Sparrow Wallet v2.1.3 includes BIP329 wallet labels export to include additional fields. 🚀
@BLUESKY , @Rob Hamilton and @Seardsalmon discuss the update... and why bullying is an indispensible tool for getting devs like @craigraw to implement your desired features! [BR093]
Bitcoin.Review
_@bitcoin.review
npub1qdca...zclt
A Podcast and Newsletter review of Bitcoin Software updates and related topics with NVK and guests.
BDK abstracts wallet dev complexity, making it accessible for all.
@BLUESKY : "It'll be the default in a few years."
@Rob Hamilton : "Even a left curve like me can build safely."
With v1.1.0, the future of wallet development is more promising than ever. 🦾
Bitcoin Safe v1.1.0 is here:
✅ Jade wallet support
✅ Deb build
✅ Xpub import
@BLUESKY and @Rob Hamilton discuss the project's progress, whilst also highlighting privacy concerns over using #nostr for multisig coordination. [BR093]
Multisig backup, rethought. 🔐
By encrypting & inscribing your k-of-n descriptor, you can recover with any k seeds—no need for redundant backups.
@BLUESKY & @Rob Hamilton discuss the recently released (and open source) multisig-backup project in BR093.
Is ESP32 really safe for securing #Bitcoin?
Undocumented commands in ESP32 Bluetooth chip have recently raised security concerns, adding to existing risks. 🚨
@BLUESKY , @Rob Hamilton , and @Seardsalmon sound the alarm in BR093.
Block explorers are evolving. 🚀
Blockstream now offers dedicated API endpoints.
Should devs embrace managed infrastructure, or is self-hosting still king? @BLUESKY , @Rob Hamilton & @Seardsalmon weigh in on BR093.
The latest @nunchuk_io for desktop & Android is here 🚀
✅ Standard & taproot multisig
✅ Single-file recovery using wallet descriptors
✅ E2E encrypted chats
All written in native C - (no JavaScript touching your keys!)
@BLUESKY , @Seardsalmon & @Rob Hamilton break it down in BR093.
Jam: A web interface for JoinMarket.
@BLUESKY , @Rob Hamilton and @Paul
discuss the project, and why it is:
✅ The best way to mix coins
✅ Free from centralized control
✅ Less likely to be a point of capture
[BR077]
Are dice rolls the answer to bad entropy?
@BLUESKY breaks down why secure elements use TRNGs, why mixing entropy matters, and why relying on a camera for randomness is pure “camera theater.”
🎲 Humans are bad at entropy.
🔐 Trust, verify, XOR.
[BR077]
🚀 BR093 - ECDSA Key Extraction, ESP32 Security Concerns, COLDCARD, Cove Wallet, Krux, Nunchuk, Invalid Mining Jobs, Javascript Injection Attack, CTV Back on the table? + MORE ft. @Rob Hamilton , @Seardsalmon & @BLUESKY
Listen to the episode:
➡️ Fountain: https://fountain.fm/episode/as8n9iw9VbKhMCyrjjjv
➡️ Spotify:
➡️ Amazon:
➡️ Apple:
➡️ YouTube:
Shownotes:
➡️ Website:
➡️ Substack:
🚨 ESP32 and Bluetooth security concerns. Is there a place for these technologies when it comes to #Bitcoin? NVK and Rob tackle this question. 👇
Spotify
BR093 - ECDSA Key Extraction, ESP32 Security Concerns, COLDCARD, Cove Wallet, Krux, Nunchuk, Invalid Mining Jobs, Javascript Injection Attack, CTV Back on the table? + MORE ft. Rob & Vivek
Bitcoin.Review Podcast with NVK & Guests · Episode
BR093 - ECDSA Key Extraction, ESP32 Security Concerns, COLDCARD, Cove Wallet, Krux, Nunchuk, Invalid Mining Jobs, Javascript Injection Attack, CTV Back on the table? + MORE ft. Rob & Vivek | Bitcoin.Review Podcast with NVK & Guests Episode on Amazon Music
I'm joined by guests Rob Hamilton & Vivek to go through the list.Housekeeping (00:01:18) Unleashed.chat rebrands to dataMachineUrgent Vulnerability...
Apple Podcasts
BR093 - ECDSA Key Extraction, ESP32 Security Concerns, COLDCARD, Cove Wallet, Krux, Nunchuk, Invalid Mining Jobs, Javascript Injection Attack, CTV Back on the table? + MORE ft. Rob & Vivek
Podcast Episode · Bitcoin.Review Podcast with NVK & Guests · 13 March 2025 · 1hr 28min

🎙Bitcoin.Review Podcast
Bitcoin Review Podcast BR093 - ECDSA Key Extraction, ESP32 Security Concerns, COLDCARD, Cove Wallet, Krux, Nunchuk, Invalid Mining Jobs, Javascript Injection Attack, CTV Back on the table? + MORE ft. Rob & Vivek
I’m joined by guests Rob Hamilton & Vivek to go through the list.

BR093 - ECDSA Key Extraction, ESP32 Security Concerns, COLDCARD, Cove Wallet, Krux, Nunchuk, Invalid Mining Jobs, Javascript Injection Attack, CTV Back on the table? + MORE ft. Rob & Vivek
I’m joined by guests Rob Hamilton & Vivek to go through the list.
From emergency comms to #cashu Over MeshTastic 🥜
@BLUESKY , @Rob Hamilton & @Paul discuss using MeshTastic for off-grid communication. Find out how in BR077.
"Hardware wallets are the best thing since sliced bread" 🍞
Although some try to trivialise hardware wallets, they offer asymmetric power for #Bitcoin security.
@Rob Hamilton and @BLUESKY discuss the risks of underestimating these tools in BR076.
Bitcoin security is at military levels - available to everyone. 🛡️🔐
Unfortunately, FUDsters still try to scare users away.
@BLUESKY & @Rob Hamilton discuss the rapid evolution of multisig, UX leaps in security, and why hardware wallets (even bad ones) are a massive net positive. [BR076]
From gaming the system to true discovery 🎯
Some creators struggle with #nostr’s lack of an algorithm - no easy way to game the system. But in return, it offers true organic virality.
Could this model outperform today's platforms? @jb55 shares his take in BR078.
Zaps are a game-changer. ⚡️
Public payments with built-in social signaling—something we've never had before. Could this be the catalyst that onboards the world to #Bitcoin?
@miljan explains why every app is about to be Bitcoin-enabled in BR083.
Zaps on nostr have yet to reach their final form.
@PABLOF7z sees Zaps as just the start—unlocking new use cases and infinite possibilities. Cashu-based Zaps? More speed, more verification, more potential. ⚡
[BR083]