that can be sanctioned holds the shiny rocks; not even the most transparent and cryptographically authenticated “trust me, bro” technology can get around that fact.

Only Bitcoin stands as a viable option to receive payment for a country at war like Iran, as the Bitcoin blockchain is an international network of highly interconnected nodes that resist censorship and thus sanctions by design, allowing quick and secure digital settlement.

Bitcoin acquired by Iran could be stored in multi-signature cold storage, a kind of high-security Bitcoin account that requires multiple keys to sign a valid withdrawal, and probably already does. The keys can be distributed throughout the world or across various bunkers in Iran, making confiscation or destruction of the access keys very difficult. Iran has had a long history with Bitcoin now, reported to have held up to 10% of the total mining capacity of Bitcoin at various times, giving them deep experience using and securing the asset.

Earlier that day, before the FT report even came out, Trump told ABC that a joint venture had been discussed with the Iranian leadership to secure the Strait of Hormuz. “We’re thinking of doing it as a joint venture. It’s a way of securing it — also securing it from lots of other people.” Impling a discussion between the U.S. and the Iranian leadership as peace talks continue and some compromises are explored to re-stabilize the international oil trade. 

This morning, I asked President Trump if he’s okay with the Iranians charging a toll for all ships that go through the Strait of Hormuz, he told me there may be a Joint US-Iran venture to charge tolls:

“We’re thinking of doing it as a joint venture. It’s a way of securing it —…

— Jonathan Karl (@jonkarl) April 8, 2026

The Saudis quickly put out a statement, “Allowing Iran any form of control over the strait would be a red line,” said Ali Shihabi, a commentator close to the Saudi royal court, according to The Times of India “The priority has to be unimpeded access through the strait.”

The FT report dropped soon after, followed by a Trump statement shunning the idea of a toll, where he said Iran “Should not charge fees”. He added that “There are reports that Iran is charging fees to tankers going through the Hormuz Strait — They better not be and, if they are, they better stop now!” 

But will Iran roll back the toll of Hormuz, and why would they?

Given the state of the conflict and dramatic collapse in international relations between the warring nations, Hormuz stands as the biggest advantage Iran has in the conflict. The Iranian regime has proven its resilience despite extensive bombardment of its military infrastructure and multiple assassinations of its leadership. Meanwhile, they continue to demonstrate long-range weapons capabilities with which they can block passage through Hormuz. The cost of these long-range weapons is far lower than the cost of the missile interceptors required to protect the oil tankers attempting to cross, and in war, economics matter a great deal.

Trump acknowledged this fact in a press conference where he said that one Iranian with a machine gun is enough to block safe pasage; “Look, problem with the strait, a guy can take a mine, drop it in the water and say, ‘oh, it’s unsafe’… Or you can take a machine gun from the shore and shoot a few bullets at a ship, or maybe an over-the-shoulder missile, small missiles.” he told CBS earlier in the month

The cost of attacking ships that go through the strait is far lower than the cost of defending them. Short of a much larger military escalation, there’s actually surprisingly little that the United States can do from a military perspective to secure the strait. In theory, the U.S. could win this war against Iran, but at what cost? Genocide perhaps, or boots on the ground and a full invasion? Ultimately, the U.S. could go as far as nuking Iran, but what consequences would any of those options have for the U.S.’s international relations, or the midterms, which republicans are expected to lose as it stands? The political costs could be too large. And the next regime to take hold in Iran would know that at any point, they could try the same Hormuz gambit.

The only long-term solution to this conflict is likely to be diplomacy, and the leverage Bitcoin gives to Iran as a sovereign nation’s sanction-resistant money will play into the negotiations. Especially if Bitcoin lets Iran monetize the toll of Hormuz.

What happens next?

If the toll of Hormuz stands and is not defused by either diplomacy or total war, then oil tankers looking to pass will need to acquire Bitcoin in the millions of dollars per ship. But that is easier said than done, since basically every Bitcoin exchange in the West is sanctioned from doing business with Iran, so shipping companies would have to acquire it from jurisdictions that allow it, likely in the East. There they could make a fiat payment to some exchange in China or Russia, perhaps, buy the Bitcoin and send it to Iran for the toll. This will increase demand and thus the price for Bitcoin in the east, making mining more profitable, which would in turn balance the hashrate distribution, which over recent years has concentrated in the United States.

China and Japan are some of the largest beneficiaries of the oil that passes through Hormuz, as is Europe, so all these nations now have an added incentive to not just facilitate Bitcoin trade at a corporate and national level, but also to acquire mining hardware, as it is fundamentally the only way to guarantee their transactions go through.

If the United States chooses to, it could try to coerce large Bitcoin miners into trying to censor Bitcoin transactions that pay for the Iranian toll, but that too will fail as long as there’s enough eastern hash rate, and the economic incentives in this case seem to favor the east. 

Editorial Disclaimer: We leverage AI as part of our editorial workflow, including to support research, image generation, and quality assurance processes. All content is directed, reviewed, and approved by our editorial team, who are accountable for accuracy and integrity. AI-generated images use only tools trained on properly licensed material. In Bitcoin, as in media: Don’t trust. Verify.

This post Why Iran Wants Bitcoin For Safe Passage Though The Strait Of Hormuz first appeared on Bitcoin Magazine and is written by Juan Galt.

The Core Issue: The Role and History of Bitcoin Core Maintainers

11 April 2026 at 16:00

Bitcoin Magazine

The Core Issue: The Role and History of Bitcoin Core Maintainers

Don’t miss your chance to own The Core Issue — featuring articles written by many Core Developers explaining the projects they work on themselves!

In the beginning there was only Satoshi Nakamoto and a powerful idea. Nakamoto started working on Bitcoin as far back as 2007[1], and as far as we know worked on it entirely himself, until a few weeks after his release of the Bitcoin white paper on October 31st 2008[2], when Nakamoto took on the first Contributor to the project, Hal Finney[3].

Running bitcoin

— halfin (@halfin) January 11, 2009

Finney, it turns out, was critical to Bitcoin’s early success. According to recently surfaced emails[4] Nakamoto’s node was unable to receive “incoming connections” for a couple of days after the minting of the genesis block, resulting in Finney being the only node other users could connect to. Nakamoto told Finney in a private email “Your node receiving incoming connections was the main thing keeping the network going the first day or two.”

Finney was also one of the first known reviewers and contributors to Bitcoin, Nakamoto shared the software with him and a few other cypherpunk legends before it was shown to the world. Finney even contributed code to the project before its first release, as revealed by Ray Dillinger who Nakamoto also shared pre-released versions of the code with.

In an interview conducted by Nathaniel Popper published on Dillinger’s blog, he said[5]; “It was when we started talking about floating-point types in accounting code that I learned Finney was involved in the effort. Finney was reviewing the transaction scripting language, and both the code he had, and the code I had, interacted with the accounting code.”

The timeline roughly matches the activity page of the oldest Sourceforge web archive we have of the Bitcoin project page, where Nakamoto added Finney to the project on December 18, 2008. This decision by Nakamoto marks the first instance of Maintainer level permissions possibly being held by anyone other than Nakamoto. It is possible and likely that Finney gained developer status within the Sourceforge Bitcoin project, allowing him to download, modify and upload versions to Bitcoin to the site.

The Role and History of Bitcoin Core Maintainers - Hal Finney the first bitcoin core maintainer

So, besides being a Contributor, reviewer, and a node runner, was Hal Finney also a Bitcoin Maintainer?

The strictest definition of a Maintainer is someone who has ‘commit access’ or write access to the primary development branch of a software project. Contributors to a project like Bitcoin may ‘commit’ code to development branches of the project, and submit ‘pull requests’ to have the code integrated to the master branch, but those updates can only be ‘merged’ into the master branch by its Maintainers[6] through “commit access”..

By that definition, Finney may very well count as the first Maintainer after Nakamoto, but being a Bitcoin core Maintainer is arguably a lot more than just having commit access. Maintainers must also have a good reputation among the developer community and be frequent, producing Contributors.

Bitcoin Maintainers have in some cases been active developers of the project, who were well known enough by other Maintainers and seemed to be a good fit for the role. In other cases, they have been active reviewers and auditors of the code, merging code contributions that appear to have consensus, and refusing to merge code that does not.

