News archive
Everything we have published, newest first. 91 stories, each one sourced to a primary document.
PaymentsBlock brings Lightning payments to x402
Block has added Bitcoin Lightning to the x402 payment standard. The design lets software pay for individual requests, with important limits on delivery and refunds.
3 min read
PrivacyShielded Bitcoin proposes private transfers without a soft fork
A new Shielded Bitcoin design puts encrypted transfer data on Bitcoin without changing consensus. The transfer layer is specified, but moving real BTC into and out of it is not.
5 min read
WalletsAlby warns about older Hubs exposed to the internet
Alby reports a critical flaw in older internet-accessible Hubs. Its updated advice includes removing app connections, and its deployment guides also needed correction.
3 min read
WalletsA wallet can miss a payment without losing the bitcoin
BDK fixed a rescan that could overlook received funds. The order of the search mattered. A merged fix is not yet proof that your wallet includes it.
2 min read
Mining EconomicsA miner turns off every machine for an AI tenant
Hyperscale Data stopped bitcoin mining in Michigan on 1 September 2026 to free the power for an AI colocation customer, and has been selling the coins to pay for the conversion. The arithmetic behind both decisions is the same one.
3 min read
Post-QuantumA hash-based signature sized for a Bitcoin block
SHRINCS is a post-quantum signature scheme whose security rests on SHA256 alone. The first draft specification puts a signature at 548 bytes when the signer tracks state, and 5,777 when it cannot. Neither number is 64.
4 min read
ETFsA bitcoin ETF drops off the weekly options list
Three MIAX exchanges rewrote which funds may list short-dated weekly options, and the filing records in passing that the iShares Bitcoin Trust came off the list in July 2026. The test that removed it never looks at what the fund holds.
4 min read
Preferred StockStrategy's common stock now funds its preferred
In the week to 30 August 2026 Strategy sold 4,531,421 common shares for $602.8 million net. Bitcoin took $369.7 million of it. The rest paid a preferred dividend, bought back preferred stock and topped up cash.
4 min read
Bitcoin CoreA wallet name that could run commands
Bitcoin Core quoted the wallet name before pasting it into the -walletnotify command, and then the pasting step read the quoted text again as a regex format string. The fix merged on 2 September 2026 and is in no release yet.
4 min read
MiningThe block template that skipped transactions that fit
Bitcoin Core measured a candidate transaction group with one ruler and the space left in the block with another. Signature-heavy groups that would have fitted were skipped, and the fix was merged on 24 August 2026.
4 min read
RegulationRussia's digital currency law starts, licensing waits
Russia's first comprehensive statute for digital currency came into force on 1 September 2026. The three provisions that actually confine trading to licensed firms are held back until July 2027, and the retail cap is left to the central bank.
4 min read
RegulationA crypto custody rule nobody outside can read yet
The SEC sent a draft rewrite of its custody rules for advisers and funds to White House review on 25 August 2026. The text is not public, no rule has changed, and the last attempt at this was withdrawn in 2025.
3 min read
Corporate FinanceThe bitcoin raise where most of the money is optional
Capital B raised 21 million euros to buy 270 bitcoin, and attached warrants that could bring another 136 million. The second number is the interesting one, because nobody has promised to pay it.
3 min read
Post-QuantumThe lattice shortlist for a post-quantum Bitcoin
Blockstream Research reviewed three lattice signature schemes as replacements for Bitcoin's signatures. One of the three had been withdrawn a month earlier after an attack. Here is what the sizes mean for block space, and what none of them can do yet.
3 min read
ChannelsA channel close that was final one block too early
LND treated a cooperative channel close as settled after one confirmation, which left a one-block reorg enough to steal the channel. The fix is real, but the version named in the disclosure is not where it shipped.
3 min read
ETFsA bitcoin ETF changes the rate it prices itself by
On 26 August 2026 the ARK 21Shares Bitcoin ETF told the SEC it would stop valuing itself against the CME CF Bitcoin Reference Rate and start using the FTSE Bitcoin Index. The fund holds the same coins either way, which is what makes the change worth reading.
3 min read
Core LightningCore Lightning ships the fix before the source
Core Lightning released patched binaries on 28 August 2026 and is holding the source code back for fourteen days. The delay is the interesting part: what it buys, and what it costs the people who verify what they run.
3 min read
Hardware WalletsThe bridge from Bitcoin Core to hardware wallets winds down
HWI, the program that lets Bitcoin Core talk to a signing device, is going into maintenance mode and will eventually be archived. The reason given is the interesting part: Python cannot be built deterministically, so it could never ship inside Core.
3 min read
Corporate TreasuryA 30,021 bitcoin merger ends with a cash payment
BSTR and Cantor Equity Partners I terminated their merger on 20 August 2026. No bitcoin moved, the private placements fell away with it, and the seller still owes 15 million dollars for a deal that never closed.
4 min read
SanctionsTreasury makes Iran's digital asset sector sanctionable
On 24 August 2026 OFAC determined that Executive Order 13902 now reaches Iran's digital asset sector. The determination sanctions nobody by itself. It switches on the power to designate anyone who operates there.
