Épisodes

  • BR097 - Cove Wallet, Harbor, ecash, Sparrow, Liana, Bull Bitcoin, JoinMarket, Hardware Wallets, Coinbase Breach, BitLocker Vulnerability, Lightning Phoenixd, LSP Legality + MORE ft. Praveen, Ben, Paul
    Jun 5 2025
    I’m joined by guests Praveen Perera, Future Paul & Ben Carman to go through the list.

    Bitcoin
    • Software Releases & Project Updates
    (00:01:29) Cove Wallet
    (00:18:14) Harbor.cash
    (00:35:45) Sparrow Wallet
    (00:37:05) BDK bdk_chain
    (00:37:52) Liana
    (00:38:24) Nunchuk Android
    (00:39:02) Bull Bitcoin Mobile
    (00:40:39) Blue Wallet
    (00:41:00) Bitkey App
    (00:43:21) FullyNoded
    (00:44:03) Zaprite
    (00:45:43) BoltzExchange
    (00:45:46) Padawan Wallet
    (00:46:23) Blockstream Green Android
    (00:46:37) Samourai Dojo
    (00:46:49) ESP-Miner
    (00:46:51) NBXplorer
    (00:47:12) Mempal


    • Poject Spotlight
    (00:47:23) DahLIAS
    (00:48:25) Manna Bitcoin
    (00:48:34) Darkwire
    (00:48:44) Parasite Pool
    (00:48:55) Blockpicker
    (00:49:10) LOCK Protocol
    (00:49:17) Sigbash
    (00:49:38) Arkade OS
    (00:50:09) Swift Bitcoin
    (00:50:36) Pythia
    (00:50:45) Arcana Seed Lodge
    (00:50:54) BIP47 Message Verifier
    (00:51:02) Traxe
    (00:51:08) Censorship Resistant
    (00:51:21) Bitcoin-4-All

    Vulnerability Disclosures
    (00:51:38) Coinbase data breach
    (00:54:07) Ledger Donjon
    (00:54:46) CVE-2023-21563
    (00:55:59) Bitpixie

    Privacy & Other Related Bitcoin Projects
    • Software Releases & Project Updates
    (00:57:14) SimpleX
    (00:57:15) NomadNet
    (00:57:16) Sideband
    (00:57:17) Mullvad VPN Loader
    (00:58:17) Signal Desktop
    (00:58:20) Have I Been Pwned
    (00:58:22) KYCnot.me

    • Poject Spotlight
    (01:00:26) Oniux

    Lightning + L2+
    • Project Spotlight
    (01:00:39) Routstr
    (01:02:22) Lightning Blinder
    (01:02:32) Phoenixd MCP Server
    (01:03:27) Amboss Rails
    (01:03:48) Sixty Nuts
    (01:03:54) BTCNutServer


    Boosts
    (01:07:13) Shoutout to top boosters AVERAGE_GARY, hgw39, Rod Palmer, Chris, Hech, AVERAGE_GARY, Bob the Cow, Plunger & Homer Hodl.


    Links & Contacts:
    Website: https://bitcoin.review/
    Substack: https://substack.bitcoin.review/
    Twitter: https://twitter.com/bitcoinreviewhq
    NVK Twitter: https://twitter.com/nvk
    Telegram: https://t.me/BitcoinReviewPod
    Email: producer@coinkite.com
    Nostr & LN: ⚡nvk@nvk.org (not an email!)
    Full show notes: https://bitcoin.review/podcast/episode-97
    Afficher plus Afficher moins
    1 h et 13 min
  • BR096 - OP_RETURN Debate, Bitcoin Core Governance, Alternative Implementations, Future Soft Forks, CTV Prospects, Core Vulnerabilities, COLDCARD Hardware Design, Testnet vs Signet + MORE ft. Rob, Odell & Craig
    May 15 2025
    I'm joined by guests Rob Hamilton, Craig Raw & Matt Odell to go through the list.

