Lyudmyla Kozlovska's avatar
Lyudmyla Kozlovska
lyuda_ODF@BitcoinNostr.com
npub13ajk...2yd9
President of the Open Dialogue Foundation, founder of BTC Coalition in the EU Support our advocacy for #freedomtech : donate@bps.odfoundation.eu
Important update on Revolut, and why this concerns anyone here whose data sits with a KYC'd service, exchange or fiat on-ramp: (1) According to the group now extorting #Revolut, and the Duel team in contact with them, the attackers took over Italian government and law enforcement mailboxes with an infostealer, sent Revolut Bank UAB in Lithuania a forged European Investigation Order in the name of the Italian authorities, and kept sending requests for five months. (2) Revolut answered every one, as #FATF Recommendations and EU AML laws require. Refusal carries fines up to €5 million or 10% of turnover. Nothing in the rules obliges the bank to check whether the state behind the request is who it claims to be. Now scale this abuse a thousand times, in the hands of authoritarian states and their proxies, who do not seek attention like these hackers and quietly collect data on citizens and entities of the #EU and other Western countries. (3) The attackers claim to hold 147 GB from the #Italian side, including internal documents and officer chat logs, and say most of the Revolut data concerns customers in #Switzerland, #France and #Hungary, with other countries affected. Passports and #KYC selfies of named individuals are being published daily until Revolut pays. Every bank, exchange, payment provider and #CASP in every jurisdiction that follows FATF rules is exposed the same way, because the rules oblige them to answer state requests and nobody is required to check whether the state behind the request is legitimate. Self-hosted wallets close one door. The moment your data touches a regulated intermediary the same channel opens. Human rights groups, victims and experts, with support of Open Dialogue Foundation, described this risk to the European Parliament three years ago with support of @jack @npub1kp7j...487l and few other bitcoiners. We proposed specific remedies, supported by the majority of the European Parliament. The European Commission and the Council removed every safeguard the Parliament adopted from the AML Regulation. That decision is why this is happening now. Three institutions have since named this transnational financial repression: (1) European Parliament resolution of 18 June 2026, under MEP Hannah Neumann leadership; (2) Council of Europe Resolution 2669 of 25 June 2026, rapporteur MP Efstathiou, with MP Wiechel pushing for an investigation and remedies; (3) OSCE PA in The Hague, July 2026, led by MP Mauro Del Barbe, with the most detailed focus on exactly these attacks. We are collecting witness statements to push for implementation. If you are a legal or security expert and want to support our work, DM me. You want fewer surveillance channels open on you? The political fight decides which safeguards go back into the law. Support the MPs and MEPs who pushed for remedies. Demand accountability from Commission and Council for the ones they rejected. Before the next leak names someone who does not have the means to move house. image
This week #Revolut confirmed it handed over customers' passports, verification selfies, home addresses, IBANs and full transaction histories, including #Bitcoin, to a fake government request. The email came from a real government agency's domain, and Revolut complied because the rules told it to. #FATF rules, transposed into #US, #EU and #UK law, oblige every regulated institution to keep this data and hand it over promptly to any state request, with fines in the millions for delay and none for handing over too much. Nobody is required to check whether the state behind the request is legitimate. Any exchange, on-ramp or card issuer you use sits under the same rules. Authoritarian states and their proxies have used these requests for years against critics, donors and businesses. We call it transnational financial repression. This time it reached bitcoiners at scale. Since 2022 the Open Dialogue Foundation has campaigned before EU regulators for the privacy of payments and asked the Bitcoin industry to join. We were grateful for the support of @jack , @npub1kp7j...487l and a few other bitcoiners. Most others laughed, saying we are losing time or it was not their business. In 2023 we won a majority in the European Parliament for our safeguards. The closed-door trilogue then removed most of them from the AML Regulation. We did not have enough loud voices from the industry to defend payment privacy, and now not only activists, but also bitcoiners, business people, donors - we all face the hunting of our data at scale. There is still a chance. In July 2026 OSCE Parliamentary Assembly parliamentarians adopted remedies against the weaponisation of AML/CFT laws and recognised transnational financial repression as a threat to the security of the OSCE area, which covers the US, Canada, Europe and Central Asia. This would have been impossible without the support of Atlas Network, @npub1elww...ctu9 and the Reynolds Foundation (@npub1hkt8...ltpw ), who understood the problem at first sight. Will you keep observing and complaining, or join and make this space safe to use, invest and build in? There is nowhere else to run, if you understand how FATF rules work. If you don’t - happy to explain. Privacy has to be protected and normalised as a human right. Now, before it is too late.