The Maintainer role in turn carries a high status within the Bitcoin industry, and it is vulnerable to reputation ending mistakes. In some cases, famous Maintainers have had their access revoked, when considered by other Maintainers to be compromised, as seen in the case of Gavin Andresen[7] when he endorsed scam artist Craig Wright as Satoshi Nakamoto. In other cases, Maintainers have quit the role, in response to targeted harassment as seen with Gregory Maxwell[8].

Generally, the Maintainer role in Bitcoin is expected by Contributors to be an engineering role and not a political one. Discussions on Github pull requests for example are expected to be about the technical and implementation details of a particular commit, rather than the person making the commit, their particular politics, allegiances. Discussions that touch consensus and are controversial or hotly debated are generally relegated to the Bitcoin mailing list and other forums, as do topics of a political nature.

It is important to note that whatever power there is embedded in the Maintainer role has arguably diminished over Bitcoin’s history, as the project has grown from the early days of Nakamoto. There are even examples of code getting merged to the master branch, only to be removed again[9] after further review, making decisions by Maintainers far from final.

Maintainers throughout Bitcoin’s history have at times been accused of being gate keepers, refusing to merge updates to Bitcoin that factions of the community support, often in part because other factions of the community oppose them. In this sense, the Maintainer role does carry a certain kind of ‘taste making’ power, the permission to discern whether a commit has consensus or not, something not easy to quantify.  

This exclusive permission to merge or not to merge may be an unavoidable necessity of open source development, as no project would be considered safe or stable if anyone could merge any code into it at any time. In an adversarial environment, a meritocracy that filters code suggestions based only on the content of the ideas and their merit is arguably the best model we can strive for, anything else is a centralizing political system.

As such, the Maintainer role has persisted across Bitcoin development history, often held by multiple people, expanding and contracting in responsibilities. The role often draws the attention and curiosity of the broader Bitcoin community, as Maintainers as well as Contributors earn, enjoy and suffer the burdens of an emergent kind of leadership, especially in technical matters.

Unfortunately, data about the very early stage of Bitcoin development is scarce, leaving us only with glimpses into what role Finney played before the Genesis block. Maintainer permission history is actually quite opaque across open source development. Hubs like Sourceforge and Github fail to expose commit access history or detailed membership permissions to the public. Records like Nakamoto adding Finney to Sourceforge are actually a rare sight in Bitcoin Maintainer history.

Nevertheless, version control systems like SVN and Git which were implemented weeks after the first release of Bitcoin, do track commits across time and branches for the public to review, giving us public insights into what has happened. As a result, our knowledge of Bitcoin Maintainer history tends to come from first and last commits made to the master repo, announcements on Bitcointalk, or other forums, and confirmation of access revocation by active Maintainers at the time —in rare cases. A significant portion of the research on this article comes from Bitcoin Core Maintainer Ava Chow’s documentation of the relevant history[10].

The tracking of commit access or Maintainers was improved in 2014 with the addition of the trusted-keys system,[11] which adds a white list of PGP public keys into the master branch of Bitcoin Core. Keys can only enter and exit the list via commits merged by active Maintainers, and all commits to the master branch should be signed, by the corresponding private keys, a process that anyone in the public can verify and audit, comparing the software signature to the corresponding PGP keys.

The trusted-keys system was added as a security safeguard by Matt Corallo[12], who told Bitcoin Magazine the feature was the result of a general process of improvements and optimizations, and not a response to any particular catalyst or event.

A Brief History of Bitcoin Core Maintainers: The Satoshi Nakamoto Era


On January 3rd 2009, Nakamoto minted the genesis block[13], effectively launching the digital currency into public beta. He added a message to the block that anchored and time stamped Bitcoin’s launch to the physical world with a headline from the British daily national newspaper, “The Times 03/Jan/2009 Chancellor on brink of second bailout for banks”. The headline is forever embedded in Bitcoin’s blockchain, a subtle yet immutable reminder of Bitcoin’s purpose and birthright.

On the night of January 8th 2009[14] version 0.1.0 of Bitcoin was released to the public, announced on various forums including the cypherpunk mailing list, on it Nakamoto wrote; “Announcing the first release of Bitcoin, a new electronic cash system that uses a peer-to-peer network to prevent double-spending. It’s completely decentralized with no server or central authority.”

The installable windows version of Bitcoin in this first release had been compiled by Nakamoto and the source code made available as part of a .rar file published on SourceForge.net. This act made Nakamoto the founder and Lead Maintainer of Bitcoin by default, a role built into the very nature of open source development. Nakamoto would take code commits from other developers during his time building Bitcoin, download them to his local machine, review and merge the code bases, and produce new version releases, a key task and work flow that differentiates Maintainers for Contributors throughout Bitcoin history. This process would continue until Nakamoto’s departure in December of 2010 and would impact versions 0.1.0 to 0.3.19 of Bitcoin.  

Multiple updates followed the first release of Bitcoin and by the end of January 2009, a third developer had officially become a Contributor to the project. Martti Malmi going by the username of “sirius-m” made the “First commit”[15] to Sourceforge, bringing online the SVN source version control system — a kind of git, popular at the time. Malmi committed to the ‘Trunk’ comparable to a master branch on Github, making Malmi the second official Maintainer in Bitcoin’s open source development history. Malmi would make a variety of contributions throughout 2009 including the first Linux version of Bitcoin, with the 0.2.0 release[16].

It wasn’t until the August of 2010 that Lazloh Hanyecz — famous for having paid 10,000 bitcoins for a pizza in 2010[17] — would join as Maintainer[18], a month after contributing the first iOS version of Bitcoin to the 0.3.0 release.

Part of Nakamoto’s role as Lead Maintainer of Bitcoin was the stewardship of the network. Nakamoto went as far as to personally ask Lazloh — who was one of the first to mine bitcoin with GPUs —  to slow down his production for the sake of the network. “The longer we can delay the GPU arms race, the more mature the OpenCL libraries get, and the more people will have OpenCL compatible video cards,” Nakamoto said to Lazloh in 2009[19], looking to prolong the CPU mining era of Bitcoin, which was a major incentive to run Bitcoin nodes at a time when the future price of the coins was entirely uncertain.

On July 17th 2010 on version 0.3.2[20][21] Nakamoto added the check pointing system, a security safeguard that hard coded a certain block height as valid and its corresponding winning hash. Its purpose was to protect the chain from miner attacks that could theoretically reorganize the chain well beyond what the “widely accepted block chain” was, Nakamoto said on the announcement, adding that “there’s no point in leaving open the unwanted non-zero possibility of revision months later.”

The checkpointing system would result in a new responsibility for future bitcoin Maintainers, who would have to hard code a new block height and its corresponding hash on future releases, well into Gavin Andresen’s era of Bitcoin development[22]. The checkpointing system was eventually phased out, as the proof of work made deep reorgs unfeasible.

The height of Nakamoto’s power as Lead Maintainer and project founder would be demonstrated during the value overflow bug event of October 2010[23], where three transactions created 184 billion bitcoin that did not and should not exist. The number of coins the transaction attempted to move was so large that the transaction validation code at the time “overflowed when summed”, breaking consensus.  

This is historically Bitcoin’s most famous bug, sometimes called the ‘inflation bug’ and was likely the most dangerous to the project’s survival. Various community members started noticing the transactions hours after they were mined into the network, springing Nakamoto into action, who, with the help of a few Contributors[24] including Andresen[25], created a patched version of Bitcoin[26] changing the relevant validation code.

Nakamoto asked miners to move to the patched version and resync the chain[27], resulting in a roll back of the network to a state before the invalid transactions were confirmed. This was a hard fork that rolled back 19 hours of Bitcoin blocks, and probably represents the peak of Bitcoin’s centralization under Nakamoto’s leadership, as well as the peak of power that has ever been concentrated in the Lead Maintainer role.

Following the events of the Value Overflow Bug, Nakamoto implemented the Alert System on version 0.3.11[28]. The feature — which was somewhat controversial — would make nodes at risk of a critical bug, show a warning and would disable essential features. This Alert System used messages that would have to be signed by a key only held by Nakamoto. He justified the feature saying that “getting surprised by some temporary down time when your node would otherwise be at risk is better than getting surprised by a thief draining all your inventory.” Months later Nakamoto disabled the Alert System in his final version release.

