Register and share your invite link to earn from video plays and referrals.

Kevin Loaec ๐Ÿง™โ€โ™‚๏ธ๐ŸŸ
@KLoaec
@wizardsardine CEO ๐Ÿช„๐ŸŸ. โฌ›๐ŸŸจ ex Breaking Bitcoin and BoB. @btcazores @revaultdev @lianabitcoin
803 Following    11.9K Followers
I have been very critical and sceptical of open source grants in the space for a long time. Pet projects with no users should not be funded, they distort the market and add tons of new "standards" with no use, no validation, no real world feedback. And I'm not even talking about the value of grants given with no risk and strings attached, to people who often don't have experience nor track record. I'm with Nick on this one. Grants should be for things that are USED, infrastructure, libraries, etc, with ACTUAL EXISTING VALUE. Sorry for everyone who feels hurt, I'm not responsible for your feelings.
Show more
Something I've been contemplating regarding open source funding is that it is substantially harder to secure open source funding if you intend to build a profitable business atop the FOSS you're producing. We did not pursue some grants ourselves because we'd been told that commercial companies are unsuitable recipients. I respect this stance and I think the instinct behind it is well-meaning, but in my opinion it produces outcomes opposite to what open source donors desire. This reasoning seems to come from various angles. One is charitable instinct: funding should go to those who otherwise wouldn't receive it. The other is distributive: why fund work that someone else intends to monetise. Both are intuitive. But I'd argue that this creates market distortions that are suboptimal for the ecosystem we want to foster. FOSS projects with commercial incentive are subject to falsifiable product exploration -- continuous, unforgiving feedback from users. Skin in the game. This selection pressure produces better software and products optimising for grant approval. Bounty style funding results in even more perverse outcomes: a prize for acheiving X often results in the minimal viable X without any regard for usability, adoption or longevity. They win the prize and move on. The current funding environment favours more hobbyist-style maintainers and well-capitalised ventures and squeezes out the middle: small commercial teams shipping FOSS, who I think may be the healthiest part of the open source ecosystem. In Bitcoin hardware, at the extremes, "company" and "business" are even used as pejoratives, as though commercial intent is antithetical to open source values! They would argue this suspicion is founded through historical events in the industry. Perhaps, but I think is unreasonable to apply broadly. In terms of our own work: we've delivered a substantial body of FOSS code (used by others), specification contributions, research, and industry vision, and in my (biased) opinion, the best hardware wallet in Bitcoin's existence. I can say with certainty that this output would have been faster, larger, and more impactful with funding (earlier, wen FROST?) in this middle ground between entirely donor funded FOSS and fully capitalised proprietary development. I realise this is somewhat off topic to your original post, but I think this ecosystem distortion is worth mentioning. Meritocracy works when the field is open to everyone advancing it -- including those building businesses on top of the FOSS they produce. Would be curious as to people's thoughts
Show more
I've wanted miniscript on @SeedSigner for years. @Rob1Ham opened a Git Issue three years ago. It sat there. So this week I built it. A SeedSigner fork with miniscript support, plus a SeedSigner x Liana bridge so the whole flow runs over QR. No cables, no USB, completely airgapped. Here's a timelocked inheritance wallet, created in @lianabitcoin, descriptor registered and PSBT signed on a SeedSigner. Bridge tool: signet-only, not audited. SeedSigner PR: tested, hardware-verified, up for review. Repos below.
Show more
Originally, Bitcoin's two timelock fields weren't designed for how we use them today. nLockTime and nSequence served a completely different purpose in 2009. That purpose was abandoned, the fields were left orphaned, then they were repurposed. This story explains every quirk of Bitcoin's timelock system as it works today. ๐Ÿงต๐Ÿ‘‡ 1/9
Show more
Dealing with security issue the wrong way is how you burn yourself forever. Morality/integrity is the only thing valuable.
AI and taste but for security - everybody can find bugs with AI now. What's important is how you handle them, which makes you a whitehat, a greyhat, a blackhat or an asshat
Fully tested @lianabitcoin + @getfloresta + @krux (and other "conceptual multivendor". Worked nicely: (1) built a test setup with @selfcustodykrux camera entropy wallet , seedpicker with my word bags and a liana hot wallet.
