🟥 URGENT: Critical vulnerability in Core Lightning
Blockstream developers urge users to shut down CLN Lightning nodes right NOW!
Please let everyone know!
cashu .me is now fully integrated with the latest version of npub .cash – that means your lightning address now works across all mints
settings -> Lightning address -> choose your mint
thank you @Egge
gained a ton of new insights working in bitcoin red team 🟥 that i wish i could share without vague posting. but this is what i got anon.
- we’re experiencing a massive collision between decades of human open source slop against 2 weeks of kimi k3 (not good)
- everything is broken, bitcoin is burning
- bitcoin is becoming stronger through this
- bitcoin is the obvious first target but the rest of the world will follow shortly
- sometimes old things need to burn so new things can grow on healthy soil
- humans should never code in c (just stop)
- lightning is complicated and is more broken than the average (sorry)
- verification is free. we used to complain about slop PRs. then about slop security audits. if you can’t handle the information overload, stop complaining and use AI to sort through it.
- those projects that started AI audits months ago are in a completely different position than those who didn’t
- projects need their own AI audit pipeline going into the future
- the burden for a developer to keep software safe and secure is pretty stressful and not for everyone. it has become a lot more stressful now.
- unmaintained projects are most probably broken, don’t rely on them. i’d rather one-shot it myself with a modern AI
- multiple concurrent, diverse human approaches have proven to be the best vulnerability search method
- external red teaming will probably have to continue forever
- we’ve basically completed a basic scan of virtually the entirety of bitcoin open source. the low hanging fruit is done.
- we’ve reported a ton of real critical and high vulnerabilities. project maintainers across the board have validated our findings.
- response speed is very different across projects and shows how healthy each project is. i recommend acting fast these days.
- red team etiquette matters. if you don’t disclose responsibly, boast on twitter about your findings on a particular project, or make indications about the nature of particular findings, you’ve disqualified yourself as a serious security researcher. trust is the most important factor in this game. if you lose it, it’s very hard to win it back.
- did i mention that humans should not code in c?
Say It — private, local text-to-speech for macOS
Open models 100% on-device, speak text from any app with a hotkey, and even clone your own voice.
Infinite voices. Free & open-source.
Listen to the video 🔊
Download for macOS:
🚨🚨 URGENT: BTCPAYSERVER 🚨🚨
There is a critical vulnerability that is being actively exploited on BTCPay Server which can lead to loss of funds.
Update your BTCPayServer to to 2.4.2 or turn off your BTCPayServer now.