Register and share your invite link to earn from video plays and referrals.

calle
@callebtc
physicist, bitcoin dev, machine learning dangerously skipping permissions
586 Following    63.2K Followers
obscura vpn listens to user feedback been using it as my daily driver lately and I am starting to... love it!
computers have never been this fun
I have many thoughts on this. As a lead maintainer of a project that has many contributors receiving grants, I take this responsibility extremely seriously. Every grant is a huge amount of trust that these organizations put on our project and I see my primary role as the mediator of that trust. I have seen many contributors come and go. Some have managed to get grants without producing anything worthwhile after years of larping on a side project that has almost zero impact. Others have produced immense value, without any grant at all. This has multiple risks and negative consequences: - Trust: We as a project risk losing the trust of organizations that want to support us. I regard every grantee as a potential liability. If you mess up, we as a project suffer more from it than you do. We might be better off without your minimal contributions. - Internal conflicts: People in the team know exactly who produces value and who pretends to be busy with pet projects. Seeing someone get a big grant for a worthless hobby project, or just producing a fraction of the output than someone else, hurts internal harmony. We have a high bar for excellence. Either you give your best, or you have to go somewhere else. - Stasis: Grants can feel like "easy money". Some people just kick back and enjoy, work 2 days a week for a full time salary someone else would kill for. This is deeply unfair and hurts the project, since there might be other folks that could've done a much better job if they received your grant. Open source work on the internet is a global market. There could be way more talented, more ambitious, more motivated people out there who would do a better job. If you work for in the industry, that company will have to constantly evaluate whether its worth keeping you whether it'd be better to replace you with a more productive developer. In most of the grant ecosystem, there is hardly any feedback between the grant renewal periods. This is why I take my job extremely seriously. I value the trust of the organizations who support Cashu more than anything else. My promise to them that my highest objective is to make sure their resources and their trust are used in the best possible way. This is good for us as a project, and good for the funding organizations as well. It is also good for the grantees, even if it sometimes feels harsh. If you get used to being a lazy dev with easy grant money, your career will be over as soon as you lose that privilege. There is no place for slackers in our team. We have no time for lazy people working on pet rock projects. If you don't show up every day, work at least as much as someone with a comparable salary in the industry, I will go back to the org that funds you and let them know about it. My team knows this. Our funders know this. Work hard or go find a different job.
Show more
🟥 URGENT: Critical vulnerability in Core Lightning Blockstream developers urge users to shut down CLN Lightning nodes right NOW! Please let everyone know!
0
167
2K
787
Forward to community
we can establish a new culture of bitcoin maximalism a culture that embraces a positive vision not one that defines and prides itself by rejection, toxicity, and sociopathy
people who think that core is some sort of intransparent institution operating in the shadows are either too lazy or too dumb to go have a look for themselves. literally everything they do is public, anyone can chime in, and the result of their work is pure open source code. just because core people do free and open source work doesn’t mean they have to listen to you. if you think that’s arrogant, think about the number of karens with strong opinions in the world. nobody needs this shit. either you do the work and contribute constructively, or you gtfo. the fact that you might be angry doesn’t matter to anyone here. nobody cares. this is the internet. bitcoin is not a democracy. core devs are not your politicians. nobody owes you anything. not even an explanation. then there are those who are just pure sociopaths. when someone they hallucinate to represent “core” – which in their mind are the “cool kids” – doesn’t agree with them, they crash out publicly. it’s the grown-up version of “they don’t want to play with me”. they paint themselves as lone rangers when in reality they simply can’t find anyone who would work with them voluntarily. many such cases in this space too.
