No. 884C59 Thursday, September 10, 2026 24h to 13:28 UTC

TheNostr Observer

All the Notes Fit to Rank
Ranked as NotBiebs 583 events through your lens 233 voices
Vulnerability · Sidechains

The Shared Code Trap: 4,000 Bitcoin Drained From Liquid as Multisig Agrees With a Flaw

Fifteen independent signers, zero stolen keys — and eleven honest machines approving a bug that emptied the sidechain.

The security model was supposed to be bulletproof: fifteen geographically distributed companies guarding independent cryptographic keys, requiring eleven concurrent signatures before funds could peg out from Liquid to mainchain Bitcoin. Yet when an exploit struck on Wednesday, eleven legitimate signers dutifully approved a withdrawal that drained nearly every satoshi in reserve.

Ungovernable reported the scale of the collapse: Roughly 4,000 Bitcoin was withdrawn from Liquid after a software bug allowed LBTC that should never have existed to be accepted as valid. Over $320 million in value crossed the bridge, leaving barely 150 to 200 Bitcoin on the entire sidechain before block generation halted.

The failure tore through assumptions about threshold security. As Ungovernable observed, Every signer was reading the same faulty software, so every signer agreed. The number of keys does not fix a shared code failure. Obi crystallized the broader lesson: The real question is not trusted vs trustless. It's how many independent things have to go wrong before you lose money.

Dispatched from commentary by Ungovernable, Ungovernable on the federation, and Obi.

Hardware · Supply Chain

The Phishing Wave That Came From Inside the House

While developers dissected the Liquid exploit, hardware wallet users faced a coordinated social engineering strike. Compromised newsletter and notification providers sent spoofed critical security warnings from legitimate BitBox, Trezor, and CoinTracking sender addresses, complete with valid DKIM signatures and official manufacturer domains.

The incident ignited fresh demands for sovereign infrastructure. Timothy Allen argued: Trezor should stop using third parties. Time to do it all in-house. AZA_21m counted the summer's cumulative fatigue: Coldcard swipe vulnerabilities, Trezor courier leaks, the Liquid drain, and now BitBox inbox intrusions.

Cited from Timothy Allen.

Diagram shared by elsirion illustrating diminishing returns on code base security and the argument for multiple implementations.
Diminishing returns on securing a single code base: elsirion argues that beyond a certain point, doubling effort yields marginal security gains, making multiple autonomous implementations the only resilient path against catastrophic loss. elsirion · via Primal
Architecture · Ecash

Calling on Cypherpunks: elsirion Proposes Multi-Implementation Federations

With machine learning shifting leverage toward attackers, Fedimint looks to Cashu's diverse ecosystem to eliminate mono-culture code risks.

The Liquid collapse has catalyzed what may become the most consequential architectural pivot in federated Bitcoin systems. Fedimint lead elsirion issued an open call across the network: Calling on fellow cypherpunks to build alternative Fedimint implementations.

The Liquid hack shows once again that single points of failure are what will break our systems and that includes the code we write. With automated code analysis lowering the barrier for exploits, he warned, Security is an asymmetric game: an attacker has to find one weakness, while defenders have to find all. AI has permanently changed the attacker-defender balance for the worse.

His economic model for security is straightforward: The assumption is that there are diminishing returns to trying to make one code base secure. Eventually you'll have to spend twice the effort to make it a little bit more secure. Drawing inspiration from Cashu's multi-client, multi-mint ecosystem, he announced funding for independent teams operating purely off an extracted specification, purposefully disconnected from the original codebase.

Dispatched by elsirion's manifesto and his diminishing returns analysis.

Privacy · The Ledger

The Cost of Compliance: Pocket Bitcoin Records Leaked

A leak of Pocket Bitcoin compliance archives exposed 291 full user dossiers and 5,120 names, IBANs, and transaction values, permanently binding individual legal identities to public on-chain transactions. As Ungovernable noted, an address alone reveals nothing, but leaked regulatory records strip privacy forever: true sovereign custody demands acquiring coins without central identity registries.

Reported by Ungovernable.

Network Conditions · As of 13:28 UTC
Bitcoin Price $77,981
Mempool Rate 1 sat/vB
Block Height 965,225
Hash Rate 896 EH/s
To Halving 84,775 blks

Readings recorded within the 24-hour window, not a live ticker. Sources: Clark Moody Dashboard, ChartsBTC.

