calle
calle@cashu.me
npub12rv5...85vg
DM @callebtc:matrix.org
@tacobell has an npub omfg
cashu .me is now fully integrated with the latest version of npub .cash – that means your lightning address now works across all mints
settings -> Lightning address -> choose your mint
thank you @Egge


nuts on the radio
View quoted note →
gained a ton of new insights working in bitcoin red team 🟥 that i wish i could share without vague posting. but this is what i got anon.
- we’re experiencing a massive collision between decades of human open source slop against 2 weeks of kimi k3 (not good)
- everything is broken, bitcoin is burning
- bitcoin is becoming stronger through this
- bitcoin is the obvious first target but the rest of the world will follow shortly
- sometimes old things need to burn so new things can grow on healthy soil
- humans should never code in c (just stop)
- lightning is complicated and is more broken than the average (sorry)
- verification is free. we used to complain about slop PRs. then about slop security audits. if you can’t handle the information overload, stop complaining and use AI to sort through it.
- those projects that started AI audits months ago are in a completely different position than those who didn’t
- projects need their own AI audit pipeline going into the future
- the burden for a developer to keep software safe and secure is pretty stressful and not for everyone. it has become a lot more stressful now.
- unmaintained projects are most probably broken, don’t rely on them. i’d rather one-shot it myself with a modern AI
- multiple concurrent, diverse human approaches have proven to be the best vulnerability search method
- external red teaming will probably have to continue forever
- we’ve basically completed a basic scan of virtually the entirety of bitcoin open source. the low hanging fruit is done.
- we’ve reported a ton of real critical and high vulnerabilities. project maintainers across the board have validated our findings.
- response speed is very different across projects and shows how healthy each project is. i recommend acting fast these days.
- red team etiquette matters. if you don’t disclose responsibly, boast on twitter about your findings on a particular project, or make indications about the nature of particular findings, you’ve disqualified yourself as a serious security researcher. trust is the most important factor in this game. if you lose it, it’s very hard to win it back.
- did i mention that humans should not code in c?
Say It — private, local text-to-speech for macOS
Open models 100% on-device, speak text from any app with a hotkey, and even clone your own voice.
Infinite voices. Free & open-source.
Listen to the video 🔊
Download for macOS:
This is my contribution to the war against paid apps that should be free. I hope you enjoy it!
Leave a star on GitHub ⭐️ PRs are welcome!


SayIt — Private, local text-to-speech for Mac
Open TTS models, running entirely on your Mac. Select text anywhere, press a hotkey, listen.
GitHub
GitHub - callebtc/sayit: Private, local text-to-speech for Apple silicon Macs
Private, local text-to-speech for Apple silicon Macs - callebtc/sayit
dickbutt.jpg
|
|
3 yrs later
|
|
V
luke dashjr
becomes a
shitcoiner
🚩 Bitcoin Red Team Update
We're continuing a large-scale security review of the Bitcoin open-source ecosystem.
25 Bitcoin developers around the world have been working on this task non-stop for 108 hours.
We scanned 501 projects and produced 7,958 findings, of which 1,280 are rated high or critical (H+C) severity.
Our goal is to provide the most useful information. Based on feedback from maintainers, we've recalibrated our severity ratings and are now stricter about what we classify as H+C.
The share of all findings rated H+C increased to 16.2%, and the share of findings with a reproducible proof of concept increased to 24.7%.
That means our accuracy is improving.
As we harvest the low-hanging fruit, we're now focusing on improving harnesses, deploying better cyber-capable models, and probing more sophisticated attacks.
Our AI spend remains consistently high.
Our cumulative spend has passed $58K as we add more inference sources. Notably, we've started using cyber models from OpenAI and Anthropic.
These models are producing incredible results, but the vast majority of our spend (74%) still goes to Kimi K3.
Kimi K3 remains the top choice among our hunters, but we've also seen a significant increase in the use of Qwen 3.8 over the past few days.
Our goal is to strengthen the Bitcoin ecosystem and increase the resilience of our infrastructure in the age of AI.
To achieve this, we're conducting the largest red-teaming campaign in Bitcoin's history.
As a Bitcoiner, I am immensely proud of this.
We're sharing all our findings with developers for free.
This would not have been possible without the generous support of organizations like @OpenSats and donors like @FPuklowski and @vik sharma.
You can help keep the Red Team alive by donating to the OpenSats Red Team Fund here:
Last but not least, our reporting rate is picking up. Thanks to our outreach team, we've reported 29.4% of our findings so far.
We're also rolling out new infrastructure to deliver these findings to projects more quickly and securely, while improving how we incorporate feedback.
Stay tuned!