    OP_RETURN Drama
    (00:00:52) Odell's thoughts
    (00:04:29) Craig's thoughts
    (00:05:59) NVK's thoughts
    (00:07:47) Rob's thoughts


    Bitcoin
    • Software Releases & Project Updates
    (00:22:10) COLDCARD
    (00:22:35) Cove Wallet
    (00:24:03) BTCPay Server
    (00:24:06) Nunchuk Android
    (00:24:12) Bitcoin Keeper
    (00:24:14) Bitcoin Safe
    (00:24:18) Wasabi Wallet
    (00:25:43) RoboSats
    (00:25:46) Umbrel
    (00:25:57) Zaprite
    (00:26:22) Blockstream Satellite
    (00:26:45) Stratum Work
    (00:26:58) SeedHammer II
    (00:27:11) ESP-Miner


    • Project Spotlight
    (00:27:34) Bitcoin Feature Matrix
    (00:27:41) secp256k1lab
    (00:28:00) GPGap
    (00:28:16) NVK Validation Tweet
    (00:28:54) BriberBrother
    (00:29:11) Stack Math


    Vulnerability Disclosures
    (00:30:23) CVE-2024-52919
    (00:33:02) CVE-2025-43707
    (00:34:46) Hackers breach LockBit


    Audience Questions
    (00:35:12) What’s the difference between test net and signet? And what are the benefits of each?
    (00:37:15) Can you explain, in simple terms, what OP_CHECKCONTRACTVERIFY does?

    Nostr
    • Software Releases & Project Updates
    (00:46:55) Nostr Messaging Layer Security
    (00:48:42) Primal
    (00:48:43) Damus

    Boosts
    (01:01:58) Shoutout to top boosters Rod Palmer, AVERAGE_GARY, pink money, user4, Wartime & btconboard

    Tech Tip of the Day
    (01:03:51) A free online cryptography course repository by Alfred Menezes

    Links & Contacts:
    Website: https://bitcoin.review/
    Substack: https://substack.bitcoin.review/
    Twitter: https://twitter.com/bitcoinreviewhq
    NVK Twitter: https://twitter.com/nvk
    Telegram: https://t.me/BitcoinReviewPod
    Email: producer@coinkite.com
    Nostr & LN: ⚡nvk@nvk.org (not an email!)
    Full show notes: https://bitcoin.review/podcast/episode-96
    Afficher plus Afficher moins
    1 h et 6 min
  • BR095 - OP_NEXT Recap, COLDCARD, Bitcoin Core, Ephemeral Dust, Ephemeral Anchors, Pay-to-Anchor outputs, Taplocks, Electrum, Cove Wallet, Mempool.space, Liana, Bitcoin Privacy Accounting, ESP32.Review + MORE ft. Rob & Rijndael
    Apr 23 2025
    I'm joined by guests Rob Hamilton & Rijndael to go through the list.

    Housekeeping
    (00:01:09) OP_Next recap


    Bitcoin
    • Software Releases & Project Updates
    (00:15:18) Coldcard
    (00:42:53) Bitcoin Core
    (00:47:21) BDK
    (00:48:12) Coinswap
    (00:48:56) Electrum Wallet
    (00:52:45) BTCPay Server
    (00:53:33) Nunchuk Android
    (00:54:04) Liana
    (00:54:51) The Mempool Open Source Project
    (00:57:01) BoltzExchange boltz-web-app
    (00:57:16) RoboSats
    (00:57:21) Bitcoin Safe
    (00:57:58) Blockstream Green
    (00:58:08) Rust Payjoin
    (01:01:15) Zaprite
    (01:01:48) Krux
    (01:02:29) Iris Wallet Desktop
    (01:02:46) Bitcoin Core Config Generator
    (01:02:52) UTXOracle


    • Project Spotlight
    (01:04:14) SwiftSync
    (01:04:43) PrivatePond
    (01:05:00) JoinMarket Fidelity Bond Simulator
    (01:05:52) DahLIAS
    (01:06:00) Satoshi Escrow
    (01:06:12) Taplocks
    (01:15:48) bitcoin.softforks.org
    (01:15:52) CTV and CSFS Enabled Bitcoin Node
    (01:16:03) UTXOscope
    (01:16:13) Block Bitcoin Treasury
    (01:16:47) Waye
    (01:17:08) Sovereign Craft


    (Not) a Vulnerability Disclosure
    (01:17:17) Pay-to-Anchor outputs now exploited for blockchain spam
    Audience Questions
    (01:23:46) How do we use open time stamps for transfer of assets using two party integrity between holders?
    (01:24:50) Does Cove have testnet4?
    (01:25:15) Can you explain like I’m 5 what opcodes are, how they are used on the network, and the level of optionality that applies to them?
    (01:26:49) Please discuss this idea: Block-based TOTP for bitcoin wallet passphrase validation.


