Logo
Home
Archives
Premium
Donate
Media Kit
Recommendations
Tags
Login
Subscribe
Logo
  • Home
  • Posts
  • ๐Ÿ”ด AI Finds Bitcoin Bugs - ๐ŸŒ .bitcoin Faces Auction - ๐Ÿ‡ท๐Ÿ‡บ Putin Bans BTC Payments

๐Ÿ”ด AI Finds Bitcoin Bugs - ๐ŸŒ .bitcoin Faces Auction - ๐Ÿ‡ท๐Ÿ‡บ Putin Bans BTC Payments

Unpaid maintainers are now triaging reports faster than ever.

Upgrade | Sponsor | Archive

Together with

Greetings Bitcoiner,

โ

Welcome to Issue #617 of Bitcoin Breakdown, where every Tuesday and Thursday, we bring you the latest must-read Bitcoin thought leadership articles and the newest tools and projects you should know about. But first, todayโ€™s Top Stories:

Sixteen volunteers pointed open-weight AI at Bitcoin code and filed nearly five thousand findings in about a day. wiz, who runs mempool infrastructure and a DNS seed, is racing an ICANN deadline to keep the .bitcoin domain out of auction. Putin signed an exchange policy that still bars spending Bitcoin inside Russia.

TOGETHER WITH CASA

Still Holding Bitcoin on One Device?

A multi-key vault with keys spread across devices from different vendors eliminates single points of failure. No single bug, theft, or mistake can touch your bitcoin.

If your setup depends on one device being perfect forever, what is your plan for the day it is not?

Casa's security team is running free consultations to review your setup, show you what a multivendor multisig wallet would look like for you, and help you plan a calm migration, including pairing hardware you already own.

Casa holds your hand, not your keys. The strongest self-custody is the kind with no single point of failure.

Book a security consultation with Casa Advisors here.

Book A Free Consult

โ

๐Ÿ”ด AI Red Team Files 4,962 Bitcoin Security Findings

A volunteer group calling itself the Bitcoin Red Team, now 16 people working around the clock, has filed 4,962 findings across 390 Bitcoin projects in roughly 28 hours, including 85 critical and 635 high severity issues. The effort runs on open-weight AI models, and Rob Hamilton of AnchorWatch says the team has covered more than 300 repositories and spent close to $40,000. Only 21.4% of those findings have been reproduced so far.

Why it matters: Open source means anyone can audit your code, including the people you would rather did not. Maintainers who work for free are now triaging reports faster than they ever have, and that queue is the real risk. Read moreโ†’

Open code raises a harder question about ownership...

๐ŸŒ Bitcoiners Race to Claim .bitcoin Before Auction

wiz, operator of mempool(dot)space and one of Bitcoin's DNS seeds, is filing a community priority application with ICANN for the .bitcoin top level domain before the window closes at 23:59 UTC on August 12. Without one, the string goes to auction and to whoever bids highest. His proposed policy is strictly Bitcoin only, run by a committee where he holds one ordinary seat and no veto, with 21% of registry revenue pledged to open source developers.

Why it matters: Six days decide how Bitcoin's name reads on the open internet for decades. Bull Bitcoin has already endorsed it, and the alternative is a corporate bidder with no obligation to the people who built this. You know what to do. Read moreโ†’

Other claims on Bitcoin get written into law...

๐Ÿ‡ท๐Ÿ‡บ Putin Signs Digital Currency Law, Payments Stay Banned

Vladimir Putin signed Russia's Law on Digital Currencies and Digital Rights on Wednesday, creating a regulated exchange market from September 1 under central bank supervision. Bitcoin still cannot be used to pay for goods and services inside the country, and retail buyers face a knowledge test plus a cap of 300,000 rubles a year per platform. Exchanges must join a registry, hold 15M rubles in equity, and have until March 1, 2027 to comply.