Per the SVN records, only Nakamoto ever merged the code of other Contributors and pushed new official release versions of the Bitcoin, at least until Gavin Andresen became Lead Maintainer in December 19th 2010[29]. Andresen had been contributing code to Nakamoto directly as early as February[30] that year, as seen in the release of 0.3.1, and would make his first commit to the SVN Trunk on October 11th[31], a couple of months before Satoshi Nakamoto published his final version on Bitcoin, 0.3.19[32], disappearing into history.

At the time of writing, over 1200 individual people have contributed code to the Bitcoin Core project.

The Gavin Andresen Era

With Nakamoto no longer contributing to the project, Gavin Andresen was left as one of the only active contributors to the project with commit access. Malmi had slowed down contribution as Andresen’s accelerated, so when Nakamoto left, Andresen was left as the default Lead Maintainer. While Nakamoto never made a public statement, granting the role to Andresen, he did send an email to Mike Hearn — a frequent Contributor at the time — famously saying “I’ve moved on to other things.  It’s in good hands with Gavin and everyone.”[33]

“With Nakamoto’s Blessing”[34] Andresen would take the mantle of Lead Maintainer of Bitcoin and would go on to expand the Maintainer team while also initiate the official migration from Sourceforge to Github[35], a process which would take some time. It wasn’t until July 14th of 2011 that we would see the first commit merged to Bitcoin from a branch on Andresen’s official github account[36].

Unlike the Nakamoto era of development, this merge was done by the Github platform, putting some trust on Github.com to not do something shady with the code, a process previously done by Nakamoto manually and on his local machine. It’s important to note that the differences between versions of the code are auditable anyway, Github merge or not, since the project is open source. Code merges in this era could and should have been reviewed by developers on both sides of the process, before Github merge and after, though an abundance of caution eventually led to the creation of the trusted-keys system. Nevertheless, this began a new trend in how code was merged into Bitcoin that would last for at least three years.

On September 13th, 2011, the Sourceforge Bitcoin project was officially shut down, favoring Github as the new collaboration platform, leaving the old Bitcoin page there as an archive. Since both Malmi and Lazloh were Contributors on Sourceforge primarily without Github accounts at the time, their commit access effectively ended with the official migration, as well as their slow down in contributions around Nakamoto’s departure.

On April 27 of 2011, version 0.3.21 was released, the first under Andresen’s leadership. It was also the first to include a Readme file a PGP signed[37] message that detailed the update, contained hashes for the released installables and gave shout outs to Contributors. Among the 16 Contributors named are well known bitcoin core developers like Luke Dashjr, Matt Corallo, Pieter Wuille and Jeff Garzik.

The next couple of years saw a flurry of new Maintainers, perhaps in an attempt to decentralize what ever perceived power and responsibility Gavin held via the Maintainer role, and to fill in the gaps left by Nakamoto, Malmi and Lazloh. Chris Moore[38] with the username “dooglas” gained commit access for a couple of months from January 21st[39] until March 31st 2011[40] and still contributes to the project from time to time[41].

A few months later on the first of June of 2011, Pieter Wuille gained commit access[42]. Wuille discovered Bitcoin in November of 2010 and soon started contributing to the project. After gaining commit access, Wuille would become a renowned Bitcoin core developer, generally credited with many small performance optimizations that sum up over time to large improvements in user experience among many other contributions[43]. Today Wuille holds the third most commits to Bitcoin core, under the “sipa” username according to Github.  

The Role and History of Bitcoin Core Maintainers - Sipa

Jeff Garzik would join as Maintainer a few days later on June 6th, 2011[44]. Garzik started contributing to Bitcoin as early as version 0.3.21 that year and would also become renowned Bitcoin developer, bringing his extensive experience from the Linux open source ecosystem[45] to the Bitcoin project. Garzik is generally credited with helping improve the stability of the Bitcoin client.

Years later in the summer of 2016 Garzik had his commit access revoked after “several months of inactivity” according to Chow. During these years the Bitcoin block size war had begun to heat up and Garzik was on the side of the big blocks update[46], leading to lots of debate, and friction with some factions of the Bitcoin community, a likely cause of his drop in development activity. Garzik would go on to lead one of the failed forks of that war a year later, version Segwit2x.

A month later on July 5th of 2011, Mara van der Laan (who identified as Wladamir at the time) was granted commit access, becoming the eighth official Maintainer of Bitcoin Core. Van der Laan started engaging in the Bitcointalk forum as early as November 2010 and started contributing to Bitcoin by May 2011[47] initially focusing on the GUI of the Bitcoin QT client and bringing deep academic experience in computer graphics[48].

On September 19, 2011 Nils Schneider going by the username “tcatm” gained commit access after frequent contributions focused on optimising the Bitcoin client for working in the background. During his time as a Maintainer, he made big contributions helping to internationalize the client, adding multiple language related updates[49], and oversaw the removal of the Crypto++ library, protecting the client from unnecessary dependencies[50]. Nils worked as a Maintainer for almost a year with his last commit made in May 31st, 2012[51].

In February 11 of 2012[52] Gregory Maxwell with the username “gmaxwell” merged his first commit to Bitcoin after various code contributions and a full year of active technical commentary on the Bitcointalk forum[53], starting off a three year career as a Bitcoin Maintainer. During this time, Maxwell focused largely on the P2P networking layer of the client as well as consensus and validation related work. To date he is held in very high regard by many in the broad Bitcoin community and occasionally contributes to technical discussions and debates. Maxwell gave up commit access in December of 2015[54] as the Bitcoin block size war was heating up, due to internet harassment and other related concerns, as he took the small block position. 

After a year or so of expanding the Bitcoin core Maintainer team, on September 27th, 2012 Gavin announced the next step in his vision for Bitcoin’s future, the Bitcoin Foundation[55]. Made in the image of the Linux foundation, which Gavin saw as a great example of a successful large open source project, the foundation attracted a great deal of attention and support as well as criticism. In his announcement post Gavin said; “I want the Bitcoin Foundation to be an open, member-driven organization, and hope that you or your organization will not only become a member but will help the Foundation accomplish its mission”. Over the next few years, the foundation would help pay the salaries of a variety of Bitcoin core Contributors and Maintainers.

The Mara van der Laan Era

In April 2014, Mara van der Laan was chosen by Gavin Andresen as his successor to the Lead Maintainer role, as Andresen had decided to move towards a more academic role he labeled “Chief Scientist”. In a blog post, published by Andresen on the Bitcoin Foundation website[56] he wrote; “Wladimir van der Laan has been paid to work on Bitcoin Core full-time for several months now – again, thanks to all of you Foundation members for stepping up and helping to fund core development – and has been doing a fantastic job. He has agreed to take over for me as the ‘Bitcoin Core Maintainer.’”

Under the usernames “Laanwj” and “wumpus”, Ven der Laan would oversee 9 years of Bitcoin Core developments, today holding the crown as having made the most commits to the Bitcoin repo[57] according to Github graphs, with 7,419 commits — most of them merges — to date. Van der Laan gave up the role in February 2023 for “personal reasons” according to Chow.

The Role and History of Bitcoin Core Maintainers - Laanwj

One of the first and most notable changes to the Maintainer role under Van der Laan was the implementation of the trusted-keys system, which was committed by Matt Corallo[58] on December 20th of 2014. The system helped solve the opaque nature of the Maintainer role, by adding a file with PGP public key fingerprints to the master bitcoin repository, as well as a series of related tools[59]. One of the tools makes sure that Maintainer commits are correctly PGP signed, another script can be used to verify commit signatures against the trusted-keys list of PGP keys.

By having these keys inside the master repo, only Maintainers are able to add and remove keys to the list with valid signatures, leaving a record on Git’s version control system, while giving us pull requests for the addition and removal of Maintainers, which Contributors and commit members can comment on.  

According to Corallo, the main role of the trusted-keys system was “to avoid trusting Github” to merge developer code, a practice normalized during Andresen’s era of development. Instead, Maintainers merge the code locally and update the repository.

On November 13, 2015, Jonas Schnelli was granted commit access, with the username “jonasschnelli”. He was granted the role of GUI Maintainer by Van der Laan, who announced it in the bitcoin mailing list[60]. Schnelli who started contributing in 2013 to Bitcoin would go on to reach the top 10 of Bitcoin Contributors by commits on github, many also likely being merges during his role as Maintainer, which lasted 6 years. Schnelli gave up commit access in October 21st, 2021 for personal reasons, writing a thread on Twitter reflecting on his experience and expressing strong confidence in the bitcoin developer community that proceeded him[61].

