Avatar
Leo Wandersleb
46fcbe3065eaf1ae7811465924e48923363ff3f526bd6f73d7c184b16bd8ce4d
https://walletscrutiny.com https://nostr.info Working on Bitcoin, Nostr and being a good dad.

"Don't trust. Verify." for me is a short hand for "Don't blindly trust stuff that could hurt you if its properties were not as advertised. Ideally some people you trust, verify these properties at all time but at the very minimum, those people have to have a way to independently verify whenever they want without the provider of the stuff knowing if they do."

So how about: "Trust if verification is plausible at all time."

They implicitly agreed to have been operating a "money transmitter" business, putting a target not only on coinjoin devs but all involved in self-custodial bitcoin wallets.

How to fix the quantum threat to your bitcoins:

1) Get off Twitter

It doesn't fix losing most of your screen real estate. Still it's mind boggling that most normies barely touch the keyboard. Copy, paste, switch window, switch tab, ... aand many more make you just so much more efficient.

First, coins got unspendable from prior forks at homeopathic quantities.

Second, freezing coins with 10 years of head notice isn't theft. It's just actual holders of Bitcoins refusing to sponsor a quantum frenzy to treasure hunt lost coins.

Losing coins was always considered deflationary. We just want to make sure to avoid inflation.

I will admit I would have failed your captcha but maybe I'm just a stupid foreigner ...

A bot could help me out though.

Gemini 3 Pro:

The "Mosaic Theory" of Intelligence (When to Panic over CRQCs)

If a nation-state is getting close, we will see signs in the academic and industrial sectors. Watch for these three things. If you see them, then you can start worrying about the "Bitcoin Upgrade Timeline."

The Brain Drain: If the top 50 researchers in superconducting qubits suddenly stop publishing papers and vanish from conferences, they have been recruited for a classified project. Currently, they are all very public, publishing openly to get tenure and funding.

Material Shortages: A sudden global shortage of Niobium (used for superconducting qubits) or Helium-3 (used for cooling) without a clear commercial explanation.

Post-Quantum Standards: The NIST (National Institute of Standards and Technology) is currently finalizing "Post-Quantum Cryptography" (PQC) standards. If the NSA suddenly pushes for an immediate, emergency adoption of these standards for military comms, it means they have made a breakthrough in offense. Right now, they are moving at a bureaucratic, leisurely pace.

Wasabi wallet or joinmarket. Coming from Samourai you will probably get along better with Wasabi but it's a desktop tool, so it's a bit more involved than a well sandboxed apk on your phone.

Don't pay Trump a ransom. If the campaign succeeds and gets Trump to "right some Biden era Lawfare", no harm is done in pardoning them.

The better course would have been to not plead guilty though. The guilty plea is a slap in the face for anybody who now is trying to help them.

I agree. That's why I made that post. As much as I hate to say this but this injustice - while it doesn't hurt the wrong guys sitting in a cell right now - can hurt others that are no dirtbags and thus I hope justice will be done.

The early days of Scamourai they claimed privacy even prior to having mixing in the product, with the product querying the blockchain.info api for the wallet balance. Blockchain logs would tell you exactly which addresses belonged to those early Scamourai users. And any criticism of their product always resulted in vicious personal attacks by Keonne. But anyway, ... nostr:nprofile1qqs8fl79rnpsz5x00xmvkvtd8g2u7ve2k2dr3lkfadyy4v24r4k3s4sh8dmel spoke the truth throughout the full video above. Scamourai screwed up and we still have to figure out how to bail them out or something.

Some knew. Apparently Samourai said that "only" 30% used the honeypot default dojo. That degraded massively the privacy of all that ran their own dojos and ... well nostr:nprofile1qqs8fl79rnpsz5x00xmvkvtd8g2u7ve2k2dr3lkfadyy4v24r4k3s4sh8dmel really said all there is to say in the video.

Him, myself and many others warned about the xpub issue and sure enough, Scamourai kept all the logs for the feds. So conveniently. And now they went to jail for 5 years, will probably come out early or something and the rest of us will have to live with this precedence.

Samourai devs are evil people. We have to #FreeSamourai anyway.

This video is fantastic at explaining why.

https://youtu.be/PrXhgn2XnKs?si=wzUk90S_f6hQU8BV

Elliptic Curve Cryptography - Schnorr signatures and ECDSA.

People will read this as "Bitcoin is safe at least another 20 years" yet coins get stolen when ECC breaks, not SHA256.

nostr:npub17u5dneh8qjp43ecfxr6u5e9sjamsmxyuekrg2nlxrrk6nj9rsyrqywt4tp proposed using bip32 for ownership proofs here already: https://groups.google.com/g/bitcoindev/c/uEaf4bj07rE/m/RMkPWnrSBwAJ

"allow recovery of legacy UTXOs through ZK proof of possession of BIP-39 seed phrase."

Given seed phrase to masterseed many expensive hashes, the solution is probably somewhere in between. Also I'm not sure about post quantum zero knowledge proofs.

My proposal is the caveman approach but it's certainly feasible for unfreezing coins if we freeze them in a panic fork. Users could then access their coins or wait for some future fork that can give them their coins and preserve their privacy.

Can't wait to see a standard emerge!

What Rabble did with divine - make legacy content available on the newcomer - is what will also drive a github replacement.

If github on nostr remains an add-on, it will fail. If I can find all projects on one (nostr enabled) tool regardless if hosted on codeberg, selfhosted gitea or github, we will win.

For me it's not about the perfect emulation of GitHub code reviews or AI integration. Discoverability is key to network effects.

