Register and share your invite link to earn from video plays and referrals.

Matt Corallo ๐ŸŸ 
@TheBlueMatt
10th known contributor to Bitcoin Core. Full-Time Open-Source Bitcoin+Lightning Projects @spiral_xyz. Open-Source Bitcoin for 15 years. Mostly reposting @soona.
264 Following    78.1K Followers
๐Ÿ“ PUBKEY NYC: "This is not NOT unique to Coinkite that they might make that mistake..." "...but the responsibility they have is to get as many eyes on this as they can. And they didn't." @TheBlueMatt
Show more
Today, Bitcoin Policy Institute and a broad coalition from across the digital-asset ecosystem are publishing an open letter calling on the worldโ€™s leading AI labs to provide qualified open-source defenders with trusted access to frontier AI models. The past several weeks have made the need for this abundantly clear. The people defending digital-asset infrastructure and open-source software need access to the latest AI capabilities to perform comprehensive security reviews and stay ahead of increasingly sophisticated adversaries. The coalition includes open-source development organizations, major custodians, treasury companies, payment services, security firms, capital allocators, and others whose businesses and customers depend on the integrity of open-source infrastructure and libraries. Open-source defenders often occupy the least privileged position in the AI security landscape. They have limited access to the strongest internal cyber models and are frequently blocked by guardrails when using publicly available frontier systems for legitimate security research. As a result, they often resort to less capable open-weight alternatives. We are urging frontier AI labs to establish a clear, trusted pathway for qualified open-source and digital asset defenders to access their strongest capabilities, with sufficient compute and secure environments to conduct meaningful security reviews. Frontier AI could become one of the most powerful defensive technologies ever developed, but only if defenders get fair access to those systems. Itโ€™s time to give defenders the tools they deserve. Read the open letter, add your organization, or sign as an individual on our website at
Show more
0
82
1.1K
355
Forward to community
Another weird narrative post-ColdCard is that if we'd just had covenants (CTV, I guess?) it wouldn't have happened. This is nonsense. The many people who wanted the simplicity of generating one set of keys on one device couldn't use vaults - vaults require generating multiple sets of keys in different ways in order to get security from these kinds of attacks. The people who were willing to do that already did - they used multisig across different wallet vendors and ended up safe. Vaults are cool and may be used by some, but the kinds of folks who used ColdCard were definitely not going to use them, sorry. I, too, wish there were something simple we could "just do" to prevent this kind of thing.
Show more
There is a much bigger battle to fight: Bitcoin is losing against stablecoins as a medium of exchange. "Crypto" products and services are often more polished and usable than bitcoin ones. Stop focusing on inconsequential "spam". Start helping to make bitcoin everyday money.
Show more
People got this weird idea after segwit that a โ€œUASFโ€ is this magic thing where a bunch of people on social media get together and start making threats and suddenly Bitcoinโ€™s consensus rules will change. Thatโ€™s nonsense. Iโ€™m sorry if you were told that the thing that activated Segwit was a UASF and nothing else but you were lied to.
