Register and share your invite link to earn from video plays and referrals.

Rob Hamilton 🟥
@Rob1Ham
CEO @AnchorWatch, Bitcoin Custody & Insurance You can't stop Math, molon labe.
2.2K Following    25.7K Followers
Incredibly grateful for @ColeMacro and the entire @Strive team for supporting the @OpenSats Red Team fund. Supporting the security of the Bitcoin protocol and its applications is a way to invest in its success, and insures a safer monetary network. 🫡🟥
Show more
It looks like ~4,000 BTC just moved from the Liquid Network bridge all at once with an OP Return saying, "we are whitehats. contact us on chain". TXID: c103de95817b43f2df635ec6f35ff126ca26a7c6d20570c4b01866b2b3e69a19
Show more
0
145
1.5K
238
Forward to community
Pleased to announce I've joined @VibeCapitalMgmt reporting to their Chief Risk Officer @Fundamentals21m as Head of Giggling. TYFYATTM
On Friday Anthropic came out with their Claude Code plugin which will do a sweep of codebases. I did some scans across different codebases both internal and of FOSS libraries and wanted to share my thoughts. The pros: 1. If you have not done any codebase scans up to this point, this is the most straight forward experience I've found up to this point. 2. It does find issues! There was 1 or 2 things that were not picked up from other scans that I've done up to this point. 3. It does a very thorough job to screen out false positives. 4. You are able to pick different levels of effort that were clearly explained (picture below) The Cons: 1. It is comically expensive, I ran a max scan that was ~$1,000, easily would have been a third to run this scan with open models. This was in line with the estimates I asked the plugin to provide prior to kicking off the analysis, so if you're curious yourself, just ask for a cost estimate before starting the scan at the level of effort you're interested in. 2. While the precision (true positive) rate was high, the recall (identifying of total confirmed issues) was quite low. The plugin is definitely steered to only showing confirmed true positives, but in a security landscape I'd rather see the larger universe of possible issues than be blinded from seeing the reality. 3. Even as a member of the Trusted Cyber Access program in Anthropic - I WAS STILL DOWNGRADED FOR CYBER CONCERNS USING THEIR PLUGIN SPECIFICALLY MADE FOR CYBER SCANS! 72% of tokens were used by Opus 4.8 after getting numerous downgrades. Opus 4.8 came out in May, using FOSS models that came out in the past month is clearly a better ROI when you consider they are cheaper and better performing. This last one gives me pause, since Anthropic has now granted the ability for enterprises to enable Mythos for scans. As much as I'd love the chance to pony up for the scan, do I have to use their harness for the mythos scans? The model is for sure a critical part of analysis, but the harness I'm finding can be just as important for being able to focus the model to find critical issues. If it is an on rails tool just like this plugin, I'm skeptical that it'd be worth it. Between this plugin and OpenAI's Codex Security SDK, I'd go for OpenAI's. It is also a lengthy and costly scanner you can't control, but the level of insights I got between the two repos was a meaningful difference. For multiple large codebases, I've had the Codex Security Harness fail on occasion and never finish, but its findings were thorough and more additive to my findings when compared to Anthropic's plugin.
Show more
Something we never formally announced, but have worked on for years: Strata. It's the best solution to scaling Bitcoin (imo). -- Everyone has an opinion on scaling: soft forks, payments, big blocks, EVM, Simplicity, DeFi, privacy, do nothing, etc. The movement has outgrown a single answer. Fortunately, Strata can satisfy almost everyone at once. At its core, Strata is a shared bridge. A public good anyone can tap into. No change to Bitcoin required (though one wouldn't hurt). No EVM requirement. No new token. How it works, simply: Any scaling solution (we call them domains) can open a "ZK account" on Strata holding a BTC balance. Periodically it submits a ZK proof: "My scaling solution changed a bunch of user balances, here's unforgeable math showing I'm not lying." Strata verifies, updates the balance. Users on any domain can bridge in and out as they please. That's the whole requirement. Produce a valid ZK proof. Fortunately, ZK proofs are absurdly flexible, you can prove any computation. A privacy protocol, big blocks, micropayments, Simplicity, Ark. Literally whatever you want. We use it ourselves at @AlpenLabs: users do EVM stuff on our rollup Alpen → we generate a ZKP → updates our balance on Strata → settles to Bitcoin via Glock ("BitVM3 / Garbled Circuits"). Anyone else can do the same without ever touching Alpen. Full agency per domain: design your own VM, your own throughput trade-offs, your own sequencing. The best part is design choices from one team don't leak into anyone else's. So, if you hate the EVM, that's fine, don't use it. Build or use whatever you prefer, use the bridge as a public good. If different domains want to inter-op or share resources they can. But they don't have to! It's a really elegant design. -- For the technical crowd: Strata is a rollup on Bitcoin, so there is a Sequencer and DA element. The DA is very minimal because the big DA costs are decided by the individual domains. One domain can settle DA to Bitcoin, another could use a federation. The only DA Strata requires is posting the balances for each ZK Account (quite small), not the full state for each domain. Honest gotchas, for now: Strata's sequencer is a single entity today (decentralizing it is on the roadmap, nothing in the design prevents it). The bridge carries Glock's 1-of-N trust assumption: one honest participant prevents theft Not perfect. But strictly less trust than every wrapped BTC in existence. -- We have a high level visual here: Or you can check out the video explainer in the quote tweet.
Show more
Uh guys, why is my @OpenAI Chat GPT Daybreak Blue speaking mandarin to me?