    Privacy & Other Related Bitcoin Projects
    • Software Releases & Project Updates
    (01:28:48) Tor Browser
    (01:28:51) TailsOS
    (01:28:53) NymVPN
    (01:28:55) MapleAI


    Lightning + L2+
    • Project Spotlight
    (01:29:17) Misty Breez
    (01:29:25) Sovereign Tools
    (01:29:28) Silk Road on Lightning
    (01:29:37) Cashu Token Decoder


    • Software Releases & Project Updates
    (01:29:48) Zeus
    (01:29:49) LDK
    (01:31:40) Minibits Wallet
    (01:31:42) Hydrus


    Nostr
    • Project Spotlight
    (01:31:44) Atomic Signature Swaps over Nostr
    (01:31:51) Lantern
    (01:31:59) Promenade
    (01:32:09) Noauth-enclaved
    (01:32:27) GM Swap

    Boosts
    (01:33:04) Shoutout to top boosters Rod Palmer Bugle News, pink monkey, btconboard, jespada, AVERAGE_GARY & larryoshi finkamoto

    Links & Contacts:
    Website: https://bitcoin.review/
    Substack: https://substack.bitcoin.review/
    Twitter: https://twitter.com/bitcoinreviewhq
    NVK Twitter: https://twitter.com/nvk
    Telegram: https://t.me/BitcoinReviewPod
    Email: producer@coinkite.com
    Nostr & LN: ⚡nvk@nvk.org (not an email!)
    Full show notes: https://bitcoin.review/podcast/episode-95
    Afficher plus Afficher moins
    1 h et 37 min
  • BR094 - COLDCARD KeyTeleport, Harbor, Ark, Cove Wallet, Zaprite, Bitcoin Core, OMEMO, Knots, Vibe Coding, Trezor Safe 3 Attack Vector, Coinbase Phishing Campaign, Bitcoin Business Software + MORE ft. Rob & Paul
    Apr 2 2025
    I'm joined by guests Rob Hamilton & Future Paul to go through the list.

    Housekeeping
    (00:01:09) Nostr DVM Playground
    (00:26:33) Bitcoin Security Guide
    (00:27:23) TestFlight need more beta testers for Cove
    (00:33:19) COLDCARD Key Teleport


    Urgent Vulnerability Disclosures
    (00:29:04) A new email phishing campaign targets Coinbase users

    Bitcoin
    • Software Releases & Project Updates
    (00:44:33) Bitcoin Core
    (00:45:52) Fulcrum
    (00:46:06) Blue Wallet
    (00:46:27) Bitcoin Safe

    Interlude
    (00:48:54) OMEMO

    Bitcoin
    • Software Releases & Project Updates (Cont.)
    (00:53:28) Bitcoin Knots
    (00:53:59) BoltzExchange
    (00:54:01) Blockstream Green QT
    (00:54:58) FullyNoded
    (00:55:11) BullBitcoin Mobile
    (00:55:19) RoboSats
    (00:55:24) Bisq 2
    (00:55:26) Zaprite
    (00:56:38) Bitcoin Jungle App
    (00:57:22) SRI
    (00:57:57) Stratum.work
    (00:58:46) Braiins OS
    (00:58:50) Coinselect

    Privacy & Other Related Bitcoin Projects
    • Software Releases & Project Updates
    (01:18:13) Sideband
    (01:18:23) Mullvad VPN
    (01:18:33) NymVPN Noise Generating Mixnet technology

    Vulnerability Disclosures
    (01:18:42) Ledger Donjon conducts a security analysis of Trezor's hardware wallets

    Interlude
    (01:21:05) Coinbase is open-sourcing their multiparty computation cryptography library
    (01:21:35) Mempool.space now supports address poisoning detection

    Lightning + L2+
    • Software Releases & Project Updates
    (01:22:46) LDK

    Boosts
    (01:26:33) Shoutout to top boosters pink monkey, Anonymous, jespada, ., btconboard, AVERAGE_GARY & alanStacksSats.

