Register and share your invite link to earn from video plays and referrals.

Matt Corallo ๐ŸŸ 
@TheBlueMatt
10th known contributor to Bitcoin Core. Full-Time Open-Source Bitcoin+Lightning Projects @spiral_xyz. Open-Source Bitcoin for 15 years. Mostly reposting @soona.
264 Following    78.1K Followers
๐Ÿ“ PUBKEY NYC: "This is not NOT unique to Coinkite that they might make that mistake..." "...but the responsibility they have is to get as many eyes on this as they can. And they didn't." @TheBlueMatt
Show more
Today, Bitcoin Policy Institute and a broad coalition from across the digital-asset ecosystem are publishing an open letter calling on the worldโ€™s leading AI labs to provide qualified open-source defenders with trusted access to frontier AI models. The past several weeks have made the need for this abundantly clear. The people defending digital-asset infrastructure and open-source software need access to the latest AI capabilities to perform comprehensive security reviews and stay ahead of increasingly sophisticated adversaries. The coalition includes open-source development organizations, major custodians, treasury companies, payment services, security firms, capital allocators, and others whose businesses and customers depend on the integrity of open-source infrastructure and libraries. Open-source defenders often occupy the least privileged position in the AI security landscape. They have limited access to the strongest internal cyber models and are frequently blocked by guardrails when using publicly available frontier systems for legitimate security research. As a result, they often resort to less capable open-weight alternatives. We are urging frontier AI labs to establish a clear, trusted pathway for qualified open-source and digital asset defenders to access their strongest capabilities, with sufficient compute and secure environments to conduct meaningful security reviews. Frontier AI could become one of the most powerful defensive technologies ever developed, but only if defenders get fair access to those systems. Itโ€™s time to give defenders the tools they deserve. Read the open letter, add your organization, or sign as an individual on our website at
Show more
0
87
1.3K
377
Forward to community
Another weird narrative post-ColdCard is that if we'd just had covenants (CTV, I guess?) it wouldn't have happened. This is nonsense. The many people who wanted the simplicity of generating one set of keys on one device couldn't use vaults - vaults require generating multiple sets of keys in different ways in order to get security from these kinds of attacks. The people who were willing to do that already did - they used multisig across different wallet vendors and ended up safe. Vaults are cool and may be used by some, but the kinds of folks who used ColdCard were definitely not going to use them, sorry. I, too, wish there were something simple we could "just do" to prevent this kind of thing.
Show more
There is a much bigger battle to fight: Bitcoin is losing against stablecoins as a medium of exchange. "Crypto" products and services are often more polished and usable than bitcoin ones. Stop focusing on inconsequential "spam". Start helping to make bitcoin everyday money.
Show more
People got this weird idea after segwit that a โ€œUASFโ€ is this magic thing where a bunch of people on social media get together and start making threats and suddenly Bitcoinโ€™s consensus rules will change. Thatโ€™s nonsense. Iโ€™m sorry if you were told that the thing that activated Segwit was a UASF and nothing else but you were lied to.
Show more
Now that BIP110 is behind us, can we get back to the important mission of making Bitcoin better money?
Lexe now supports zero-reserve and zero-fee commitment transactions (0FC)! After updating your node to v0.10.0, new channels can spend their balance all the way down to 0, finally solving the "unspendable balance" UX issue. ๐ŸŽ‰ 0FC arriving in Lexe is only the final step in a long chain of work ๐Ÿ˜‰ across multiple software layers, open-source devs, and companies. Many thanks to: - @glozow and @theinstagibbs for shipping TRUC (v3) txs, P2A, 1P1C package relay, and ephemeral dust in Bitcoin Core v29+ - @lightningdevkit, @spiral_xyz, @TheBlueMatt, @tankyleo, Wilmer Paulino for working on the spec and shipping LDK 0.3.0-beta1 with 0FC and 0 punishment reserve support - @Blockstream, @mempool, @bitcoindevkit for Esplora submitpackage support
Show more
PUBKEY LIVE AT NYC. COLDCARD STATE OF THE UNION. Featuring: @TheBlueMatt @darosior @intangiblecoins ...with more to call in! Click below to watch the stream.
The Coldcard situation is devastating. But we are hosting an EMERGENCY PANEL to regroup, have a beer, and emerge with clearer heads. Join us for this week's Coin Based (our live Bitcoin discussion series) featuring: @TheBlueMatt @darosior ...and more to come! RSVP below.