For a cybersecurity nerd the race to secure Bitcoin from AI fueled cyberattacks feels like Christmas came early and the folks doing the heavy lifting are straight up superheroes. Thank you to @callebtc for speaking with me and special shoutout to @Rob1Ham and the rest of the Bitcoin Red Team.
Show more
Okay let me tell you about what's happening with DeepSeek v4 Flash. First some background, it launched on Aug 1st and within 2 weeks it went from doing 3T tokens a day to 18T tokens a day on OpenCode; an absurd 6x increase. To put it in context, that's close to doubling up all of OpenRouter's daily volume. It's also likely 30-50% of DeepSeek's total volume. Jumps like these over a 2-week span are not normal. This happened because the model is absurdly cheap; 350x cheaper than Fable, 175x cheaper than 5.6 Sol, 70x cheaper than Sonnet, and 7x cheaper than Luna. And secondly, it was a marked improvement over the previous Flash model. For the first time our users got a feel for AI that's "too cheap to meter". Then on August 16th DeepSeek raised prices by 5x (for peak hours, 2.5x off-peak hours). And it completely killed the growth of the model. It's doing less than half the tokens per day from its peak. Obviously people were unhappy with the sudden change. Our guess is that DeepSeek genuinely could not handle the absurd 6x jump. Also, it's likely that the increase in GPU prices meant that even if they acquired new capacity, they wouldn't be able to serve it at the original prices. A quick aside on why DeepSeek Flash is so cheap. It looks like they are running some custom infrastructure to cache way more tokens, for far longer. This matters because we've been scrambling trying to find providers that can fill this near 10T token per day void left by DeepSeek Flash. Unfortunately there are just a couple of people who are able to match DeepSeek's original pricing and that's likely only the case because they are using newer hardware. That brings us to the current state of things. Over the last week we've talked to as many people as possible to get DeepSeek hosted at the original price. The issue is that even if somebody is able to, it's very hard for them to have enough capacity to handle our volume. It'll take roughly 1000 B300s to handle our throughput. This is why if you've been using DeepSeek Flash on Go over the past few days, you might not have had the best experience. We've unfortunately cycled through a few different providers. This 10T token per day gap, though, is an opportunity for every other model lab. It's very clear there's an appetite for a model that's at least as competent and cheap as DeepSeek Flash. And somehow that still feels like the floor.
Show more
0
130
3.5K
183
Forward to community
Security researchers watching AI-native hunters find criticals without spending 14 hours manually reading the code
Dear users, we have made the hard decision to take all atomiq swap routes offline for now. As a small team we are currently not able to fight against the numerous sophisticated AI-assisted attacks on our infrastructure. Rest assured that user funds were not at risk due to the trustless nature of the swap protocol, and the webapp remains accessible, so you can always refund your past swaps. In case of any doubts/questions, feel free to reach out via our support at A big thank you to all our loyal users, we we'll try come back stronger.
Show more
Three weeks until the Open Source AI Summit! @Rob1Ham from @AnchorWatch, @moneyball & @_tnull from @ProjectLoupe and @spiral_xyz, and @jordanmecom from @blocks are joining us for a panel on securing open source software in an AI future. Apply to attend, or catch the recording after!
Show more
The bounty has been increased to over $7m today.
Hash-based signatures on hardware wallets are feasible: @blksresearch benchmarks show that SHRINCS & SLH-DSA take less than 2 minutes. Future wallets could be optimized & faster. Code is open-source. Thanks to @BlockstreamJade @Ledger @satoshilabs @BitBoxSwiss for the help!
Show more
people who think that core is some sort of intransparent institution operating in the shadows are either too lazy or too dumb to go have a look for themselves. literally everything they do is public, anyone can chime in, and the result of their work is pure open source code. just because core people do free and open source work doesn’t mean they have to listen to you. if you think that’s arrogant, think about the number of karens with strong opinions in the world. nobody needs this shit. either you do the work and contribute constructively, or you gtfo. the fact that you might be angry doesn’t matter to anyone here. nobody cares. this is the internet. bitcoin is not a democracy. core devs are not your politicians. nobody owes you anything. not even an explanation. then there are those who are just pure sociopaths. when someone they hallucinate to represent “core” – which in their mind are the “cool kids” – doesn’t agree with them, they crash out publicly. it’s the grown-up version of “they don’t want to play with me”. they paint themselves as lone rangers when in reality they simply can’t find anyone who would work with them voluntarily. many such cases in this space too.
Show more
When you thought your codebase was free of vulnerabilities:
We are all Red Team🟥
Excited to announce the launch of Cyberscan - Prem's proprietary security agent for vulnerability detection built in partnership with @ArkLabsHQ and the @Breez_Tech Powered exclusively by open-source models like Kimi-K3, Qwen-3.8-Max and more, Cyberscan has helped over 20 teams find mission critical vulnerabilities in their codebases, preventing massive liabilities. Starting Today, Cyberscan is available for public access (link below) with $25 in free-credits for new users. Login with your github, connect a repo and it takes care of the rest - surfacing vulnerabilities that you definitely might have missed out.
Show more
I got my first commit merged into bitcoin core today! Last week I started poking scans into bitcoins codebase looking for straight forward wins. Thank you @L0RINC for doing the heavy lifting after my clankers sifted for bugs. Just the start!
Show more
I know I've been a vocal proponent before, but wanted to +1 this again. Vaults provide orders of magnittude more security. In bitcoin today, once you broadcast a transaction, its a race in the mempool on saving funds. With vaults, you can make it days/weeks of response time.
Show more
Buried the hatchet with @rot13maxi MPC Gang 🤝 Team Script