The Role and History of Bitcoin Core Maintainers - jonasschnelli

On April 13, 2016, Marco Falke was given commit access under the username “maflcko” [62]. Van der Laan announced the decision on the Bitcoin mailing list[63], saying “Hereby I’m announcing Marco Falke as the new Testing & QA Maintainer for Bitcoin Core.” Falke contributed to core all the way until 2023, when he decided to give up commit access and the Maintainer role, for personal reasons[64].

Less than a month later, on May 6th 2016, Gavin Andresen had his commit access removed. The decision made by Van der Laan came after Andresen endorsed now known Satoshi Nakamoto impersonator Craig Wright[65]. Many in the Bitcoin community were already skeptical of Wright’s claims and Andresen’s position at the time was quickly revealed to be based on deception by Wright. Months earlier, Mike Hearn, a Bitcoin Contributor who was seen as close to Andresen, advocated on a podcast that Andresen should revoke commit access from all Maintainers and become a “Benevolent Dictator” of Bitcoin[66], as is done in many other open source projects. Andresen did not follow Hearn’s advice, but the event demonstrated the levels of tension the Bitcoin community was under, as the block size war raged on, which Wright was also a part of.  

Years later Andresen would express his regrets about the events saying “I now know it was a mistake to trust Craig Wright as much as I did. I regret getting sucked into the “who is (or isn’t) Nakamoto” game, and I refuse to play that game any more.”

It would be a couple of years until the next Bitcoin Contributor would gain commit access. On December 4th of 2018, Samuel Dobson known by the username “MeshCollider” was made wallet Maintainer by Van der Laan[67]. Dobson had been making contributions to Bitcoin since at least the summer of 2017[68] and would go on to make over 300 commits throughout his Bitcoin developer career, focusing on the wallet side of the Bitcoin code base. Dobson gave up commit access and the Maintainer role in February of 2023 to focus on his PHD[69].

A year later on June 7th 2019, Michael Ford would gain commit access, the first in the latest generation Maintainers who works on the role to date. Wielding the username “Fanquake”, Ford might have been the first Contributor to gain commit access by Contributor consensus, having been nominated during a core developer meetup in Amsterdam[70] [71]. Nomination by Contributor consensus would become a trend after this period, demonstrating Bitcoin development’s trend towards decentralization, with meetings taking place in various locations and environments, and even via IRC.

Ford started contributing to Bitcoin in February of 2012[72] and would thereafter become one of the most prolific Maintainers in Bitcoin history, locking in second place for the most commits according to Github with 4920 to date, many of them merges and maintenance related updates to the work of other Contributors.

The Role and History of Bitcoin Core Maintainers - fanquake

The Contributor Consensus Era

On January 21st, 2021 Van der Laan published a blog[73] that would break with the tradition started by Nakamoto and Andresen, of having a Lead Maintainer for Bitcoin core development. In it, Van der Laan explained that she would start delegating many of her roles as Lead Maintainer, that Bitcoin was too large of a project now to use the model setup by Nakamoto and Andresen, and effectively that it was time to decentralize Bitcoin core development.

Van der Laan made explicit a series of duties that needed to be done by others and laid a road map for making the software release process of Bitcoin more censorship resistant, such as moving the Bitcoincore.org website to the ownership of an organization rather than be under her control, while encouraging mirrors. The setup of release distribution via torrents and possibly IPFS, skepticism towards Github.com and a call out to start looking for alternative code contribution platforms, and a threshold signing scheme for Maintainers to be able to sign releases via some kind of cryptographic consensus, rather than having one person be the final PGP signer of a release, among other ideas.

The blog post effectively marked the end of Van der Laan’s role as Lead Maintainer, and symbolized a maturation milestone in Bitcoin, which came months after the release of version 0.20.0 and only days after the version 0.21.0 release[74].

Hannadii Stepanov known by the username “hebasto” gained commit access in March 19th 2021 to be GUI Maintainer[75] for the Bitcoin client. Stepanov began contributing code to Bitcoin core in August 2018[76], with over a thousand code contributions before becoming a Maintainer, placing him at 5th place in Github’s commits ranking for the project with 2070 locked in to date. Stepanov remains a Bitcoin Maintainer as of the time of writing.

The Role and History of Bitcoin Core Maintainers - hebasto

Ava Chow gained commit access in December 12, 2020[77] as the wallet Maintainer, after contributing since January 2016[78]. Wielding the username “achow101” Chow is a well known Contributor whose efforts in the Bitcoin development community go beyond github contributions, including a significant portion of the historical research in this history of core Maintainers. Chow is also know to do Bitcoin core review livestreams on Twitch[79] which gathers an active audience, helping further technical Bitcoin education. Chow ranks on Github as number 4 with most commits at 2198, and still has commit access as of the time of writing.

The Role and History of Bitcoin Core Maintainers - achow101

Gloria Zhao gained commit access in August 7th 2022 after being nominated by Contributor consensus[80], for the role of mempool and policy Maintainer[81]. Zhao started contributing in March of 2020[82] and had at least 200 commits in Bitcoin core before gaining commit access. Today she ranks at number 9 according to Github with 777 commits in the repo. Zhao is a Maintainer to this day.

The Role and History of Bitcoin Core Maintainers - glozow

Russ Yanofsky gained commit access in June 10th of 2023[83] after being nominated by Contributor consensus[84], to the role of interface Maintainer. Russ specializes in modularization and multiprocess work which earned him the role, after contributing to the project since October 2016[85], with 970 commits for 7th place in Github ranking. Yanofsky is known by the username “ryanofsky” and remains a Maintainer to this day.

The Role and History of Bitcoin Core Maintainers - ryanofsky
Get your copy of The Core Issue today!

Don’t miss your chance to own The Core Issue — featuring articles written by many Core Developers explaining the projects they work on themselves!

This piece is the Letter from the Editor featured in the latest Print edition of Bitcoin Magazine, The Core Issue. We’re sharing it here as an early look at the ideas explored throughout the full issue.


[1] https://www.metzdowd.com/pipermail/cryptography/2008-November/014863.html 

[2] https://Nakamoto.nakamotoinstitute.org/emails/cryptography/1/ 

[3] https://web.archive.org/web/20090106201347/http://sourceforge.net/projects/bitcoin/ 

[4] https://www.coindesk.com/markets/2020/11/26/previously-unpublished-emails-of-Nakamoto-nakamoto-present-a-new-puzzle 

[5] https://www.ofnumbers.com/2018/10/01/interview-with-ray-dillinger/ 

[6] https://bitcoin.stackexchange.com/questions/99674/how-do-devs-decide-who-should-have-commit-access-what-is-the-process/99676#comment112930_99676

[7] https://web.archive.org/web/20230406134017/http://gavinandresen.ninja/Nakamoto 

[8] https://www.reddit.com/r/Bitcoin/comments/3x7mrr/comment/cy29vkx/ 

[9] https://github.com/bitcoin/bitcoin/pull/31908 

[10] https://bitcointalk.org/index.php?topic=1774750.0 

[11] https://github.com/bitcoin/bitcoin/blob/master/contrib/verify-commits/README.md 

[12] https://github.com/bitcoin/bitcoin/commits/master/contrib/verify-commits/trusted-keys 

[13] https://mempool.space/block/0 

[14] https://Nakamoto.nakamotoinstitute.org/emails/cryptography/16/ 

[15] https://sourceforge.net/p/bitcoin/code/1/tree/ 

[16] https://bitcointalk.org/index.php?topic=16.msg73#msg73 

[17] https://en.bitcoin.it/wiki/Laszlo_Hanyecz 

[18] https://bitcointalk.org/index.php?topic=238.msg2004#msg2004 

[19] https://www.bitcoin.com/Nakamoto-archive/emails/laszlo-hanec/1/ 

[20] https://bitcointalk.org/index.php?topic=437.msg3807#msg3807 

[21] https://github.com/bitcoin/bitcoin/commit/4110f33cded01bde5f01a6312248fa6fdd14cc76#diff-118fcbaaba162ba17933c7893247df3aR1344 