    Links & Contacts:
    Website: https://bitcoin.review/
    Substack: https://substack.bitcoin.review/
    Twitter: https://twitter.com/bitcoinreviewhq
    NVK Twitter: https://twitter.com/nvk
    Telegram: https://t.me/BitcoinReviewPod
    Email: producer@coinkite.com
    Nostr & LN: ⚡nvk@nvk.org (not an email!)
    Full show notes: https://bitcoin.review/podcast/episode-94
    Afficher plus Afficher moins
    1 h et 29 min
  • BR093 - ECDSA Key Extraction, ESP32 Security Concerns, COLDCARD, Cove Wallet, Krux, Nunchuk, Invalid Mining Jobs, Javascript Injection Attack, CTV Back on the table? + MORE ft. Rob & Vivek
    Mar 13 2025
    I'm joined by guests Rob Hamilton & Vivek to go through the list.

    Housekeeping
    (00:01:18) Unleashed.chat rebrands to dataMachine


    Urgent Vulnerability Disclosures
    (00:01:52) Private key leak via malformed ECDSA input
    (00:09:12) ESP32 Security Concerns
    (00:21:32) Coinos revokes NWC connection secrets

    Vivek's Corner
    (00:22:51) Invalid mining jobs by AntPool & friends during forks

    Bitcoin
    • Software Releases & Project Updates
    (00:37:44) COLDCARD
    (00:52:47) Sparrow Wallet
    (00:54:33) Lark
    (00:55:03) Krux
    (00:56:37) Cove Wallet
    (00:59:09) Nunchuk Desktop
    (01:00:32) BTCPayServer
    (01:00:44) Bitcoin Keeper
    (01:01:25) BlueWallet
    (01:02:08) Bitcoin Safe
    (01:03:15) Bitkey App
    (01:04:05) libwally-core
    (01:06:00) Bisq2
    (01:06:04) RoboSats
    (01:06:08) Boltz Exchange
    (01:06:10) Zaprite
    (01:06:13) Blockstream Explorer API
    (01:07:22) Mempal
    (01:07:29) Iris Wallet desktop
    (01:07:31) Utreexo
    (01:07:34) ESP Miner


    • Project Spotlight
    (01:07:38) Reorg Calculator
    (01:07:51) Bitcoin Core Config Generator
    (01:09:05) Bitcoin Core Snapshots
    (01:09:11) Boot Protocol
    (01:09:18) multisig-backup
    (01:09:58) Wallet backup
    (01:10:04) regtest-in-a-pod


    Vulnerability Disclosures
    (01:11:56) JavaScript injection attack
    (01:15:05) Malicious PyPI package 'set-utils' steals Ethereum private keys
    (01:16:57) OpenSSH vulnerabilities expose clients and servers to attacks
    (01:17:05) USB side-channel attacks
    (01:17:37) Cellebrite
    (01:17:49) Messengers vulnerabilities
    (01:17:56) GitVenom
    (01:18:10) Stablecoin payment firm Infini loses $50M in exploit
    (01:18:18) Five dollar wrench attacks
    Audience Questions
    (01:20:00) Comment on a flaw in Bitcoin Core regarding mining pools and their vulnerability against block withholding attacks

    Nostr
    • Project spotlight
    (01:22:32) 24242.io
    (01:22:49) nostr.media
    (01:22:58) Frostr
    (01:23:33) nostr-double-ratchet
    (01:23:44) DVMCP
    (01:23:53) Samiz
    (01:24:00) Welshman
    (01:24:09) Norma
    (01:24:20) Wallet Relay
    (01:24:27) Nostr0
    (01:24:35) nAuth Protocol
    (01:24:43) Hostr


    Boosts
    (01:25:36) Shoutout to top boosters @sean, @pink monkey, @Anonymous, @martinbarilik, @Momo Tahmasbi & @jespada.