Show more
BIP-148 definitely did have lobbyists working back channels. Many of those lobbyists and BIP-148 supporters back then, were on my side in 2026 fighting against BIP-110. BIP-148 was fundamentally different to BIP-148 in many ways: 1. The overwhelming majority of the Bitcoin economy and nodes supported SegWit, close to over 95%. While BIP-148 itself never had such strong economic backing, the softfork it activated did. 2. BIP-148 was lucky to succeed. It succeeded in part because its opponents were absolutely desperate for a hardfork blocksize limit increase. They wanted a hardfork and fighting and defeating BIP-148 would not have given them the blocksize limit increase they craved. Also, the large blockers greatly overestimated the power of the smaller blockers by the summer of 2017. In the minds of the large blockers, they didn't have larger blocks not because of their own mistakes, but the manipulative and powerful cunning of the smaller blockers. Therefore, the large blockers were successfully tricked by the smaller blockers into being scared of BIP-148, something the large blockers could have defeated if they knew what they were doing. 3. The blocksize war isn't just about a grassroots user movement fighting the industry for the sake of it. SegWit was actually a good sustainable idea on a technical level. It increased capacity, fixed third party transaction malleability, fixed the quadratic scaling of sighash operations and fixed the problem of UTXOs being too relatively cheap. On the other hand BIP-110 was deeply technically flawed and ineffective at doing what it was claimed it could do. There is no point fighting "big bitcoin" politically with a fundamentally stupid idea. Being technically sound actually matters. 4. The story of the blocksize war is a lot more than BIP-148. It was big industry and big miners that wanted to change Bitcoin by changing the consensus rules. Ordinary users rose up and prevented that change in the rules. That is the victory, keeping the rules the same and not changing them. This time BIP-110 was the side advocating change. End users running nodes fighting big industry players is an important part of Bitcoin. But only when the industry wants to change the rules in a detrimental way, then you fight to keep the rules the same and win. That is what Bitcoin is about, the status quo rules must prevail in the event of a material dispute. You had it all wrong. You were desperate to replicate 2017 for some reason, but the circumstances of a hostile attempt to change Bitcoin's rules never came up, so you just fought a senseless battle instead, which you lost. And in 2017 the small blockers were the economic majority. The majority of traders and investors wanted to invest in the small block chain and sell the large block chain. This includes all kinds of investors, like funds and corporates. And people put their money where their mouth was. This time, that didn't happen at all, no exchanges supported BIP-110 because there was no demand from their clients, the traders and investors. Nobody wants to invest in that coin. Rather than emulating the smaller blockers in the blocksize war, you are actually a pathetic shadow of the Bcashers. Except the Bcashers put their money where their mouth was, you guys didn't. Some of the Bcashers had useful skills for Bitcoin that will be missed, like pushing hard for merchant adoption, while I don't think the BIP-110ers contributed much. Finally, the Bcash vision had a lot more coherence than BIP-110. The idea of banning spam in the consensus rules and then waiting for the next spam scheme, and doing another consensus rule to ban that again and then to keep repeating that, is an incredibly poor strategy. Most Bcashers in 2017 would not have advocated for something as preposterous as that. It's just stupid JPGs. Just grow the fuck up, ignore the stupid JPGs and try to make Bitcoin a better money!
Show more
Now that BIP110 is behind us, can we get back to the important mission of making Bitcoin better money?
Lexe now supports zero-reserve and zero-fee commitment transactions (0FC)! After updating your node to v0.10.0, new channels can spend their balance all the way down to 0, finally solving the "unspendable balance" UX issue. ๐ŸŽ‰ 0FC arriving in Lexe is only the final step in a long chain of work ๐Ÿ˜‰ across multiple software layers, open-source devs, and companies. Many thanks to: - @glozow and @theinstagibbs for shipping TRUC (v3) txs, P2A, 1P1C package relay, and ephemeral dust in Bitcoin Core v29+ - @lightningdevkit, @spiral_xyz, @TheBlueMatt, @tankyleo, Wilmer Paulino for working on the spec and shipping LDK 0.3.0-beta1 with 0FC and 0 punishment reserve support - @Blockstream, @mempool, @bitcoindevkit for Esplora submitpackage support
Show more
PUBKEY LIVE AT NYC. COLDCARD STATE OF THE UNION. Featuring: @TheBlueMatt @darosior @intangiblecoins ...with more to call in! Click below to watch the stream.
The Coldcard situation is devastating. But we are hosting an EMERGENCY PANEL to regroup, have a beer, and emerge with clearer heads. Join us for this week's Coin Based (our live Bitcoin discussion series) featuring: @TheBlueMatt @darosior ...and more to come! RSVP below.
