Logo
Home
Archives
Premium
Donate
Media Kit
Recommendations
Tags
Login
Subscribe
Logo
  • Home
  • Posts
  • Swiss BTC Pay Hacked 🔓, Dev Shield Scrapped ⚠️, DOJ Targets Iran Funds 🏦

Swiss BTC Pay Hacked 🔓, Dev Shield Scrapped ⚠️, DOJ Targets Iran Funds 🏦

The processor says a non-custodial design kept user funds safe while it has not named a date for restoring service.

Upgrade | Sponsor | Archive

BITCOIN BREAKDOWN BANNER IMAGE

In partnership with

Greetings Bitcoiner,

❝

Welcome to Issue #651 of Bitcoin Breakdown, where every Tuesday and Thursday, we bring you the latest must-read Bitcoin thought leadership articles and the newest tools and projects you should know about. But first, today’s Top Stories:

Swiss Bitcoin Pay disclosed an intrusion that exposed customer emails, IBANs, and transaction histories, though user funds stayed safe under its non-custodial design. New CLARITY Act text dropped the Section 1960 carve-out for wallet developers, and federal prosecutors moved to seize $61 million tied to Iranian oil sales.

Analytics on Live Data Without Leaving Postgres

When analytics on Postgres slows down, most teams add a second database. Then come the pipelines, the sync jobs, and a copy of your data that's always a little behind.

TimescaleDB takes a different approach: extend Postgres instead of splitting away from it. Hypertables partition your data automatically as volume grows. Hypercore compression cuts storage up to 95%. Continuous aggregates keep dashboards live without re-querying everything.

CERN runs Postgres this way for sensor data from the Large Hadron Collider.

No split architecture, no pipeline lag, no new query language to learn. Same SQL, same drivers, same tools.

Start on Tiger Cloud and get $1000 in credits.

Get $1000 Credit

❝

🔓 Swiss Bitcoin Pay Breach Exposes Customer IBANs

Swiss Bitcoin Pay said an unauthorized intruder likely reached internal systems and customer records covering emails, Bitcoin addresses, IBANs, transaction histories, and hashed passwords. The platform said user funds remain secure because of its non-custodial architecture, while it has not given a specific date for restoring services and servers.

Why it matters: Non-custodial design kept user funds out of reach while the intruder held internal records, because the operator never controlled those keys. The exposed emails, IBANs, and transaction histories are the identity layer that fiat rails demand. Read more→

🗳️ Congress Drops Wallet Developers' Section 1960 Shield

New CLARITY Act text removes every Section 1960 reference from the Blockchain Regulatory Certainty Act compromise, cutting the explicit criminal carve-out earlier drafts gave non-custodial developers. The Bitcoin Policy Institute argues Section 1960 does not apply to such developers and says the revised bill still improves their position, but the Samourai and Tornado Cash theory is left to courts.

Why it matters: Policy experts are selling a compromise that trades away the developer carve-out, while Samourai developers remain in prison. Measured by outcomes, this lobbying is failing, because other wallet developers still live in fear of the criminal theory the deal leaves open. Read more→

🏦 US Seeks $61 Million Tied to Iranian Oil Sales

The Justice Department is seeking forfeiture of $61 million in cryptocurrency it calls proceeds of black market oil sales for the Iranian military. Prosecutors allege two Chinese entities serving petroleum clients ran fiat-to-crypto on-ramping through US-based issuers and moved tens of millions through the US financial system.

Why it matters: The alleged path ran through US-based issuers and the US financial system before reaching self-custodial addresses, which shows where the state can actually seize. Permissioned on-ramps are the chokepoint, not the Bitcoin network itself. Read more→

Listen on Fountain: Swiss Bitcoin Pay Hack, Section 1960 Dropped, DOJ's $61M Iran Case

Today’s top stories, under 5 minutes.

Fountain: Podcasts & Music

PREVIOUS POLL RESULTS
INSIGHTS & ANALYSIS
  • Steven Roose, CEO of Second and former Blockstream engineer, explains how an unsafe cache key concatenation bug in Liquid Network enabled a catastrophic 4,000 BTC exploit, warning developers that flawed optimization and absent reserve ceilings jeopardize sidechain security (Sep 12 | 15 min read).

  • Jamie Crawley of CoinDesk details findings from Bitcoin Suisse showing that reallocating from bonds to bitcoin improves portfolio returns amid soaring AI investment, rising US sovereign debt past $40T, and failing stock-bond diversification (Sep 11 | 3 min read).