Why it matters: Putin once asked who could ban Bitcoin and answered nobody. He then signed a law banning his own citizens from spending it, which tells you the target was never the network. Read moreโ†’

  • Start9, a self-hosting solution provider, warns Bitcoin users that BIP-110's RDTS softfork risks a chain split and urges closing Lightning channels and taking self-custody of bitcoin before block 961,632, while critics call the fork doomed for lacking hashrate and consensus (Aug 6 | 40 min read).

  • American HODL, a Bitcoin commentator, addresses the psychological fallout from the Coldcard entropy bug, outlining five emotional 'rooms,' fight-flight-freeze responses, and a recovery protocol to help bitcoiners process shattered trust and grief (Aug 5 | 7 min read).

  • Laser, a Nostr user, traces how Coinkite CTO Peter Gray, under the pseudonym switck, swapped Coldcard's hardware RNG for a weak software PRNG in 2021, enabling a heist exposed in last week (Aug 4 | 3 min read).

  • Allard Peng of Bitcoin For Corporations argues that the Coldcard hack looks like a state-backed insider job targeting self-custody, citing suspicious old posts from the hardware wallet's social handle (Aug 4 | 2 min read).

  • Juan Galt of Bitcoin Magazine argues that the Coldcard entropy bug and theft of over 1,300 BTC won't kill self-custody, since multisig and Bitcoin's digital nature outmatch gold's vulnerability to confiscation like FDR's 1933 Executive Order 6102 (Aug 4 | 6 min read).

  • Allard Peng, analyst at Bitcoin For Corporations, explains how companies should navigate the BIP-110 soft fork, advising most firms to stay the course while miners, exchanges, and custodians prepare for potential chain splits (Aug 4 | 4 min read).

  • Koji Higashi, Japanese Bitcoiner and CEO of Diamond Hands, explains how Korean Bitcoiners avoided losses in the Coldcard security incident by using dice-roll passphrases instead of trusting vendor RNG, exposing how English-speaking influencers' financial ties skewed objective risk assessment (Aug 4 | 4 min read).

  • Pavol Rusnak, Co-founder of Satoshi Labs, argues that toxic maximalism within the Bitcoin community, highlighted by the recent Coldcard controversy, ultimately fails and urges builders to embrace excellence and constructive collaboration instead (Aug 4 | 2 min read).

  • PortlandHODL of AnchorWatch verifies the Coldcard diceroll seed path across firmware versions using a simulator trace, confirming that seeds generated using the diceroll method correctly generates valid entropy and remain safe (Aug 4 | 17 min read).

  • The Smart Ape reviews entropy sources across hardware wallets after Coldcard's reproducible seed flaw drained BTC holders, ranking Trezor, BitBoxSwiss, and SeedSigner's multi-source, verifiable designs above single-source, closed models like Ledger and Tangem (Aug 3 | 2 min read).

  • Lauri Hรคnninen of Trezor argues that the Coldcard security incident reflects a licensing distinction, not open source failure, since Coldcard's firmware is merely source-available, lacking the free-to-modify terms that drive genuine community auditing and improvement (Aug 3 | 2 min read).

  • UTXOClub of Frostsnap argues that export controls and AI guardrails on American models are limiting who can hunt Bitcoin vulnerabilities while their Chinese counterparts prove more effective for the task (Aug 2 | 2 min read).

  • Tom Kirkpatrick, CTO of Strike, explains how his company uses AI-driven, continuous review to trace real attack paths across code, infrastructure and identity boundaries, letting engineers validate findings and fix confirmed weaknesses before attackers exploit them (Aug 4 | 5 min read).

  • L0la L33tz of The Rage publishes a post with details on the Coldcard hack, detailing next steps for affected users, chances of recovering stolen funds and events that led to this situation (Aug 3 | 7 min read).

  • Frank Corva, a Bitcoin writer and journalist, summarizes the Coldcard incident and argues that despite the firmware flaw exposing private keys and causing theft, this isn't the end of Bitcoin self-custody, while advocating for dice-roll seed generation and multisig setups (Aug 2 | 11 min read).