3 min read
Bitcoin CoreOne random number generator, two threads
Bitcoin Core merged a fix on 26 August 2026 for a change made eight days earlier that let two threads reach the same random number generator. No release ever carried it, and the reason the generator is there at all is the interesting part.
3 min read
Payment ProcessorsStolen macaroons drained BTCPay Lightning nodes
BTCPay Server 2.4.2, released 7 August 2026, closed a hole that let an unauthenticated remote attacker read LND credential files off a merchant's server. Anyone holding the admin one can move the node's money, which is what happened.
5 min read
Wallet StandardsThe extended keys a wallet is supposed to refuse
On 21 August 2026 Electrum merged two checks that reject extended keys BIP-32 has listed as invalid for years. Without one of them, the parser read the last 32 bytes of a key field whatever the byte in front of them said.
4 min read
SplicingA splice input that claimed to belong to one side
On 21 August 2026 LDK merged a fix for splice negotiation. Presenting the shared channel input as a wholly owned one let the other side be credited with money it did not bring, and the transaction was signed anyway.
4 min read
Preferred StockStrategy sold 6,916 bitcoin to fund its preferred
On 29 June 2026 Strategy adopted a framework whose fifth component authorises selling bitcoin to pay preferred dividends. Over the following six weeks it sold 6,916 bitcoin, and one filing says in plain words that the proceeds funded the dividend.
5 min read
Stratum V2Stratum V2 stops leaving its keys lying around
On 19 August 2026 the Stratum V2 reference implementation merged 27 commits to the crate that encrypts a miner's connection to its pool and the codec around it. None of them fixes the encryption. All of them are about what the code does with keys and counters around it.
4 min read
Fee MarketBitcoin Core adds a mempool fee estimator
A second fee estimator was merged into Bitcoin Core on 21 August 2026. It reads the mempool as it is now, and it is only allowed to lower the number the old estimator gives you.
4 min read
Wallet StandardsCombining two PSBTs could make a file nothing can read
Bitcoin Core merged a fix on 19 August 2026 for combinepsbt, which could return a partially signed transaction that its own deserialiser rejects. Every release since v23.0 can still produce one.
4 min read
Key DerivationWallet encryption had a count that could go negative
Bitcoin Core merged a fix on 19 August 2026 for a wallet encryption path where an iteration count above 2,147,483,647 turned negative. The part worth reading is where that number comes from.
4 min read
PrivacyBIP-351 private payments is marked Closed
A 2022 proposal for reusable payment codes was moved to Closed on 19 August 2026 after four years of silence. What it was trying to solve is still open, and the design that shipped instead made the opposite trade.
4 min read
ConsensusThe merkle rule Core had never written down
A change merged on 20 August 2026 alters no behaviour. It writes down what Bitcoin Core's merkle root function has done since 2012, and adds a test that fails if a future refactor quietly changes it.
4 min read
Bitcoin CoreCore's commit verifier accepted unrelated history
Two paths through the script that checks Bitcoin Core's signed commit history reached the success exit without proving anything: a failed git command, and a history that had diverged from the trusted root. The fix makes the script prove the link or refuse.
4 min read
ProtocolA silent payments check was reading scripts too eagerly
BIP-375 forbids mixing a silent payment output with an input the wallet cannot classify. Its reference validator decided which inputs those were by looking at one byte, and one byte is not enough to tell a witness program from an ordinary script.
3 min read
Nostr KeysDeriving a Nostr identity from your Bitcoin seed
BIP-85 now has a Nostr application, so a Nostr secret key can be derived from a seed phrase already written down rather than backed up separately. The design allows several unlinkable identities and key rotation within each.
3 min read
DisclosureWhere to report a flaw in a Bitcoin specification
The BIPs repository now carries a security policy. Its first instruction is not to use it: report to the implementations, because a specification has nothing to patch.
3 min read
Key DerivationChain code delegation: signing without seeing the wallet
A multisig co-signer normally has to be handed an xpub, which shows them every address and every balance in the wallet. BIP-89 hands over a per-input tweak instead, and it has now been marked as deployed.
3 min read
ProtocolBitcoin Core warns I2P nodes that ElGamal is going away
A merged release note tells operators running Bitcoin Core over I2P that the legacy ElGamal encryption type is being retired, and that nodes older than v26.1 will end up talking only to each other. The interesting part is what a fallback entry in a list is actually for.
3 min read
LNDLND bounds what one peer can make a node buffer
Two LND releases cap how many channel identifiers a peer can make a node accumulate while syncing the Lightning graph. No funds were at risk. What was at risk was the node staying up, which is not the same as nothing.
3 min read
Monetary PolicyThe fourth halving cuts the subsidy to 3.125 bitcoin
Block 840,000 arrived at 00:09 UTC on 20 April 2024 and the block subsidy halved. Nobody scheduled it, nobody could delay it, and every node would have rejected a block that ignored it.
3 min read
UTXO SetRunes activates at block 840,000, in an output nodes can discard
A second token protocol went live in the halving block. Its interesting choice is where it puts its data: an OP_RETURN output, which no node has to remember.
3 min read


















