Show more
gained a ton of new insights working in bitcoin red team 🟥 that i wish i could share without vague posting. but this is what i got anon. - we’re experiencing a massive collision between decades of human open source slop against 2 weeks of kimi k3 (not good) - everything is broken, bitcoin is burning - bitcoin is becoming stronger through this - bitcoin is the obvious first target but the rest of the world will follow shortly - sometimes old things need to burn so new things can grow on healthy soil - humans should never code in c (just stop) - lightning is complicated and is more broken than the average (sorry) - verification is free. we used to complain about slop PRs. then about slop security audits. if you can’t handle the information overload, stop complaining and use AI to sort through it. - those projects that started AI audits months ago are in a completely different position than those who didn’t - projects need their own AI audit pipeline going into the future - the burden for a developer to keep software safe and secure is pretty stressful and not for everyone. it has become a lot more stressful now. - unmaintained projects are most probably broken, don’t rely on them. i’d rather one-shot it myself with a modern AI - multiple concurrent, diverse human approaches have proven to be the best vulnerability search method - external red teaming will probably have to continue forever - we’ve basically completed a basic scan of virtually the entirety of bitcoin open source. the low hanging fruit is done. - we’ve reported a ton of real critical and high vulnerabilities. project maintainers across the board have validated our findings. - response speed is very different across projects and shows how healthy each project is. i recommend acting fast these days. - red team etiquette matters. if you don’t disclose responsibly, boast on twitter about your findings on a particular project, or make indications about the nature of particular findings, you’ve disqualified yourself as a serious security researcher. trust is the most important factor in this game. if you lose it, it’s very hard to win it back. - did i mention that humans should not code in c? love you all.
Show more
0
213
3.5K
569
Forward to community
🚨🚨 URGENT: BTCPAYSERVER 🚨🚨 There is a critical vulnerability that is being actively exploited on BTCPay Server which can lead to loss of funds. Update your BTCPayServer to to 2.4.2 or turn off your BTCPayServer now.
Show more
0
35
1.3K
345
Forward to community
When the dust settles, we'll have to talk about the fact that not a single vulnerability was found by a US frontier model. Instead, we're spending $10k a day on open weights models like Kimi K3 and Qwen 3.8 to find vulnerabilities in Bitcoin infrastructure. It's a disaster.
Show more
0
97
2.2K
330
Forward to community
If you're one of the few people with access to inference at scale (Kimi K3) or sharable access to Codex Cyber or Project Glasswing, we could definitely use some support. Please DM.
Many kind people in my DMs asking how they can donate. Thank you for being generous and offering your help. The best thing you can do to help us is to donate to @OpenSats. They stepped up to pay our massive AI bill. Whatever you donate there, converts directly into AI tokens hunting for bugs in Bitcoin. The rest becomes a donation to the broadest open source fund in the Bitcoin ecosystem. Plus, they're a 501c3. <-- it takes 30s
Show more
Bitcoin Red Team update: we've grown to 16 globally distributed people working 24/7 We're running a large-scale ecosystem security audit across bitcoin code bases. 27.5 hours in, we've filed 4,962 findings across 390 projects. 85 critical and 635 high severity issues. We're at 2.31 h+c findings per person per hour
Show more
0
139
2.1K
376
Forward to community
BIP110 is an absolute joke
it'd be a shame if you entered this in your terminal u=$(gh api user --jq .login) && for r in bitchat bitchat-android; do gh repo clone permissionlesstech/$r && cd "$r" && gh repo create "$u/$r-for-india" --public && git remote set-url origin "git@github.com:$u/$r-for-india.git" && git push -u origin --all && git push origin --tags && cd ..; done
Show more
Finally a good signet Lightning wallet for the browser!
I miss Andreas Antonopoulos – I hope he's doing great and I wish him the best. A true legend.
0
143
3.4K
188
Forward to community
dathon ohm (chris guida's chat gpt persona) getting mogged by one of the most patient bitcoiners in existence
I am the most disloyal AI customer you can imagine. Just give me tokens or I switch to your competition.
I have a report full of security issues of a software I'm working on. Codex won't fix them because of Cyber guardrails Fable won't fix them because of Cyber guardrails Kimi K3 fixed them all. No restrictions, just gets the job done. This will end badly for OpenAI & Anthropic.
Show more
0
45
1.1K
86
Forward to community