"The bounty" is huge and I trust nostr:nprofile1qqsgydql3q4ka27d9wnlrmus4tvkrnc8ftc4h8h5fgyln54gl0a7dgsppemhxue69uhkummn9ekx7mp0qythwumn8ghj7un9d3shjtnswf5k6ctv9ehx2ap0qyt8wumn8ghj7un9d3shjtnddaehgu3wwp6kytc79p4zh will honor it if somebody delivers something serious. And discoverability to me would be the top metric. If self-hosted becomes an option for young devs building their portfolio, we win.

nostr:nevent1qqsfcxfkt9qj5ewdhryuhgdhn8wx74kk9pkkgtgeakx53nqhyhpknpcpz4mhxue69uhhyetvv9ujuerpd46hxtnfduhsygy6sdmeuaggq4tvv4k56svdq2jd0md79z9zl8nd626g0x0vjdgcfspsgqqqqqqsr6ap93

Backups in 5 relays are probably safer than on 2 relays and your hard drive. Just make sure it remains 5 over time.

Trying to figure out how nostr:npub1mftv2j67vayavkks8rqev3u8jjhefe86tf80msstfxvpunk9vmps6prkl3 works ...

I had an ad open since a year or so and now somebody contacted me on it. Our "common friend" is the mailbox number. WTH? Might this and maybe other numbers be worthy of black-listing for the purpose of friend-of-a-friend estimates?

Also, as a beginner I did not understand that this was the most important information I should have looked for given my ad was limited to "friends of friends". Maybe that "common friend" should be zero clicks away, not one?

With our Chilean provider it would show up on their website shortly and I wonder how they could do this otherwise, as people would bombard them with calls. Bet you found out eventually.

Networks matter.

How about: Bots can bootstrap the illusion of valuable networks. People in search of entering valuable networks will fall for these.

There are countries that do not honor IP laws. Iran for example. So it's probably not only IP but also actual trade secrets.

Oh, that got me thinking. At WalletScrutiny we dismiss deeper analysis of custodial products as the custodian has full control, thus it's on him to keep the funds safe but with eCash the custodian almost can't exercise any discretion to protect the user.

Let's say somebody would backdoor some popular eCash client to then trigger a "send all funds to me", what could a mint do about it? nostr:npub12rv5lskctqxxs2c8rf2zlzc7xx3qpvzs3w4etgemauy9thegr43sf485vg have there been any such considerations? Are there mints that would lock funds all of a sudden thousands of IPs would ask to send to the same address? As mints don't send to addresses but to invoices I doubt it would even be possible. The mint would simply detect a sudden surge in activity.

For WalletScrutiny that means that we either can treat eCash as worse than custodial (they can rug you but also cannot protect you against your wallet rugging you) or as "yeah, custodial but popular and vulnerable to both custodian and client, so we better scrutinize the wallets".

I don't see knots on https://bitnodes.io/dashboard/1y/

Nodes on .onion vs. IP:

.onion grew 26% while IP grew 13%.

Around 39% of the U.S. violent crime prison population is black. The rate of arrest for violent crimes is also 38% black. Might it be the US has a crime problem and not a particular black problem?

This case's offender clearly stood out many times but the stats matching tells me that there is no racial bias to keep black offenders out of prison.

Lastly, prison for life is unnecessarily expensive. Violent crime peaks at a young age and is barely committed by people aged 45 or older. To keep people locked away after 55 should really be reserved for actual murderers or otherwise very extreme cases.

So what are your policy suggestions? Pre-crime put away all blacks? Should we also put away all men that are also drastically over-represented in violent crime?

A thing I could get behind is to put away all gang members that are actually more over-represented among violent offenders than blacks or young men.

Lastly, the whole "put them away" thing is also very popular in the US already, so they are doing something wrong but it's certainly not that they don't put away enough people.

Replying to Avatar Kazani

WiFi signals can measure heart rate, no wearables needed

The Pulse-F system enables highly accurate, clinical-level heart rate monitoring using ultra-low-cost WiFi devices, making it useful for low-resource settings.The system works with the person in various positions and from up to 10 feet away, demonstrating its versatility and robustness.Heart rate is a crucial health indicator, providing insights into physical activity, stress, anxiety, hydration levels, and more.Traditional heart rate measurement requires wearables, but the Pulse-F system offers a non-intrusive alternative using household WiFi devices.The technology was developed by engineers at the University of California, Santa Cruz, and demonstrated using low-cost WiFi devices like ESP32 chips ($5-$10) and Raspberry Pi chips ($30).The system combines WiFi devices with a machine learning algorithm to distinguish even the faintest signal variations caused by a human heartbeat.Experiments with 118 participants showed that after only five seconds of signal processing, heart rate could be measured with clinical-level accuracy.The Pulse-F system performed accurately regardless of the equipment's position in the room or the participant's posture, including sitting, standing, lying down, or walking.The researchers created their own dataset to train the machine learning algorithm, as no existing data for these patterns using an ESP32 device was available.Future research aims to extend the technology to detect breathing rate in addition to heart rate, which can be useful for detecting conditions like sleep apnea.

https://news.ucsc.edu/2025/09/pulse-fi-wifi-heart-rate/

Cool but also creepy. They already can measure the pulse while walking? If that doesn't mean the sensor also knows about the walking I'd be surprised. How long before this can be used for even more spying into every home via the phones? Will youtube monitor my heart rate while watching clips to better detect what grabs my attention?

1. Spawn 101 accounts

2. Follow each other

3. Share this post

4. Profit