[22] https://github.com/bitcoin/bitcoin/commit/bd7d9140f915d68e0abfdcd7ebdbb681c87d18c7 

[23] https://en.bitcoin.it/wiki/Value_overflow_incident 

[24] https://bitcointalk.org/index.php?topic=822.0 

[25] https://bitcointalk.org/index.php?topic=823.msg9524#msg9524 

[26] https://sourceforge.net/p/bitcoin/code/139/log/ 

[27] https://bitcointalk.org/index.php?topic=823.msg9531#msg9531 

[28] https://bitcointalk.org/index.php?topic=898.0 

[29] https://bitcointalk.org/index.php?topic=2367.0;all 

[30] https://bitcointalk.org/index.php?topic=383.msg3198#msg3198 

[31] https://sourceforge.net/p/bitcoin/code/165 

[32] https://bitcointalk.org/index.php?topic=2228.msg29565#msg29565 

[33] https://www.bitcoin.com/satoshi-archive/emails/mike-hearn/16/ 

[34] https://github.com/bitcoin/bitcoin/commits?before=a4e96cae7d3db3f7bfffd14a7fb6754ffbbc084e+46430 

[35] https://bitcointalk.org/index.php?topic=2367.msg31651#msg31651 

[36] https://web.archive.org/web/20101218045728/http://sourceforge.net/projects/bitcoin/develop/ 

[37] https://web.archive.org/web/20110708091605/http://sourceforge.net/projects/bitcoin/files/Bitcoin/bitcoin-0.3.21/ 

[38] https://github.com/bitcoin/bitcoin/commit/86c0af514b59971f7a5c3876898165667cbbeb6b 

[39] https://github.com/bitcoin/bitcoin/commit/86c0af514b59971f7a5c3876898165667cbbeb6b 

[40] https://www.reddit.com/r/Bitcoin/comments/4hvevo/comment/d2t16mh/ 

[41] https://github.com/bitcoin/bitcoin/commits?author=dooglus 

[42] https://github.com/bitcoin/bitcoin/commit/fbfbf94deb4224ce65bdbbc9151ddd44a4128753 

[43] https://businessabc.net/wiki/pieter-wuille 

[44] https://github.com/bitcoin/bitcoin/commit/62b427ec5532065744f9836e6a7b1676428c3434 

[45] https://bitcoinwiki.org/wiki/jeff-garzik 

[46] https://medium.com/@jgarzik/bitcoin-is-being-hot-wired-for-settlement-a5beb1df223a#.qgx99rxpr 

[47] https://github.com/laanwj?tab=overview&from=2011-05-01&to=2011-12-31 

[48] https://dl.acm.org/profile/81474651580 

[49] https://github.com/bitcoin/bitcoin/commit/560078a7685b33bdc8d1a94631633cb2af841976 

[50] https://github.com/bitcoin/bitcoin/commit/6ccff2cbdebca38e4913b679784a4865edfbb12a 

[51] https://github.com/bitcoin/bitcoin/commit/50fac686541686191647ddabd87d6dae75c24c52 

[52] https://github.com/bitcoin/bitcoin/commit/9f3de58d83f54536076be44fe945f56670ef9b60 

[53] https://bitcointalk.org/index.php?action=profile;u=11425;sa=showPosts;start=6000 

[54] https://www.reddit.com/r/Bitcoin/comments/3x7mrr/gmaxwell_unullc_no_longer_a_bitcoin_committer_on/cy29vkx/ 

[55] https://bitcointalk.org/index.php?topic=113400.0

[56] https://web.archive.org/web/20140915022516/https://bitcoinfoundation.org/2014/04/bitcoin-core-Maintainer-wladimir-van-der-laan/ 

[57] https://github.com/bitcoin/bitcoin/graphs/Contributors 

[58] https://github.com/bitcoin/bitcoin/commits/master/contrib/verify-commits/trusted-keys 

[59] https://github.com/bitcoin/bitcoin/blob/master/contrib/verify-commits/README.md 

[60] https://gnusha.org/pi/bitcoindev/20151113073052.GB19878@amethyst.visucore.com/ 

[61] https://x.com/_jonasschnelli_/status/1451268520159875080 

[62] https://github.com/bitcoin/bitcoin/pull/7921 

[63] https://www.mail-archive.com/bitcoin-core-dev%40lists.linuxfoundation.org/msg00003.html 

[64] https://x.com/MarcoFalke/status/1627987123788824576 

[65] https://laanwj.github.io/2016/05/06/hostility-scams-and-moving-forward.html 

[66] https://www.youtube.com/watch?v=8JmvkyQyD8w&t=2878s 

[67] https://github.com/bitcoin/bitcoin/commit/1ca050254145ebbbbf5910bfee2e82a45e465ca1 

[68] https://github.com/bitcoin/bitcoin/commit/41f3e84aaca82540582fd5a93fd632e752c3e6bf 

[69] https://x.com/MarcoFalke/status/1627987123788824576 

[70] https://diyhpl.us/wiki/transcripts/bitcoin-core-dev-tech/2019-06-06-Maintainers/ 

[71] https://github.com/bitcoin/bitcoin/pull/16162 

[72] https://github.com/bitcoin/bitcoin/commit/27adfb2e0c1caeef3970605f519edf9058f119ef 

[73] https://laanwj.github.io/2021/01/21/decentralize.html 

[74] https://github.com/bitcoin/bitcoin/releases?page=3 

[75] https://github.com/bitcoin/bitcoin/pull/21615 

[76] https://github.com/bitcoin/bitcoin/commit/11b9dbb439a15ed275cba673fdc743c612ea374f 

[77] https://github.com/bitcoin/bitcoin/pull/23798 

[78] https://github.com/bitcoin/bitcoin/commit/5ed2f16480142f0887cc1a6257ff53e2abc3e5b6 

[79] https://www.twitch.tv/achow101/ 

[80] https://gnusha.org/bitcoin-core-dev/2022-06-30.log 

[81] https://github.com/bitcoin/bitcoin/pull/25524 

[82] https://github.com/bitcoin/bitcoin/commit/2455aa5d7f54befeade05795ed8f5dd89d01042a 

[83] https://github.com/bitcoin/bitcoin/pull/27604 

[84] https://gnusha.org/bitcoin-core-dev/2023-05-04.log 

[85] https://github.com/bitcoin/bitcoin/commit/18dacf9bd25154e184b097ee4e8f786d9be25637 

This post The Core Issue: The Role and History of Bitcoin Core Maintainers first appeared on Bitcoin Magazine and is written by Juan Galt.

EB82 – Mike Hearn - Blocksize Debate At The Breaking Point

Support the show, consider donating: 3Pxbqsv8AJgn68HoZ5jAz5otxWwJSisLPs (http://bit.ly/1Qt8fMk)Whether the block size should be increased to 20MB has created...

Stacked (formerly Lightning Pay) launches self-custodial Lightning wallet as New Zealand’s last major non-custodial Bitcoin exchange

9 April 2026 at 22:23

Bitcoin Magazine

Stacked (formerly Lightning Pay) launches self-custodial Lightning wallet as New Zealand’s last major non-custodial Bitcoin exchange

Formerly known as Lightning Pay, Stacked may be the only Bitcoin exchange left standing after a series of mergers and bankruptcies in the New Zealand crypto industry. Doubling down on their vision to make Bitcoin “useful as money,” they just launched a self-custodied Lightning wallet.

Found at StackedBitcoin.com, the company has taken a different path than larger exchanges in the country, which, according to Simon, co-founder and CRO of Stacked, are going all-in on selling custodial and paper bitcoin. Exchanges like Sharesies are built following the Robinhood model, with no path to withdraw crypto to self-custodied wallets. While EasyCrypto, a popular swap exchange that received user fiat and sent crypto back to user wallets — similar to the Bull Bitcoin model — was recently bought out by SwyFTX and shut down, funneling its userbase to the parent custodial exchange. 

Stacked, a 4-person company that’s seen significant growth in the country in recent years, believes this is the wrong direction for the local Bitcoin industry, and as such has launched a self-custodied Bitcoin and Lightning wallet that complements their own swap exchange offering. Users send fiat to Stacked and receive Bitcoin into their self-custodied wallet of choice. They can also pay utility bills or even their rent with Bitcoin through Stacked, who settle out the fiat recipients via New Zealand’s innovative Open Banking payments framework. 