Garden photograph filed by CKMe showing basil in the garden.
Morning harvest: CKMe clearing garden beds for the compost pile, noting Basil will absolutely be the last to go. CKMe · via nostr.build
Broadcasting · Live Now

NoGood Radio on air via zap.stream.

Synthdragon Radio — FIERCE playing Crimson Racer.

Synthdragon Radio — CHILL playing Glaciella.

ScardustTV broadcasting live tour announcements.

Streams were active at publication closing; live status subject to change.

The Instrument

The control query read without this reader's lens produced 400 global notes. The overlap with the 380 ranked notes was 0 of 400.

Zero overlap demonstrates the web-of-trust lens operating at full discrimination, filtering unranked firehose content entirely.

The Dispatch · Ecosystem & Code

Bounties · Devstr

Five Million Sats to Put Nostr in Omarchy

Developer Five offered a substantial reward to bring Nostr directly into external desktop distributions: I am offering a 5.000.000 (5M) sats bounty for the first author of a meaningful nostr integration with Omarchy that is merged by a maintainer and shipped in the canonical release. He urged developers to focus on demonstrable real-world utility.

Source: Five.

Tools · Remote Compute

Pete Winn Assembles a Remote Nostr Browser

Screenshot of Pete Winn's Nostr-based web browser with built-in signer.
Pete Winn's prototype Nostr browser running remote apps over FIPs. Pete Winn · via Primal

Exploring remote client architectures, Pete Winn showcased a weekend experiment using FIPs to reach host machines: I now have a simple Nostr based web browser with built in signer.

Source: Pete Winn.

Ecash · Infrastructure

Mint Failover: Cuba Bitcoin Drops; Routstr 0.4.7 Ships

Decentralized mint routing faced a live drill when the Cuba Bitcoin Cashu mint experienced downtime, prompting routstrd to instruct node runners to switch to Minibits. Concurrently, Routstr tagged version 0.4.7 with completions updates and security fixes.

Source: routstr.

Reading Room · Highlights

The Printed Page · Marcel
there is something unique in the kind of writing that was done by a full editorial team and meant for permanently printing on paper.

Marcel marked this passage in Michael Enger's retrospective on early computer subcultures and the enduring permanence of print editorial work.

Surfaced by Marcel.

Signatures · Gigi
Cryptographic signatures don’t decay with social distance or sordidness.

Gigi surfaced Robert Heaton's analysis of why verified digital signatures preserve mathematical validity across dubious custody chains.

Surfaced by Gigi.

Plausible Deniability · Gigi
“A dog ate my homework” is a much more credible excuse if you ostentatiously purchased twenty ferocious dogs the day before.

Gigi marked this second passage from Heaton illustrating how cryptographic deniability relies on plausible circumstances rather than theoretical perfection.

Surfaced by Gigi.

Diary & Calendar

Friday, September 11 · Bellevue, WAEastside Bitcoin and Beer Gathering at Steve’s Bar and Grill (14230 NE 20th St).

Friday, September 11 · Bologna, ItalyMeetup bitcoiner Bologna at Ristorante Masini. Topic: custodial, non-custodial, and federations.

Saturday, September 12 · Miraflores, LimaLima - Bitcoin desde Cero, a practical four-hour workshop for beginners.

Monday, September 14 · Cagliari, SardiniaMeetup Bitcoiner Cagliari at Handy Capp Due for the monthly Satoshi Spritz.

Wednesday, September 23 · San Juan, PRSocratic Seminar #29 at Ralf's Game Club dissecting cutting-edge Bitcoin developments.

The Classifieds

$16.99 USDSweet Almond Lip Butter by Born To Be Free. Formulated with skin-compatible fats and oils.

$11.00 USDBasil & Lemongrass Tallow Soap Bar by Born To Be Free. Rich-lathering tallow soap with citrus notes.

$16.99 USDSweet Peppermint Lip Butter by Born To Be Free. Made with grass-fed beef tallow.

$16.99 USDCoconut Vanilla Tallow Lip Butter by Born To Be Free. Seed-oil free and plastic free.

$11.00 USDDried Chamomile & Calendula Unscented Soap Bar by Born To Be Free. Fragrance-free tallow soap.