    Links & Contacts:
    Website: https://bitcoin.review/
    Substack: https://substack.bitcoin.review/
    Twitter: https://twitter.com/bitcoinreviewhq
    NVK Twitter: https://twitter.com/nvk
    Telegram: https://t.me/BitcoinReviewPod
    Email: producer@coinkite.com
    Nostr & LN: ⚡nvk@nvk.org (not an email!)
    Full show notes: https://bitcoin.review/podcast/episode-93
    Afficher plus Afficher moins
    1 h et 28 min
  • BR092 - Nostr Wallet Connect, DeepSeek, AI Coding, Sparrow, Bitcoin Keeper, Maple AI, Calculating Tx Sizes + MORE ft. Future Paul
    Feb 11 2025
    I'm joined by guest Future Paul to go through the list.

    Prelude to the list
    (00:01:00) Conversation on AI and building with AI


    Housekeeping
    (00:22:02) New Coldcard Q tutorial by Loïc Morel
    (00:22:10) Looking for bitcoin builders to come on the show
    (00:23:13) Unleashed.Chat Update
    (00:23:19) NWC and Olas/Primal
    Urgent Vulnerability Disclosures
    (00:37:17) Replacement Cycling Attacks on Bitcoin Miners Block Templates

    Bitcoin
    • Software Releases & Project Updates
    (00:37:34) Sparrow Wallet
    (00:41:08) BDK
    (00:41:35) Bitcoin Keeper
    (00:42:40) Wasabi Wallet
    (00:42:43) Blockstream
    (00:43:06) Electrs
    (00:43:44) Umbrel
    (00:44:29) Bisq
    (00:44:40) Bisq2
    (00:44:51) Zaprite
    (00:45:54) Mempal
    (00:46:04) Bitcoin Safe
    (00:48:50) ESP Miner


    • Project Spotlight
    (00:49:02) cbip32
    (00:49:15) StackStates
    (00:49:21) Instamouse bitcoin
    (00:50:24) Iris Wallet Desktop
    (00:50:43) Explorer.timechainindex
    (00:50:54) txTree
    (00:50:58) HurriCash
    (00:51:29) The Bitcoin Trail
    (00:51:41) Bitcoin Laws
    (00:51:50) CoinMarketCrap


    Vulnerability Disclosures
    (00:54:19) Researchers uncover two security flawsin Apple's A and M-series chips
    (00:54:33) Kaspersky identifies malware in both Google Play and Apple's App Store
    (00:54:40) Exploit targets users on adult sites via Phantom or Trust Wallet browser
    (00:56:30) Lazarus Group deploys electron-based malware to steal cryptocurrency data
    (00:56:36) Coinbase users lose millions to social engineering scams amid security failures
    (00:56:57) Phemex suffers $85 million hack
    (00:57:56) NoOnes suffers $8 million exploit due to Solana bridge vulnerability
    (00:58:40) Deepseek exposes over a million plaintext chat records
    (00:58:16) Five dollars wrench attacks


    Audience Questions
    (01:00:55) Why, when you sign a transaction on the COLDCARD, does it generate 2 files?
    (01:01:50) P1: What's the maximum number of outputs there can be for a bitcoin transaction?
    (01:03:43) P2: Is there any way to estimate what the size that a transaction will be depending on it's number of outputs?
    (01:04:13) Does using a passphrase offer any protection against a malicious hardware wallet?


    Privacy & Other Related Bitcoin Projects
    • Software Releases & Project Updates
    (01:06:10) Maple AI
    (01:06:20) SimpleX
    (01:11:00) TailsOS
    (01:13:24) Reticulum MeshChat
    (01:25:26) Mullvad VPN


    Lightning + L2+
    • Project spotlight
    (01:26:17) Ark Wallet SDK


    Boosts
    (01:26:35) Shoutout to top boosters Anonymous & AVERAGE_GARY

    Links & Contacts:
    Website: https://bitcoin.review/
    Substack: https://substack.bitcoin.review/
    Twitter: https://twitter.com/bitcoinreviewhq
    NVK Twitter: https://twitter.com/nvk
    Telegram: https://t.me/BitcoinReviewPod
    Email: producer@coinkite.com
    Nostr & LN: ⚡nvk@nvk.org (not an email!)
    Full show notes: https://bitcoin.review/podcast/episode-92
    Afficher plus Afficher moins
    1 h et 29 min
  • BR091 - AnchorWatch Trident Vault, Ledger Co-founder Kidnapped, Blue Wallet, M17, The Case for Multi-vendor Setups, Tails removes HWW Support + MORE ft. Craig & Rob
    Jan 24 2025
    I'm joined by guests Craig Raw and Rob Hamilton to go through the list.