Stacked (formerly Lightning Pay) launches self-custodial Lightning wallet as New Zealand’s last major non-custodial Bitcoin exchange
Stacked (formerly Lightning Pay) launches self-custodial Lightning wallet as New Zealand’s last major non-custodial Bitcoin exchange
Stacked (formerly Lightning Pay) launches self-custodial Lightning wallet as New Zealand’s last major non-custodial Bitcoin exchange

The Stacked wallet, which features a sleek and modern design, uses Breez and Spark SDKs in the back end to provide users a stable and easy-to-use Bitcoin experience, with full Lightning Network integration. The app lets users purchase Bitcoin manually and on a schedule via Autostack a DCA style set it and forget it purchase feature. Users can also manage contacts in the app to pay with bitcoin on their end and deliver fiat to recipients. The country has no capital gains tax; instead, Bitcoin profits are taxed as income, resulting in what may be a much more favorable regulatory environment for hyper Bitcoinization.  

Stacked has been focusing its efforts to make Bitcoin useful as money in the Bitcoin Basin, a growing circular economy in Queenstown, New Zealand, which boasts around Bitcoin-accepting merchants to date. The company has created a dedicated website for the community and hosts regular events in the area, encouraging the local bitcoin economy. 

Stacked (formerly Lightning Pay) launches self-custodial Lightning wallet as New Zealand’s last major non-custodial Bitcoin exchange

In the 2025 financial year, 227,000 New Zealanders were identified as unique cryptoasset users partaking in around 7 million transactions. Local cryptocurrency exchange volumes reached approximately NZ$7.8 billion. Stacked projects the local digital asset market will to generate revenue exceeding US$200 million in 2026. Nearly 50% of New Zealanders are current or prospective Bitcoin and digital asset investors, according to 2024 research by Protocol Theory.

This post Stacked (formerly Lightning Pay) launches self-custodial Lightning wallet as New Zealand’s last major non-custodial Bitcoin exchange first appeared on Bitcoin Magazine and is written by Juan Galt.

Second’s Bark Boasts New era of Bitcoin Payments, drawing in former Blockstream developers

6 April 2026 at 21:34

Bitcoin Magazine

Second’s Bark Boasts New era of Bitcoin Payments, drawing in former Blockstream developers

Second, a new Bitcoin development lab, has gained attention recently as it drew in yet another former Blockstream employee known as “Grubles”, with over 8 years of engineering at the company. Bark, Second’s lead product, promises to deliver a next-generation “Fast, low-fee, self-custodial” wallet. 

After 8+ years, today is my last day at Blockstream.

It’s been an incredible opportunity to work with such a world class team on both the marketing and engineering side, and words alone do not convey my gratitude for the experience.

Even though I’m leaving, I’m super excited…

— grubles (@notgrubles) March 3, 2026

Alongside Grubles, other former Blockstream employees have joined the Second, such as Neil Woodfine (CMO), Steven Roose (CEO), and Erik De Smedt (CTO). The lab is currently focused on the cutting-edge of end-user Bitcoin wallet technology. In this niche of the industry, the Ark protocol is the new kid on the block, a layer two payments protocol that makes different trade-offs than the Lightning Network to deliver end users scalable self-custody and payments features at a low cost. Bark is Second’s custom implementation of the Ark protocol, designed for interoperability with the Lightning Network. 

“The technique used for Bark is different from payment channels in Lightning, but the two are actually very complementary.” Grubles told Bitcoin Magazine in an exclusive interview, adding that “At Second, we’ve chosen to build an Ark that is focused entirely on making Bitcoin onboarding and payments excellent.” Their website describes an Ark-to-Lightning bridge that lets users pay Lightning invoices directly from an Ark balance with no channels, liquidity, or LSPs required. Handled atomically.

According to Grubles, the company has raised 5.1M from a private investor, with a team of 11 people working on Bark. Deep technical documentation about the project can be found at second.tech, with the main net launch expected “Soon”. 

Interested users can test out making Bark payments on Signet. “I highly recommend doing so since it’s such a shift in the way we can do onboarding and payments,” said Grubles, encouraging early adopters to test out the tech. 

Scaling Bitcoin Self-Custody

The most impressive claim made by Bark is the promise of self-custody at a low cost. While it is relatively trivial to scale Bitcoin payments in a custodial manner, as demonstrated by apps like Wallet of Satoshi, or as is being done now by the payments giant Cash App. Delivering self-custody for relatively small amounts of value to millions of people is another matter entirely.

Onchain Bitcoin can handle roughly 7 transactions per second, which does not scale to too many users if they are all doing maximum self-custody on-chain transactions multiple times a day. To quote Knifefight’s excellent article on the matter on Bitcoin Magazine, tittled “Free As In Freedom Is Not Free As In Beer”; “Bitcoin confirms ~0.4M transactions/day. That’s one transaction/person every ~55 years, assuming no one is born or dies while waiting.” Onboarding users with onchain Bitcoin can also be rather awkward, as wallets correctly signal that deposits made to new users are pending confirmation until confirmed, which can take up to 30 minutes while blocks are mined. 

To address the challenges of scaling Bitcoin payments to the whole world, while retaining the cypherpunk and decentralization qualities of onchain self-custody, the Lightning Network was developed, and for the most part, it has worked, but with significant trade-offs. Self hosting a sovereign Lightning node, — while easier than ever today — still requires a significant learning curve, or specialized hardware that pushes all the right buttons for you. Both of these barriers to entry are too much for most people who don’t care about tech and just need to be able to pay a bill securely.

Mobile wallets like Phoenix have taken Lightning Network-style self-custody to end users, but with some caveats. Users need to trust Phoenix with some extreme scenarios, while they also give up a significant amount of privacy, since Acinq, the app developer, needs to know user balances pseudonymously to process transactions. Users are also locked into Phoenix as a liquidity provider, paying often higher fees than custodial lightning alternatives. The app is non KYCed, and offers users self-custody recovery paths, and an excellent feature set, but still falls short of the user experience expected from cash, where onboarding is as easy as handing a new user some paper money — no liquidity challenges, channel managment or onboarding fees — and payment is as easy handing over a bill and calculating the cash back for change.

Phoenix specifically works very well after users have been onboarded, but the process can cost over $10 dollars in SATS and take over 30 minutes, which is too high a cost when trying to sell Bitcoin as digital cash, and trying to onboard new people on the spot.

Other companies have attempted to solve these scaling and user experience challenges by leveraging Blockstream’s Liquid Network, an international federation of Bitcoin corporations that operate an alternative Bitcoin-compatible blockchain with fast block times and much larger on-chain capacity. Wallets like Bull Bitcoin or Aqua onboard users with Liquid’s LBTC, which can take a minute or less to confirm a transaction and then offer them a built-in swap exchange to onchain BTC, or the Lightning Network for payments compatible with the broader Bitcoin market. 

Both of these solutions work ok, but Bark believes they can do better. The reasonable self-custody recovery paths that onchain Bitcoin users know and love, with the instant payment velocity of the Lightning Network, are both delivered upon app download to users, without the onboarding roadblocks of a Liquid side chain or Lightning channel management. 

“I think the UI for Bark wallets will be simplified in comparison, considering how you won’t need to differentiate between L-BTC and BTC,” said Grubles of current Liquid and Lightning solutions. “This is important when thinking of onboarding new Bitcoin users. You don’t want to bombard them with information that can be confusing.”

“Don’t get me wrong, we love Lightning,” added Grubles, explaining that “Many of us at Second have worked on projects like Blockstream’s Core Lightning or are currently working on things like the rust-lightning library…So I do not say it lightly that Lightning is in Second’s DNA. With a Bark wallet, you can receive some bitcoin and begin doing Lightning payments literally in seconds. All of the liquidity micromanagement is gone. The onboarding potential is huge, and a large reason why I was attracted to Second and the technology in Bark.” 

The Virtual UTXO

As an implementation of the Ark protocol, Second’s Bark lets users pay each other with Virtual Unspent Transaction Outputs, or vUTXOs. Shinobi, the Technical Writer for Bitcoin Magazine, wrote about the Ark protocol in 2025 in detail, explaining that vUTXOs “are simply pre-signed transactions that guarantee the creation of a real UTXO under the unilateral control of a user once submitted onchain, but are otherwise held offchain.”