  • Francisco Calderón, developer of lnp2pBot and Mostro, reveals that a silent dependency patch in the BOLT11 invoices library caused an exploit draining Bitcoin funds, urging open-source maintainers to transparently announce critical security fixes rather than burying them inside breaking changelogs (Sep 10 | 2 min read).

  • Scoresby, a Bitcoin commentator and ecash analyst, argues that while L-BTC and federated ecash tokens are not sh!tcoins, catastrophic network halts would prove that they are inherently custodial rather than self-custodial solutions for holding bitcoin (Sep 9 | 3 min read).

  • Cypher Box, a 'progressive Bitcoin self-custody' platform, counters claims that Ark is custodial by demonstrating that users can execute slow, unilateral on chain exits for their VTXOs without third-party permission even when servers go offline (Sep 10 | 2 min read).

  • Bark, an open source Ark wallet implementation, introduces Payjoin boarding in version 0.6.2 to enable direct on-chain Bitcoin cut through deposits onto Ark layer two balances and ecash mint reserves in a single transaction that saves users time and fees (Sep 10 | 4 min read).

  • Eric Yakes of Epoch Ventures refutes the narrative that Zcash is 'private Bitcoin,' arguing that its weaker security budget, centralized governance, consensus instability, lack of supply auditability, and bloated transaction sizes prevent it from ever matching Bitcoin's monetary immutability (Sep 10 | 9 min read).

  • Matt Howard of Solosatoshi writes that verifiable open source mining firmware like AxeOS and Mujina is essential to protect operators from closed-source risks such as vendor lockouts, hidden fees, and the inflated hashrates recently exposed in the Bitfortun BS-1 (Sep 10 | 18 min read).

  • Lillian Wang, an undergraduate student researcher at the MIT Digital Currency Initiative, compares proposed Bitcoin covenant mechanisms including CTV, CCV, and TXHASH, showing how each approach navigates critical tradeoffs between operational complexity, fee management, and withdrawal flexibility for securing Bitcoin vaults (Sep 8 | 18 min read).

  • Btrust, a non-profit organization supporting Bitcoin developers, details how engineers can secure open-source developer grants and fellowships by outlining technical readiness, contribution records, and realistic project timelines to create sustained full-time impact (Sep 9 | 9 min read).

TOOLS & PROJECTS
  • Noah, an Ark-protocol Bitcoin wallet by Second, introduces an emergency exit fee estimator, letting users calculate on-chain recovery costs for virtual transaction outputs if service goes offline and they want a unilateral exit.

  • Desobediente Tecnológico demonstrates a proof of concept running open-source SeedSigner software on a retro handheld console, creating a discreet, wireless-free air-gapped signing device.

  • DMND, a Stratum V2 mining pool, launches a read-only monitoring API, allowing Bitcoin miners to track live hashrate, worker activity, and payouts securely without risking any fund movements.

  • B10c updates Bitcoin network monitoring tool fork(dot)observer to display real-time mining pool targets using stratum(dot)work data, boosting transparency around potential chain splits and network health.

  • Stacy Herbert, head of El Salvador's National Bitcoin Office, announces the return of the Bitcoin Histórico conference to San Salvador in November 2026.

  • Lugano Plan B, a municipal Bitcoin adoption initiative in Switzerland, hosts its ten-day Plan B Week in October, featuring 15 educational Bitcoin events to accelerate local Bitcoin adoption.

  • Hazync compiles unmodified Bitcoin Core consensus code into zero-knowledge proofs to let users quickly verify blockchain history without full initial block downloads.

  • Murch, a Bitcoin developer, joins host Christine D. Kim on the podcast 'Ready for Merge' for 15 biweekly episodes to explain Bitcoin Core protocol development to broader audiences.

  • Vinicius Cestari of Vinteum develops an AI-driven mutation testing tool called mutant-harness, helping developers uncover overlooked test gaps and prevent potential consensus bugs in node software.

  • ICYMI: Issue #10736 on LND's GitHub repository tracks the integration of BOLT12 on LND, which is the last remaining Lightning implementation to adopt the standard.

MEME OF TE DAY

meme

Thank you for reading!

❝

P.S. If you received it from a friend and would like to subscribe, you can do so here.

P.P.S. Looking to start your own newsletter? Use this link to sign up for beehiiv and get a 30-day free trial plus a 20% discount.

background

Bitcoin-only daily newsletter with the highest signal-to-noise ratio in the industry