We scanned 501 projects and produced 7,958 findings, of which 1,280 are rated high or critical (H+C) severity.
Our goal is to provide the most useful information. Based on feedback from maintainers, we've recalibrated our severity ratings and are now stricter about what we classify as H+C.
The share of all findings rated H+C increased to 16.2%, and the share of findings with a reproducible proof of concept increased to 24.7%.
That means our accuracy is improving.
As we harvest the low-hanging fruit, we're now focusing on improving harnesses, deploying better cyber-capable models, and probing more sophisticated attacks.
Our AI spend remains consistently high.
Our cumulative spend has passed $58K as we add more inference sources. Notably, we've started using cyber models from OpenAI and Anthropic.
These models are producing incredible results, but the vast majority of our spend (74%) still goes to Kimi K3.
Kimi K3 remains the top choice among our hunters, but we've also seen a significant increase in the use of Qwen 3.8 over the past few days.
Our goal is to strengthen the Bitcoin ecosystem and increase the resilience of our infrastructure in the age of AI.
To achieve this, we're conducting the largest red-teaming campaign in Bitcoin's history.
As a Bitcoiner, I am immensely proud of this.
We're sharing all our findings with developers for free.
This would not have been possible without the generous support of organizations like @OpenSats and donors like @FPuklowski and @vik sharma.
You can help keep the Red Team alive by donating to the OpenSats Red Team Fund here: 
OpenSats
Red Team Fund - OpenSats
Funding for people red teaming Bitcoin software.

it's finally over!
the bip110 cancer is finally removed from bitcoin!
what a massively inconsequential waste of time!


fork off
gg

gm


🚨🚨 URGENT: BTCPAYSERVER 🚨🚨
There is a critical vulnerability that is being actively exploited on BTCPay Server which can lead to loss of funds.
Update your BTCPayServer to to 2.4.2 or turn off your BTCPayServer now.
🚩 Bitcoin Red Team update 55 hours into the campaign
We're now 24 people working around the clock.
We've scanned 425 projects so far and have produced 1029 high+critical (H+C) findings.
We generated 6700 findings so far and are hitting 7.7 projects per hour.
Our H+C rate per person per hour is back at ~1 as we work off a massive backlog and as the team grows and naturally divides up roles.
We have hunters, wizards, outreachers, sugar daddies, and gigglers.
Our H+C ratio is at 15.4% of all findings, increased by a percentage point compared to yesterday.
This is great, our accuracy is stable, and even slightly increasing. We're trying out best to reproduce all critical findings in local regtests before reporting them to projects.
Our biggest bottleneck is outreach. Most projects don't have a SECURITY .md in their repos (19.5%). Only 13.1% have an email in there.
We're working on better ways to reach folks. In the mean time, the best thing you can do as a project maintainer is to leave an email address in your repo.
Thank you to the sponsors and donors who cover the costs of this campaign and help to keep it alive.
Specifically @OpenSats, FPuklowski, @vik sharma, and everyone who has donated to OpenSats Red.
An incredible team of some of the most hard core Bitcoiners I know have assembled and dedicated their last days to this effort.
We've seen shit.
I don't want to reveal anyone personally, they can choose to do that themselves, but I think the way that people came together to join forces was and still is the most beautiful part about this entire program.
It makes me very hopeful, seeing so many people step up and give their time and energy to Bitcoin, especially during times of pain.
We're not done yet.

We generated 6700 findings so far and are hitting 7.7 projects per hour.
Our H+C rate per person per hour is back at ~1 as we work off a massive backlog and as the team grows and naturally divides up roles.
We have hunters, wizards, outreachers, sugar daddies, and gigglers.

Our biggest bottleneck is outreach. Most projects don't have a SECURITY .md in their repos (19.5%). Only 13.1% have an email in there.
We're working on better ways to reach folks. In the mean time, the best thing you can do as a project maintainer is to leave an email address in your repo.
Thank you to the sponsors and donors who cover the costs of this campaign and help to keep it alive.
Specifically @OpenSats, FPuklowski, @vik sharma, and everyone who has donated to OpenSats Red.

OpenSats
Red Team Fund - OpenSats
Funding for people red teaming Bitcoin software.

hi