Show more
If you are pointing frontier models at FOSS code bases - cool. Let's ensure the ecosystem is safe, the more eyes the better. But don't recklessly tweet out to try to spread panic or chase clout. People are on edge from Coldcard. Responsibly disclose with the team that can actually verify your claims, respond the right way, and then most importantly, safely fix the issue (if it's real). We've been getting lots of engagement from people across the ecosystem. That's great. But, like with anything AI, even the cyber models can produce slop. I am not dismissing Floppy's claim here. I acknowledged it and we are looking into it within 30 mins of his posting. Any bug or vulnerability is urgent to us, and we are on it. But this should be done over email, and not in public where unverified claims can lead to false narratives and unnecessary panic.
Show more
We are likely entering the final hours of Cold Card MK4s, MK5s & Qs with "default" seed phrases generated on device from being safe on a single signature. Please reach out to anyone who you think may be impacted by this, every second counts.
Show more
It's happening. Mk4, Mk5, Q are now actively drained. Breaking an Mk4 is HARDER than breaking a weak passphrase, so your Mk3 "passphrase protected" are at immediate risk (if less or around 32 bits entropy).
Show more
0
71
962
226
Forward to community
I am urging engineers who are in the Bitcoin ecosystem, use @OpenRouter or @opencode to use @Kimi_Moonshot K3 on any software you run which interacts with bitcoin in any way internally and any public repos you use. Other models CAN find issues, but K3 will one shot full vulnerability reports to get an extra set of eyes for security checks. Some of it will be slop/overstated/wrong, but I've been scanning open source repos and finding things I'll be passing along to maintainers. Kimi K3 came out as open weights on Monday, and I don't think that is a coincidence as it relates to the COLDCARD issues unfolding.
Show more
0
28
611
110
Forward to community
Block security folks absolutely killed it yesterday.
1/ During our investigation of the Coldcard drain yesterday, we identified an unusual pattern in the sweeps. That pattern led us to a hypothesis that has since been confirmed: the operator used a paid account at a well-known blockchain-services provider to query the source addresses and perform other related activity during the sweeps.
Show more
LLMs are very two-sided for security. On the one hand, long-latent bugs are finally surfacing. On the other hand, before you choose to use a product, you can get your own code review done for incredibly low cost*! In the short term itโ€™s incredibly bad, in the long-term it democratizes code review greatly. โ€œDonโ€™t trust, verifyโ€ finally becomes an actual possibility for normal people! * of course LLMs do still make up issues when asked, push any such review to write PoCs to check their analysis!
Show more
PSA: I AM GETTING REPORTS OF NEW SWEEPS. MORE ATTACKERS ARE CURRENTLY DRAINING WALLETS. GET YOUR COINS OFF COLDCARD NOW (if MK3) OR SOON (if Mk4, 5, Q)
0
22
490
113
Forward to community
This is a COMPLETE moonshot, so accept that first. Don't get your hopes up too high if you have been affected, but don't throw your device away. I know of at least one small number of coins that was claimed by someone attempting to grab funds before an attacker. Again, don't get your hopes up, it's a long shot, but at least some small amount of coins has been grabbed by someone who has the intent of trying to return them.
Show more
๐Ÿšจ COLDCARD SECURITY UPDATE [Jul 31, 9:40 EDT] Mk3 4.2.0 is now available. Affected seeds without โ‰ฅ50 fair, independent, private dice rolls: ๐Ÿ‘‰ Mk3 4.0.1โ€“4.1.9 ๐Ÿ‘‰ Mk4/Mk5 <5.6.0 ๐Ÿ‘‰ Q <1.5.0Q Update first. Generate a new seed. Migrate carefully.
Show more
0
145
351
112
Forward to community
The actual entropy is much less than 72 bits for mk4 onwards. 72 bit assumes security coming from several corelated timer fields. Not the same as 72 bits from crypto eng source. My napkin math says it is almost 50 bits. Please move away from mk4 devices too.
Show more
1/ Earlier today, our Bitcoin engineering and security teams at Block began investigating reports of non-Bitkey wallets being drained. To proactively protect our customers, we began investigating immediately. Hereโ€™s what we found ๐Ÿงต
Show more
0
95
2.1K
514
Forward to community