Logo
Home
Archives
Premium
Donate
Media Kit
Recommendations
Tags
Login
Subscribe
Logo
  • Home
  • Posts
  • White Hat Keeps 598 ๐Ÿ”, Coldcard Thief Mixes ๐Ÿ•ต๏ธ, Ledger Demands Fixes ๐Ÿ›ก๏ธ

White Hat Keeps 598 ๐Ÿ”, Coldcard Thief Mixes ๐Ÿ•ต๏ธ, Ledger Demands Fixes ๐Ÿ›ก๏ธ

Liquid's attackers returned 3,400 BTC after onchain talks, but their retained 598.5 BTC clouds the white-hat claim.

Upgrade | Sponsor | Archive

In partnership with

Greetings Bitcoiner,

โ

Welcome to Issue #645 of Bitcoin Breakdown, where every Tuesday and Thursday, we bring you the latest must-read Bitcoin thought leadership articles and the newest tools and projects you should know about. But first, todayโ€™s Top Stories:

Liquid recovered about 85% of withdrawn bitcoin through an on-chain negotiation, while 598.5 BTC remained without a public bounty agreement. Galaxy Research tracked a minority of stolen Coldcard funds moving in apparent laundering as Charles Guillemet and wallet security firms backed coordinated bug disclosure amid cheaper AI-assisted discovery.

Where Quantitative Thinkers Compete, Learn and Grow

The International Quant Championship (IQC) is one of the world's largest quantitative research competitions, bringing together 156,000+ participants globally.

Participants have the opportunity to develop quantitative research skills, challenge themselves alongside peers from around the world and connect with a global community of quantitative thinkers.

Build skills on WorldQuant BRAINยฎ

โ

๐Ÿ” Liquid Return Leaves 598.5 BTC Outstanding

Purported white-hat actors returned exactly 3,400 BTC, about 85% of the withdrawn funds, after Blockstream confirmed bridge-node patches. Roughly 598.5 BTC remained outstanding, and neither Blockstream nor Liquid publicly identified it as a bounty.

Why it matters: Bitcoin exposed the negotiation and settlement, but not consent for the outstanding 598.5 BTC. Verifiable transfers still need explicit agreements, responsible disclosure, and incentives that protect users. Read moreโ†’

Meanwhile, Galaxy is tracking other stolen bitcoin moving...

๐Ÿ•ต๏ธ Galaxy Tracks 18% of Stolen Coldcard Bitcoin

Galaxy Research said about 18% of stolen bitcoin moved in apparent laundering while 82% remained at original attacker-controlled addresses in total. The Wave 3 operator moved about 45% of that wave's funds, a separate denominator.

Why it matters: Bitcoin settlement follows control, even when control was stolen. Public movement can expose the trail, but secure key handling remains the boundary that prevents irreversible loss. Read moreโ†’

Those losses sharpen the debate over responsible disclosure...

๐Ÿ›ก๏ธ Wallet Makers Demand Responsible Bug Disclosure

Ledger Chief Technology Officer Charles Guillemet urged coordinated disclosure as artificial intelligence makes bug discovery cheaper. He named Ledger, Trezor, Foundation, AnchorWatch, and SEAL Org as supporters, while Foundation and AnchorWatch separately backed private remediation.

Why it matters: Self-custody depends on tools that protect keys. Private remediation, fair rewards, and prompt firmware updates align security research with users instead of turning exposed assets into publicity collateral. Read moreโ†’

Listen on Fountain: Liquid's Bounty Dispute, Coldcard Coins Move, Disclosure Standards

Todayโ€™s top stories, under 5 minutes.

Fountain: Podcasts & Music

  • Mononaut of Mempool(dot)space clarifies that Liquid Network reserves were drained due to a newly deployed patch introducing a cache-collision vulnerability rather than a long-standing flaw, enabling an attacker to bypass range proof validation and inflate L-BTC outputs via variable-length key manipulation (Sep 7 | 2 min read).

  • Calle, a Bitcoin developer, breaks down the recent Liquid Network exploit to clarify how a range proof cache collision bug allowed attackers to trigger confidential transaction inflation and drain funds to the Bitcoin's base chain (Sep 7 | 2 min read).

