Episode notes
AOB
- Max: flooded the downstairs after leaving a sink running over the weekend, spent Saturday ripping out old timber and clutter he'd been meaning to clear out anyway, then a full kids' day that left them sick afterwards
- Q: spent the weekend building his own local, voice-controlled AI assistant after watching the new Spider-Man film
- Q: read this week's letter #7 from Keone, "Notes from the Inside", posted on The Rage -- a tough one on conditions moving between facilities; audio version out later this week, timed with Rick's Free Samurai prize draw
- Q: enjoyed last week's Freedom Tech Friday listener questions episode, ranging from Bitcoin to Monero to privacy, multisig and local AI
NEWS
- Research lab [alloc] init, founded by Misha Komarov with Clara Shikhelman as Head of Protocol Research, published Shielded Bitcoin, a proposal for Zcash-style private transfers needing no soft fork; shielded transactions are encrypted data blobs carried in OP_RETURN or witness data that Bitcoin only orders and timestamps, while separate indexer software checks zero-knowledge proofs and stops double-spends; value sits in encrypted "notes" spent by publishing a one-time nullifier that proves the spend without revealing which note it is; the peg moving real BTC in and out isn't designed yet and rests on an unproven witness-encryption scheme called PIPEs v2; CoinDesk reports fees around 4x normal, a trusted setup and no launch date -- Bitcoin Magazine, CoinDesk, allocinit
- Blockstream published its own post-mortem of the 6 September Liquid exploit: a rangeproof-cache flaw dating to April 2018 ("Bug A"), responsibly disclosed 2 August and patched by 11 August, introduced a second flaw ("Bug B") where unprefixed cache keys let two different proofs collide; the attacker used it to mint about 4,000 unbacked LBTC and peg out 3,996 BTC through SideSwap, draining the reserve from about 4,205 BTC to 197 BTC; 3,400 BTC was returned and the network resumed 9-10 September, but about 602 BTC remains with the attacker and peg-outs stay paused with no date; the 11-of-15 federation multisig worked exactly as designed, the failure was in the software deciding what counted as a valid transaction -- Blockstream
- Bitget detected unauthorised transfers from its hot and warm wallets at 18:31 UTC on 24 September and froze withdrawals platform-wide; CEO Gracy Chen says the attacker compromised a backend system, spoofed transaction data and triggered Bitget's own approval process, with private key compromise ruled out; the loss was revised from $351.6M to about $387.5M once Zcash and TRON assets were counted, mostly ETH, TRX and USDT with no bitcoin taken; Circle and Tether froze about $318K, while roughly $83M in native XRP moved beyond Ripple's power to freeze; North Korea attribution comes from Bitget, Elliptic and MetaMask's Taylor Monahan, not yet from any government; Bitget says its User Protection Fund covers the loss and is reopening withdrawals in phases from 28 September -- CoinDesk, TFTC, Bitcoin Magazine, CoinDesk (freezes), CoinDesk (XRP), Bitget
- AMLBot traced part of the Bitget haul from TRX to USDT, bridged to Ethereum, swapped to about 145 ETH, then through THORChain into about 4.59 BTC, with roughly 4 BTC of that linked to an unnamed Wasabi coinjoin round and the addresses "blacklisted"; most of the stolen funds have not moved -- AMLBot on X, crypto.news
- Matt Morehouse disclosed two denial-of-service bugs in Eclair v0.13.1 and earlier, fixed in v0.14.0: oversized feature-bit init messages could allocate about 300MB per message and crash a node, and zlib-compressed channel queries could inflate 64KB into 64MB; his smite fuzzer found the first, an LLM-assisted search for similar code patterns found the second -- Delving Bitcoin
- Lightning Labs published four security advisories: a High-rated bug let an invoice be marked settled after an interceptor had already cancelled the HTLC, affecting tapd 0.5.0 and earlier and lnd 0.18.4 to 0.18.5; three Low-rated DoS bugs covered a gossip stall, a panic on a malformed DNS seed response, and memory exhaustion from Brontide write allocations; nodes on current lnd (0.21.3 or 0.20.4) are unaffected -- Lightning Labs security
- Galaxy's Alex Thorn disclosed that 52.37 BTC from weak-entropy Coldcard addresses, about 2.8% of the total taken and roughly $4.5M, had been moved into an address belonging to a Wyoming "Crypto Recovery Trust" carrying an OP_RETURN reading "claim:cryptorecoverytrust.com"; the trust says owners can reclaim coins by proving control, but the white-hats are unnamed and its legal documents are unverified -- CoinDesk