    Housekeeping
    (00:01:11) Ross Ulbricht receives a pardon from President Trump
    (00:03:44) New Marketing Manager opening at Coinkite
    (00:03:48) Exchanges added to BitcoinSecurity.guide
    (00:04:15) Olas - new nostr app
    (00:04:48) Call for guests


    Urgent Vulnerability Disclosures
    (00:05:58) Ledger co-founder David Balland released after kidnapping
    (00:12:28) AxeOS CSRF Vulnerability

    Bitcoin
    • Software Releases & Project Updates
    (00:12:58) AnchorWatch
    (00:47:28) Bitcoin Core
    (00:48:10) Wasabi Wallet
    (00:48:15) BDK
    (00:48:27) Nunchuk Android
    (00:48:37) Specter Desktop
    (00:49:02) Bitcoin Keeper
    (00:49:18) Blue Wallet
    (00:50:32) BTC Pay Server
    (00:55:39) Liana
    (00:55:58) Blockstream Green QT
    (00:57:58) BoltzExchange
    (00:58:00) Live Wallet
    (00:58:11) Kyoto
    (00:58:19) ESP-Miner
    (00:58:21) Bitcoin Safe
    (00:58:40) BTC Map


    • Project Spotlight
    (00:58:44) Bitaxe Touch
    (00:58:51) Coinswap
    (00:59:20) Scure
    (00:59:28) Bitcoin Is Data
    (00:59:43) Qoinstr
    (00:59:53) TollGate


    Vulnerability Disclosures
    (01:01:27) 0-click deanonymization attack targets Cloudflare-backed apps
    (01:02:00) UEFI secure boot vulnerability allows malicious bootkit deployment
    (01:02:23) Google Ad directs users to malicious homebrew clone
    (01:03:01) Critical rsync vulnerability on Linux and Unix systems
    (01:03:31) January 2025 Patch Tuesday
    (01:03:48) Unsecured tunneling protocols expose 4.2 million hosts
    (01:03:58) Apple's CUPS printing system vulnerable to spoofing attacks
    (01:04:11) Thomas Roth demonstrates code execution on Apple's ACE3 USB-C controller
    (01:05:32) Five dollar wrench attacks

    Privacy & Other Related Bitcoin Projects
    • Software Releases & Project Updates
    (01:07:17) Tails
    (01:09:52) Module_17

    Boosts
    (01:12:29) Shoutout to top boosters Anonymous, manbyt, agichoote & btconboard

    Links & Contacts:
    Website: https://bitcoin.review/
    Substack: https://substack.bitcoin.review/
    Twitter: https://twitter.com/bitcoinreviewhq
    NVK Twitter: https://twitter.com/nvk
    Telegram: https://t.me/BitcoinReviewPod
    Email: producer@coinkite.com
    Nostr & LN: ⚡nvk@nvk.org (not an email!)
    Full show notes: https://bitcoin.review/podcast/episode-91
    Afficher plus Afficher moins
    1 h et 16 min
  • BR090 - COLDCARD, BullBitcoin, Bitcoin Safe, miningpool-observer, Zero Fee/P2PK Playgrounds, Tangem Private Keys Exposed, Proton Wallet Vuln, Signatures Explained, "Not Enough UTXOs!" + MORE ft. Rob
    Jan 3 2025

    I'm joined by guest Rob Hamilton to go through the list.

    (Timecodes coming soon)

    Links & Contacts:
    Website: https://bitcoin.review/
    Substack: https://substack.bitcoin.review/
    Twitter: https://twitter.com/bitcoinreviewhq
    NVK Twitter: https://twitter.com/nvk
    Telegram: https://t.me/BitcoinReviewPod
    Email: producer@coinkite.com
    Nostr & LN: ⚡nvk@nvk.org (not an email!)
    Full show notes: https://bitcoin.review/podcast/episode-90

    Afficher plus Afficher moins
    1 h et 23 min