  • Katie Mestre, aka Bitcoin Katie, breaks down the Coldcard hardware wallet flaw, detailing what happened, what affected users should do and what we can all learn from it (Aug 2 | 11 min read).

  • L0la L33tz also questions whether the US State Department's new Freedom Tech Excellence Program with Bitcoin Policy Institute, Palantir, and Anduril genuinely protects digital freedom or actually enables surveillance against dissidents amid escalating financial warfare (Jul 30 | 6 min read).

  • Bitcoin News, another Bitcoin-only publication, reports on Trezor's 12th anniversary of shipping the Model One, the first hardware wallet, as founders Marek Palatinus (aka Slush) and Pavol Rusnรกk reflect on Bitcoin self-custody's origins and its ongoing usability challenges (Jul 29 | 5 min read).

  • ZEUS, a Lightning Network wallet and service provider, confirms that a cybersecurity incident took infrastructure offline temporarily, but no customer funds were lost or remain at risk.

  • CKTripwire by James O'Beirne funds bitcoin honeypot wallets mimicking Coldcard's flawed random number generator bug, tracking how quickly attackers drain coins from predictable, brute-forceable private keys.

  • Blockstream launches a swap tool in beta for Lightning and Liquid wallets after Boltz suspends its services.

  • Geyser, a Bitcoin crowdfunding platform, confirms that contributions and payouts remain frozen as its swap partner Boltz stays disabled, though users' funds stay secure.

  • Second releases Bark version 0.5.0, letting Ark protocol wallets restore full off-chain balances from a mnemonic seed phrase.

  • Cashu Me, a Chaumian ecash wallet built on the Cashu protocol, is now available for public beta testing on Google's Play Store.

  • Prem AI, an open source AI infrastructure company, launches prem-router and sponsors credits granting Bitcoin researchers and security experts free access to the Kimi K3 model.

  • Wizardsardine's Outofband, a browser only tool, lets Liana and multisig wallet users submit signed bitcoin transactions privately to MARA Slipstream, bypassing the public mempool.

  • Electrum, a lightweight non-custodial Bitcoin wallet, maintains that its decentralized Lightning swap market is unaffected amid Boltz suspending its services.

  • Satora, formerly Lendasat, a peer-to-peer BTC-collateralized lending and non-custodial atomic swap platform, pauses operations, joining Boltz in doing the same.

  • Coinkite, maker of the Coldcard bitcoin hardware wallet, denies claims that new firmware permanently bricks devices, citing a fixable true random number generator fault requiring a power cycle.

  • Second, a company building an Ark implementation on Bitcoin, launches its Bark Wallet app on Start9's self-hosted server registry.

  • Tuma, a Bitcoin writer, launches 'Il Caffรจ Cypherpunk,' a weekly Italian language newsletter covering Bitcoin development and Freedom Tech news for readers.

  • Aeon, developer of the Ibis wallet, announces that version 5.0 of his product is coming out this week in beta, with full support for Bark, Second's implementation of the Ark protocol.

  • JoinMarket-NG, a privacy focused Bitcoin coinjoin wallet project, releases version 0.35.0 with automatic wallet history reconstruction, Neutrino fee estimation, and security fixes for maker and taker flows.

  • Cashu developers merge PR #382, adding NUT-04/05 support for custom payment methods beyond bolt11, letting mints and wallets handle unknown payment types generically.

Thank you for reading!

โ

P.S. If you received it from a friend and would like to subscribe, you can do so here.

P.P.S. Looking to start your own newsletter? Use this link to sign up for beehiiv and get a 30-day free trial plus a 20% discount.

background

Bitcoin-only daily newsletter with the highest signal-to-noise ratio in the industry

ยฉ 2026 Proof of Press LLC.
beehiivPowered by beehiiv