  • Daniel Batten, an advocator for mining using renewable energy, demonstrates how Bitcoin mining monetizes stranded renewable energy to accelerate grid expansion across nation states like Ethiopia, lower power prices, and disprove outdated environmental myths about bitcoin network consumption (Sep 7 | 6 min read).

  • Neha Narula, director of the Digital Currency Initiative at the MIT Media Lab, examines how a range-proof caching vulnerability enabled a $320M bridge exploit on Blockstream's Liquid sidechain, arguing that cryptographic privacy requires systemic defense-in-depth guardrails rather than relying on federated security theater (Sep 7 | 5 min read).

  • Yuval Kogman of Spiral reveals how naive CoinJoin anonymity models fail in practice, showing that toxic change outputs, coin consolidation, and auxiliary metadata allow real-world adversaries to deanonymize post-mix Bitcoin transactions through clustering and intersection attacks (Sep 3 | 12 min read).

  • Roman Storm, Tornado Cash cofounder targeted by US prosecutors for writing open-source code, leverages court transcripts alongside a 153M ID breach to argue that mandatory centralized surveillance creates dangerous honeypots while criminalizing essential financial privacy tools for law-abiding citizens (Sep 3 | 26 min read).

  • William L. Anderson, senior editor at the Mises Institute, writes that former Fed chair Ben Bernanke failed to rescue the US economy, contending his aggressive quantitative easing artificially propped up toxic malinvestments, fueled persistent inflation, and blocked genuine economic recovery instead of preventing another depression (Sep 3 | 6 min read).

  • LLFourn, a Bitcoin developer and researcher behind Frostsnap, reconstructs how the Coldcard Mk3 firmware RNG collapse enabled a 2,054 BTC exploit across 2,145 wallets to help researchers analyze attacker transaction heuristics and prevent further exploits (Sep 3 | 21 min read).

  • Sam Baker of River demonstrates that replacing bonds with a 10% bitcoin allocation in a standard 60/40 portfolio more than doubles decade-long returns while adding merely six percentage points of drawdown risk, effectively reviving portfolio diversification against persistent inflation (Sep 2 | 12 min read).

  • Cory Klippsten, CEO of Swan Bitcoin, highlights an academic paper debunking popular BTC forecasting models, arguing that no stock-to-flow or power law framework reliably outperforms naive price predictions as 8B global citizens gradually recognize the networkโ€™s value (Sep 2 | 5 min read).

  • Developer Ben Carman releases open-ssp, an open-source Rust implementation of a Spark Service Provider, enabling self-hosted Lightning Network settlements without requiring a commercial partnership with payments firm Lightspark.

  • Zaprite, a Bitcoin payments infrastructure platform, launches a closed beta mobile app designed to eliminate QR codes and invoices, simplifying peer-to-peer bitcoin transactions across multiple wallets and protocols.

  • Developer Average Gary proposes Silent Payments coinbase, a protocol utilizing BIP352 stealth addresses to let mining pools pay out individual bitcoin miners directly and privately within coinbase transactions.

  • Sovran Bitcoin is an open-source NixOS module replacing the discontinued Nix-Bitcoin project to give node runners a streamlined, sovereign Bitcoin and Lightning setup.

  • Hampus Sjรถberg, developer of Blixt and Noah Wallet, releases BcashJr Wallet, an open-source tool enabling users to safely split their bitcoin from newly hard-forked Blake-chain coins to trade on niche exchanges.

  • OCEAN mining pool restores its Lightning Network payouts after resolving chain split issues, while also halving its on-chain payout threshold to 500,000 sats to benefit smaller miners.

  • Bitshala, an Indian open-source developer initiative, launches Bitspace 2.0 in Bengaluru, opening an expanded coworking hub to support local engineers, researchers, and contributors building on Bitcoin.

  • Jack Mallers, CEO of payment app Strike, launches an anonymous audio platform allowing anyone worldwide to submit unfiltered questions for him to answer weekly on his Bitcoin show.

  • Fedimint, an open-source Bitcoin ecash implementation, launches version 0.12.0, enabling next-generation default modules, zero-downtime wallet recovery, and faster Lightning Network settlement speeds..

Thank you for reading!

โ

P.S. If you received it from a friend and would like to subscribe, you can do so here.

P.P.S. Looking to start your own newsletter? Use this link to sign up for beehiiv and get a 30-day free trial plus a 20% discount.

background

Bitcoin-only daily newsletter with the highest signal-to-noise ratio in the industry