Show more
CEO & CO-FOUNDER OF WIZARDSARDINE KEVIN LOAEC TO SPEAK AT BITCOIN ASIA 2026 ๐Ÿ‡ญ๐Ÿ‡ฐ "#Bitcoin# managed to keep a hard focus on what's important: a system that works no matter what." ๐Ÿš€
Show more
PANEL ANNOUNCEMENT ๐Ÿ‡ญ๐Ÿ‡ฐ The Coldcard exploit sparked a major conversation around #Bitcoin# security. Now, itโ€™s time to unpack what happened, what comes next, and why Bitcoin emerges even stronger. โœŠ August 27 | Nakamoto Stage
Show more
I see people are confused why @lianabitcoin doesn't offer "normal multisig". They mean 2-of-3. The answer is simple, Miniscript is strictly better, for example you can use the "expanding multisig" template to do a: 2-of-2, that becomes a 2-of-3. Of course, adapt to your needs.
Show more
Best I could do from the island right now. I wish I was in the mainland for once!
I interviewed @KLoaec around 1 month ago in Lugano, while nothing was happening in the Bitcoin space... Itโ€™s a light talk, as my "Block with Mir" interviews usually are, but in hindsight we touched on so many important topics: self-custody, UX, inheritance, and Bitcoin culture. If you want to know more about @lianabitcoin, @Wizardsardine and the hero of the moment, check it out โฌ‡๏ธ
Show more
@Rob1Ham @BeccaAmilee @Excellion @BlockstreamJade thanks for that๐Ÿ‘@AnchorWatch and @lianabitcoin by @wizardsardine are power users of miniscript! and @achow101 & sipa, apoelstra and others for developing miniscript in 2019 or so.
Show more
๐Ÿค“ Our NEW deep dive of the Coldcard disaster is out! This one covers: - The ACTUAL entropy level - The collision risk - The multiple sources of "entropy", and how each was triggered It's extremely long, I couldn't review it all yet.
Show more
0
35
500
112
Forward to community
PUBLIC SERVICE ANNOUNCEMENT: A phishing email impersonating "support-liana" (we don't have such emails) is circulating. It seems to target people very broadly, even outside of Bitcoin. Be aware of phishing, do not enter mnemonics on the internet (nor on the real liana, for that matter).
Show more
Instead of shitting on NVK and co, please make sure your fellow bitcoiners are OK. Contact the ones are your local meetup, those you know are physically around you, etc. They may have lost EVERYTHING, and they need human support, from people who understand. They won't manage to get help from non-bitcoiners, who just see it as monopoly money, or "was being lucky, now unlucky". This situation is so fucking sad. Thousands have lost everything. You might save a life today.
Show more
We are just launching a tool for Liana users (and other wallets) to easily send their transactions through Slipstream (out of band, for Miniscript and Multisig wallets affected). This may still have some bugs/issues, please send feedback. This is running entirely on your browser, not on our servers.
Show more
Ass CEO hat: "You should all have used what we've been building for the past many years. @lianabitcoin . You would not have lost your bitcoin then, even with no dice rolls. Liana is free, open source, and quite easy to use. "
Show more
By NOT rolling dice, you did NOTHING WRONG. You never were expected to roll dice or add a passphrase. Human generated entropy, even of great quality like dice, is LOWER than device generated entropy. The problem is, the device you bought to do that job was not doing it. Same as if you bought casino dice but they only roll 6s. Not your fault. The quoted tweet below is explaining why. How to protect yourself in the future, against a BUG in a signing device? The solution is not dice, that code could have been buggy too. The solution is MULTI-VENDOR MULTISIG. Any type of bug or attack in one device, you are still protected. Entropy, Key derivation (from dice for example), Signing (nonce), Malicious cryptographic library (Key exfil), Supply chain attack (physical RNG not random, not a code issue), etc, etc.
Show more