“There are other exciting things you can do with VTXOs, such as mass payouts,” said Grubles of the scalability of Bark. “Imagine you’re an employer and need to process payroll. That’s something you can do with instant finality and low fees using Bark. Mining pools could also offer more frequent payouts for their clients instead of forcing them to wait a long time because onchain fees can be high.”

These vUTXOs function in a similar way as Lightning Network transactions, moving offchain with an option to settle to the main Bitcoin blockchain when needed. Though unlike the Lightning Network, each Ark implementation has a centralized coordination server that enhances the service, this is the main trade-off made by Ark-style protocols, and its risks are mitigated by moving all self-custody-related power to the end user in what is often described as “unilateral exit” capabilities. 

Shinobi further explained the trade-offs of Ark, saying, “The protocol depends on a central coordinating server in order to function properly, but despite that, it is able to provide the same functionality and security guarantees that the Lightning Network does.” Similar to Lightning, self-custody is governed by a kind of smart contract with multiple people involved and a time constraint, in this case, the Ark operators, each user, and a round to refresh vUTXO’s every month or two. “As long as a user stays online during the required time period,” Shinobi adds, “(unless they choose to trust the operator for short periods of time) every user is capable of unilaterally exiting the Ark system at any time and taking back full unilateral control of their funds on-chain.”

This unilateral exit is the very definition of self-custody in the context of Bitcoin. By enabling it offchain, it bypasses the constraints of Bitcoin’s block size, respecting the decentralization of the network, so users can run full nodes, audit the full supply and integrity of the chain, but also access unprecedented levels of sovereignty over their money, even in a future where the fees are high and the blocks are full. 

Grubles believes the time constraint in Bark is not only manageable but more lenient than that of the Lightning Network; “There are real tradeoffs like with any scaling solution. Wallets need to come online at least once a month (though Lightning technically requires always-on to be secure). Emergency exits require multiple onchain transactions and can be expensive, but cooperative offboards are the normal path,” adding that “I think the breakthrough is going to come down to execution. As long as we’re managing our Lightning gateway well and have a reliable SDK, the ingredients are there to deliver a bitcoin payment UX that beats everything else out there. Our expectation is that Bark becomes the default way end users engage with the Lightning Network.”

This post Second’s Bark Boasts New era of Bitcoin Payments, drawing in former Blockstream developers first appeared on Bitcoin Magazine and is written by Juan Galt.

LNVPN Rebrands to Nadanada.me as Privacy Infrastructure Expands with Anonymous eSIMs and Lightning Payments

2 April 2026 at 18:36

Bitcoin Magazine

LNVPN Rebrands to Nadanada.me as Privacy Infrastructure Expands with Anonymous eSIMs and Lightning Payments

Offering anonymous eSIM data plans in over 200 countries, disposable and rental phone numbers for SMS verification, WireGuard VPN access and anonymous AI chat tools, LNVPN has outgrown its original brand. The company has grown into a full-spectrum privacy infrastructure service.

The company started in 2022 as LNVPN. It began as a proof-of-concept Lightning Network VPN built for the Oslo Freedom Forum after Alex Gladstein asked the team to create a Lightning-enabled VPN for activists in oppressive regimes. The original focus was short-term VPN access paid with Lightning, allowing users to buy service by the hour or day instead of monthly subscriptions.

The service grew quickly. Users liked the flexibility of short-term access without accounts or contracts. In 2023 the company won a price in the 2023 bolt.fun hackathon and added SMS verification services. Users pay a Lightning invoice for a disposable phone number and receive a one-time confirmation code. The system uses HODL invoices so that if the code does not arrive the payment is refunded automatically.

The company later introduced eSIM data plans available in more than 200 countries. Customers buy fixed data bundles that can activate anonymously. Rental phone numbers followed last November. These let users rent a unique phone number for three, six or nine months to receive unlimited SMS messages without creating an account. At present the rental numbers are available only in the United Kingdom, with United States numbers planned for May. The team also launched anonymous AI chat services that require no sign-up or login and are free to use. 

The name nadanada.me comes from the Spanish phrase for “nothing at all.” As the company stated, “What do we know about our users? Nada. What do we log? Nada. The name is the promise.”

This approach stands in contrast to traditional service providers that collect large amounts of user data, a practice that has led to repeated large-scale breaches at major corporations and government contractors. 

In November 2025, analytics provider Mixpanel was hacked, exposing names, email addresses and approximate location data of some OpenAI API users. In early 2025, U.S. government contractor Conduent suffered a ransomware attack that compromised personal and health records of more than 25 million Americans. In January 2026, cryptocurrency hardware wallet maker Ledger reported that customer names and contact information were exposed through a breach at its third-party payment processor Global-e. Such incidents frequently enable identity theft, as stolen personal details like names, emails, addresses and health or financial records can be used to open fraudulent accounts, file fake tax returns or impersonate victims.

Nadanada.me represents a new generation of privacy services integrated with Lightning in pay-as-you-go models that leave no trace on the financial system or the blockchain, in defense of user privacy.

This post LNVPN Rebrands to Nadanada.me as Privacy Infrastructure Expands with Anonymous eSIMs and Lightning Payments first appeared on Bitcoin Magazine and is written by Juan Galt.

The Amazing Life of Chun Wang: From OG Bitcoin Miner to Astronaut

24 March 2026 at 16:00

Bitcoin Magazine

The Amazing Life of Chun Wang: From OG Bitcoin Miner to Astronaut

On March 31, 2025, Chun Wang, co-founder of the historic Bitcoin mining pool f2pool, launched as mission commander of Fram2—the first crewed spacecraft to enter a polar orbit. The SpaceX Crew Dragon Resilience lifted off from the Kennedy Space Center on a Falcon 9 rocket into a 90-degree retrograde inclination orbit passing directly over the North and South Poles. No prior crewed mission had achieved this trajectory; the previous highest inclination for humans in orbit was 65 degrees on the Soviet Vostok 6 flight in 1963.

In an exclusive interview with Bitcoin Magazine, Wang shared one of his most memorable moments in space: “I don’t remember much from my time in space, but gazing down at the Earth rotating below, I just kept thinking: we’re flying so fast, how could we possibly get back down to the ground? The distance itself isn’t actually that great, less than 500 km, but the enormous difference in velocity is what matters. It reminded me of what I learned about the uncertainty principle,” he added, referring to Heisenberg’s 1927 physics theorem, which states that there is an inherent limit to how precisely certain pairs of physical properties of a quantum particle can be known simultaneously. The most famous pair is position (x) and momentum (p, which is mass times velocity).

The Amazing Life of Chun Wang: From OG Bitcoin Miner to Astronaut

He continued, “Δx ⋅ Δp ≥ ℏ/2: position only makes sense when you consider momentum together with it. Both determine whether two objects can really ‘meet.’ Here, distance isn’t just the difference in position vectors; it must be considered together with the velocity vectors, too.” The two objects he was probably considering were Earth and the Fram2 spaceship he was aboard, both moving at incredible speeds, and which could easily miss each other for landing if not for the minds of great engineers. 

Wang led an all-civilian crew of first-time astronauts: vehicle commander Jannicke Mikkelsen, a Norwegian filmmaker and polar explorer, pilot Rabea Rogge, a German robotics researcher, and mission specialist Eric Philips, an Australian polar explorer. The mission lasted three and a half days with no docking to the International Space Station. The primary objectives were polar Earth observation and execution of 22 research experiments

Space may have been the most extreme travel destination for Wang, but it was far from the first. Wang is on a self-declared mission to visit every territory on earth, described on his X profile as “Documenting my travel to every country/territory in the world following ISO 3166: 60% (150 of 249) on 1 planet/moon(s) done and counting.” To date, he boasts over 1153 different flights around the world, averaging 36 a year, including many recent visits to Antarctica and polar regions. 

Wang was not always such an avid traveler, however. Born in 1982 in Tianjin, China, Wang was five years old when his grandfather brought home a world map that sparked a lifelong obsession with exploration, but it wasn’t well into his adulthood that he began traveling the world, after building a legendary career as an early Bitcoin miner and pool operator. Computers entered his life early: he heard about them at age seven and owned his first 486 SX running MS-DOS by 13. He learned to code games and planetary gravity simulations. University followed through programming contests, but he dropped out without a degree and moved between software jobs across China.