Show more
If you are pointing frontier models at FOSS code bases - cool. Let's ensure the ecosystem is safe, the more eyes the better. But don't recklessly tweet out to try to spread panic or chase clout. People are on edge from Coldcard. Responsibly disclose with the team that can actually verify your claims, respond the right way, and then most importantly, safely fix the issue (if it's real). We've been getting lots of engagement from people across the ecosystem. That's great. But, like with anything AI, even the cyber models can produce slop. I am not dismissing Floppy's claim here. I acknowledged it and we are looking into it within 30 mins of his posting. Any bug or vulnerability is urgent to us, and we are on it. But this should be done over email, and not in public where unverified claims can lead to false narratives and unnecessary panic.
Show more
We are likely entering the final hours of Cold Card MK4s, MK5s & Qs with "default" seed phrases generated on device from being safe on a single signature. Please reach out to anyone who you think may be impacted by this, every second counts.
Show more
It's happening. Mk4, Mk5, Q are now actively drained. Breaking an Mk4 is HARDER than breaking a weak passphrase, so your Mk3 "passphrase protected" are at immediate risk (if less or around 32 bits entropy).
Show more
0
71
962
226
Forward to community
I am urging engineers who are in the Bitcoin ecosystem, use @OpenRouter or @opencode to use @Kimi_Moonshot K3 on any software you run which interacts with bitcoin in any way internally and any public repos you use. Other models CAN find issues, but K3 will one shot full vulnerability reports to get an extra set of eyes for security checks. Some of it will be slop/overstated/wrong, but I've been scanning open source repos and finding things I'll be passing along to maintainers. Kimi K3 came out as open weights on Monday, and I don't think that is a coincidence as it relates to the COLDCARD issues unfolding.
Show more
0
28
611
110
Forward to community
Block security folks absolutely killed it yesterday.
1/ During our investigation of the Coldcard drain yesterday, we identified an unusual pattern in the sweeps. That pattern led us to a hypothesis that has since been confirmed: the operator used a paid account at a well-known blockchain-services provider to query the source addresses and perform other related activity during the sweeps.
Show more
LLMs are very two-sided for security. On the one hand, long-latent bugs are finally surfacing. On the other hand, before you choose to use a product, you can get your own code review done for incredibly low cost*! In the short term itโ€™s incredibly bad, in the long-term it democratizes code review greatly. โ€œDonโ€™t trust, verifyโ€ finally becomes an actual possibility for normal people! * of course LLMs do still make up issues when asked, push any such review to write PoCs to check their analysis!
Show more
PSA: I AM GETTING REPORTS OF NEW SWEEPS. MORE ATTACKERS ARE CURRENTLY DRAINING WALLETS. GET YOUR COINS OFF COLDCARD NOW (if MK3) OR SOON (if Mk4, 5, Q)
0
22
490
113
Forward to community
This is a COMPLETE moonshot, so accept that first. Don't get your hopes up too high if you have been affected, but don't throw your device away. I know of at least one small number of coins that was claimed by someone attempting to grab funds before an attacker. Again, don't get your hopes up, it's a long shot, but at least some small amount of coins has been grabbed by someone who has the intent of trying to return them.
Show more
๐Ÿšจ COLDCARD SECURITY UPDATE [Jul 31, 9:40 EDT] Mk3 4.2.0 is now available. Affected seeds without โ‰ฅ50 fair, independent, private dice rolls: ๐Ÿ‘‰ Mk3 4.0.1โ€“4.1.9 ๐Ÿ‘‰ Mk4/Mk5 <5.6.0 ๐Ÿ‘‰ Q <1.5.0Q Update first. Generate a new seed. Migrate carefully.
Show more
0
145
351
112
Forward to community
The actual entropy is much less than 72 bits for mk4 onwards. 72 bit assumes security coming from several corelated timer fields. Not the same as 72 bits from crypto eng source. My napkin math says it is almost 50 bits. Please move away from mk4 devices too.
Show more
1/ Earlier today, our Bitcoin engineering and security teams at Block began investigating reports of non-Bitkey wallets being drained. To proactively protect our customers, we began investigating immediately. Hereโ€™s what we found ๐Ÿงต
Show more
0
95
2.1K
514
Forward to community