- SEC Commissioner Hester Peirce announced she resigns effective 2 October after nearly nine years to join Regent University School of Law, leaving the SEC with two Republican commissioners and no replacement nominee named; two days earlier, at SIFMA's Digital Assets Conference, she argued for replacing KYC document collection with zero-knowledge proofs and attribute-based credentials, telling regulators "we build ever bigger data haystacks on the theory that we will find a needle or two inside" -- CoinDesk, TFTC, TFTC (speech)
- New York Attorney General Letitia James and Governor Kathy Hochul sued Polymarket US in state court on 24 September alleging unlicensed gambling and underage betting, seeking at least $4.6B in fines; Polymarket moved the case to federal court and countersued, arguing the Commodity Exchange Act gives the CFTC exclusive authority; the next day a unanimous Sixth Circuit panel ruled Kalshi's sports contracts are subject to state gambling law, splitting with the Third Circuit and making a Supreme Court case more likely -- CoinDesk, CNBC, CoinDesk (Kalshi)
- BitMEX stopped trading, deposits and new positions at 04:00 UTC on 23 September after 11 years, with API withdrawals ending 28 September and website withdrawals staying open; from 1 October verified accounts with a balance pay the greater of 1% a year or $50 a month; owner HDR Global Trading cites a strategic review, with no legal or regulatory issues behind the closure -- CoinDesk
- The x402 protocol, reviving HTTP 402 "Payment Required" for machine payments, merged Ben Carman's spec for paying with Lightning: the server issues a BOLT11 invoice whose description hash commits to the exact request, the client pays and returns the preimage, and the facilitator checks it against the payment hash and invoice signer without querying the receiver's node -- GitHub PR #2861
RELEASES
Am I Exposed v0.36.0 -- 2026-09-26
- Detects Whirlpool tx0 premix outputs and Wasabi 1.x coinjoins it previously missed or misgraded, and flags input-side address reuse as a leak instead of scoring it as good.
- Fourth beta of the JoinMarket web UI: adds Sign Message, pins the exact UTXOs shown when sweeping, and lets you freeze or unfreeze several UTXOs at once.
- A self-hosted, privacy-focused Ark wallet preview adding optional Payjoin v2 on Signet, Tor-only networking that fails closed, Silent Payments and experimental post-quantum messaging.
- Stable release embedding LND v0.21.3 with SATS Routing and Coinos as swap providers, plus a critical fix moving iOS wallet data out of iCloud-synced Keychain.
- Adds manual coin selection filters, transaction notes and a price chart, and restores 2-of-2 and 2-of-3 multisig account creation.
- Stable release of Umbrel's home-server OS adding a Photos app, multiple user accounts, virtual machines, FailSafe RAID storage and a redesigned App Store.
- Fixes a bug where one valid input in a multi-input transaction could make a fake change output look legitimate; every input is now checked against the actual cosigner keys.
- Adds paying to Lightning addresses and LNURL-pay from the send flow, redesigns manual coin selection, and restores 2-of-2 and 2-of-3 multisig account creation.
- Amber v6.6.5 -- 2026-09-21
- Nostr signer: relay backups are now encrypted with a separate derived key, previously readable by any app with a remembered decrypt permission.
- Arkade TS SDK 0.4.76 -- 2026-09-25
- Developer SDK patch release for the Arkade (Ark) protocol, following 0.4.75 earlier in the week.
- Bisq Easy (Android) 0.14.1 -- 2026-09-26
- Security release: embedded Tor updated to 0.4.9.13, closing high-severity Tor issues, now built from Bisq's own Tor fork.
- Sister app: Bisq Connect 0.10.0 (2026-09-26), same Tor upgrade.
- Breez Spark SDK 0.26.0 -- 2026-09-23
- Adds receiving USDT and USDC, and instant or expedited claims for on-chain deposits.
- Cashu TS v4.11.0 -- 2026-09-22
- Backported fixes: melt preimages checked against the invoice hash, requests default to a 5-minute timeout, and closed subscriptions report an error.
- cln-nip47 v0.2.1 -- 2026-09-26
- Nostr Wallet Connect plugin for Core Lightning. Dependency updates.
- Core Lightning v26.06.8 -- 2026-09-22
- Security release fixing responsibly reported vulnerabilities, confirmed to include the dual-fund drain reported in issue #9498. Upgrade.
- Ditto v2.42.2 -- 2026-09-27
- Nostr social server: verified-link badges, muted users blocked from push notifications.
- Also in window: 2.39.2 to 2.42.0 (posting streaks, emoji packs, push).
- JoinMarket-NG 0.40.0 -- 2026-09-27
- BIP-329 labels now distinguish coinjoin output, coinjoin change and deposits; adds PSBT v2 signing and warns when the wallet daemon listens in plaintext off localhost.