Bitcoin entered his world in May 2011. Wang saw two articles on the Chinese tech site Solidot and spent the night reading the Bitcoin wiki. “Driven by curiosity, I opened the wiki link on en.bitcoin.it and studied it for one night. I finally understood everything, and it was like the discovery of the New World,” he wrote in his 2015 memoirs. He borrowed $40,000 from his father, mined on a MacBook at 800 khash/s, then scaled up with GPUs bought in Zhongguancun. Over the first two years, he personally mined 7,700 BTC, netting roughly 2,700 after power costs. He sold most in January 2013 at $11 to repay the loan.

The Amazing Life of Chun Wang: From OG Bitcoin Miner to Astronaut

Early GPU mining rigs in China, the kind of setup Chun Wang used before founding f2pool. (Credit: f2pool official history)

In April 2013 Wang co-founded f2pool with Mao Shihang, known online as Discus Fish. They set up in Wenzhou. Wang coded the backend; Discus Fish handled operations. The pool launched on May 5 and quickly grew to command roughly one-third of Bitcoin’s hashrate at its peak. 

To this day, f2pool mined over 1.3 million BTC, more than 9 percent of all blocks ever produced. It remains one of the largest and longest-running mining pools in Bitcoin’s history. During the 2017 block-size wars, the pool played a quiet but decisive role supporting Bitcoin’s Nakamoto consensus. Wang later stated: “Proof-of-work is the constitution of Bitcoin. Please respect mining and respect the miners. Without miners’ support, we wouldn’t have had SegWit activated, and we wouldn’t have made the Lightning Network possible.”

From 2014 through the early 2020s, Wang kept f2pool operating while navigating industry shifts, including China’s 2021 mining crackdown that pushed operations offshore. In 2017, he discussed the coming proof-of-stake era with Vitalik Buterin. That conversation led him to launch stake.fish in 2018, a non-custodial staking service that became one of the largest validators across Ethereum, Polkadot, Solana, and other networks. The move diversified his infrastructure business across the broader crypto industry, bringing his experience as a large operator to the rapidly transforming crypto market.

To The Moon

The Amazing Life of Chun Wang: From OG Bitcoin Miner to Astronaut

Chun Wang (far right) inside the Crew Dragon capsule with the Fram2 crew, strapped in for launch. (Credit: SpaceX via Space.com)

The next frontier was space. Wang had pitched a private polar-orbit mission to SpaceX since 2023. He funded the entire Fram2 flight himself by selling Bitcoin. No sponsors or government backing. The team trained for eight months in California simulators, doing high-G spins, zero-G flights, emergency drills, and polar survival prep.

Launch came on April 1, 2025, from Kennedy Space Center. Wang commanded from the commander’s seat. “The ride to orbit was much smoother than I had anticipated. Apart from the final minute before SECO, I barely felt any G-forces—it honestly felt like just another flight,” he posted. Zero-g was only noticed when he loosened a small stuffed polar bear by accident, and it started floating. Day one brought space motion sickness for the entire crew. “It felt different from motion sickness in a car or at sea. You could still read on your iPad without making it worse. But even a small sip of water could upset your stomach.”

The ride to orbit was much smoother than I had anticipated. Apart from the final minute before SECO, I barely felt any G-forces—it honestly felt like just another flight.

I had imagined it would feel like being in an elevator that suddenly drops, but that sensation never came.… pic.twitter.com/h7YMyPY9ld

— Chun (@satofishi) April 2, 2025

By day two, the nausea passed. “I felt completely refreshed. The trace of motion sickness is all gone.” They opened the cupola over Antarctica. “Hello, Antarctica. From four hundred sixty kilometers up, it’s only pure white—no human activity visible.” The crew ran 22 experiments in three-and-a-half days: the first human X-ray in space, including hand scans with a ring, mirroring Roentgen’s 1895 original X-ray, oyster mushroom growth for Mars food code “Mission MushVroom”, female hormone tracking with urine strips, radiation monitoring, blood-flow restriction, mobile MRI, sleep tracking, and more. Radiation data showed the South Atlantic Anomaly, not the poles, delivered the highest radiation dose. The Polar orbit actually reduced time in that zone compared with ISS paths, which was noted by the highlight discovery of the trip.

The Amazing Life of Chun Wang: From OG Bitcoin Miner to Astronaut

View of Antarctica from the Fram2 cupola. (Credit: Fram2 crew via Space.com)

Splashdown occurred on April 4 off California. Wang shared radiation graphs in March 2026, confirming lower-than-expected polar exposure. Full scientific papers on the experiments have not yet been published.

Since then, Wang has hardly stayed still, with his astronaut wings from SpaceX, and NASA Johnson checkups behind him, he went straight back to travel. In March 2026, he reached Bouvet Island—his 150th territory out of 249 on his travel list — via ship and helicopter, spending 201 hours on the ice before heading to Cape Town. He continues logging flights and updating his X account with photos, charts, and occasional Bitcoin and Crypto tech thoughts.

The Amazing Life of Chun Wang: From OG Bitcoin Miner to Astronaut

Helicopter departure from Bouvet Island, March 2026—Chun Wang’s 150th territory. (Credit: Chun Wang via X/@satofishi)

This post The Amazing Life of Chun Wang: From OG Bitcoin Miner to Astronaut first appeared on Bitcoin Magazine and is written by Juan Galt.

Boltz Exchange Launches Atomic USDT Swaps for Lightning Network Users

18 March 2026 at 18:02

Bitcoin Magazine

Boltz Exchange Launches Atomic USDT Swaps for Lightning Network Users

Boltz Exchange launched USDT Swaps on March 18, 2026, introducing atomic, non-custodial swaps between sats on the Lightning Network and USDT on Arbitrum-based networks via USDT0.

The integration relies on USDT0, an omnichain version of Tether built on LayerZero’s Omnichain Fungible Token (OFT) standard. USDT0 concentrates liquidity into a single token primarily on Arbitrum, eliminating the need for Boltz to build separate liquidity pools and integrations across dozens of USDT chains like Ethereum, Polygon, Optimism, Rootstock, and others. This approach delivers seamless swaps to and from USDT to Bitcoiners that do not care to understand the complexities of blockchain bridge networks. While giving DEFI a direct path to lightning payments, without counterparty risk. 

Users also gain practical access to the world’s leading stablecoin, while sidestepping custody risks from centralized exchanges or anonymous “trust me bro” swap services, as well as the privacy trade-offs of KYC-heavy platforms. Business applications include topping up crypto debit cards that natively support USDT by converting Lightning sats in seconds, receiving Lightning payments when clients or counterparties send USDT, or merchants accepting USDT inflows but settling revenue in Lightning sats on their preferred terms—all without relinquishing control of funds or trusting third parties at any point. Its all open source.

Boltz Exchange Launches Atomic USDT Swaps for Lightning Network Users

Atomic swaps ensure trustless, simultaneous execution of trades across different blockchains or layers, preventing one party from defaulting after receiving assets. In traditional swaps, especially cross-chain, users face timing risks where one side could claim funds without delivering the other. Atomic swaps resolve this through cryptographic commitments (like hash preimages) and conditional claims: both legs of the trade either complete together or fail entirely, reverting funds to their original owners. Boltz achieves this for Lightning and USDT by routing through tBTC, Threshold’s permissionless ERC20 Bitcoin wrapper on Arbitrum. The flow is Lightning to tBTC via an atomic Boltz swap, then to USDT0 via a DEX swap akin to those on Uniswap, stitched into one irreversible transaction by the Router contract on Arbitrum. Gas abstraction removes the need for ETH on Arbitrum, making the process seamless for Bitcoin-native users.

Boltz plans to expand USDT Swaps across all currently supported Bitcoin layers, including on-chain BTC, Liquid, Rootstock, and Arkade, broadening the utility for businesses and individuals holding Bitcoin in various forms. Future updates will also incorporate USDT0’s Legacy Mesh, which is expected to enable direct support for additional chains such as Tron and Solana. Tron currently holds the largest USDT supply at approximately $83.9 billion according to Tether’s March 17, 2026 transparency report, underscoring the demand for eventual integration on high-volume networks beyond the initial OFT-focused deployment.

This post Boltz Exchange Launches Atomic USDT Swaps for Lightning Network Users first appeared on Bitcoin Magazine and is written by Juan Galt.

❌