Your Identity for Sale. Protect it NOW! For the last decade, governments across the world have followed Financial Action Task Force (FATF)'s mantra: we need full transparency and to identify everyone for security, for "better protection". This statement has not only proven to be a great failure, but it has now become the main weapon against western society and its governments themselves. On Aug. 31, Brian Krebs reported that a new service on the Russian cybercrime forum Exploit was offering access to digital scans of identity documents on more than 153 million people in North America. The FBI's New Orleans field office has launched an official investigation. How did more than 153 million identity documents from people in the United States and Canada end up in the hands of cybercriminals selling them on the dark web? Based on Krebs's interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by idscan.net, a widely-used identity verification company based in Louisiana that processes over 21 million verifications monthly at more than 20,000 locations, serving clients including Hertz, Target, FedEx, and Caesars Entertainment. The data had been continuously exfiltrated for over a year before it was discovered. For me this is also personal. As someone who has been subjected to the weaponisation of cybersecurity and financial laws by an authoritarian regime for my human rights work seeking to obtain my travel, financial, and communication data across the EU and the U.S., I know exactly what this kind of breach enables. Travel records, financial histories, and communication metadata are the most sought-after information for physical, economic, or digital attacks by authoritarian regimes and their proxies - we call it transnational financial repression. And I'm endlessly grateful for Mauro Del Barba, Markus Wiechel, Hannah Neumann for leading and pushing for clear remedies against these attacks at the level of the OSCE Parliamentary Assembly, Parliamentary Assembly of the Council of Europe, and European Parliament. This is real protection of our citizens and entities against cyberattack, not pushing for new aggregation of personal data! When 153 million identity documents sit in a single database for over a year, undetected, every person in that database becomes a potential target, not just for common fraud, but for transnational repression. Privacy has to be recognised as a fundamental human right, including in the digital space, where the same data that sits unprotected can be weaponised by bad actors and AI-powered tools alike. This is one more example of the message I'm not going to tire of repeating: the weaponisation of FATF's financial, national security and cybersecurity laws no longer serves as protection. Time to stop it and implement the most recent resolutions on transnational financial repression NOW. image
Not your intelligence, not your rights. No matter how much of your own intelligence goes into a document, if #Claude touched it, it comes out marked as AI generated since August 2. Consequences for small NGOs using AI to cut costs on design and translation: a witness statement translated into English, a testimony de-identified to protect the source, a report an exiled activist ran through Claude to fix their grammar, all carry the same mark as “fabricated content”. Once detection tools are public, “this NGO report is AI-generated” becomes the cheapest discrediting line available to the governments we document. The honest caveats in Anthropic’s small print will not travel with the accusation. European Commission declared #Europe a place for innovation. This is not the way to do it…. Would I stop using AI to defend human rights? No. Dictators and bad actors already use every tool available to repress people. We should be able to use every tool available to protect them.
If we’re doing security checkups in Bitcoin self-custody, we need to cover everything: cold and hot wallets, multi-signature setups, all of it. We can’t audit one storage type and leave the rest for later. AI-driven attacks won’t wait for us to finish patching one vulnerability before moving to the next. Many people are offline, not following X or Nostr discussions. Please check your contact lists and make the effort to reach everyone in the bitcoin space. Also, telling people to use such platforms as GoFundMe after a bitcoin hack is dangerous advice. GoFundMe will freeze accounts after a few donations once they see funds are being raised in connection with bitcoin / hack attacks. You are sending people into a wall. @ODFoundation take our responsibility to inform our network of activists, where bitcoin is the only financial tool they have. But we also live in a different reality from most of the bitcoin community. A hot wallet with a small amount is our everything. We need a coordinated response - develop clear instructions on what we can actually advise, reflecting this new reality where AI systems are testing us endlessly.
With the Digital ID framework, the Digital Euro, and Chat Control all moving toward implementation, the question 'what happens when the state turns off your money?' is no longer theoretical for any EU resident or entity. Are you ready to fight back for your rights? Let's meet at @BTCHEL 25.-26. SEPTEMBER in September! image
Lyudmyla Kozlovska's avatar
lyuda_kozlovska 2 months ago
Addressing the weaponization of INTERPOL: 3/3 This is where your voice can make a difference in protecting people from INTERPOL abuse. As constituents, lawyers, civil society, privacy specialists and people who have been victims of INTERPOL’s abuse, we should jointly push for the reform. France holds the Presidency of INTERPOL's Executive Committee. The US, Germany and Canada also sit on it — four of the thirteen members of the body that supervises the General Secretariat. These are the states with a direct hand in INTERPOL's governance. They are the ones who can turn the resolution's recommendations into protection and accountability. Safeguards that depend on the good faith of the requesting state are not safeguards. Notification and published statistics work regardless of who issues the notice. In the next posts we will go through the remedies and accountability measures the OSCE PA proposes. If you want to support this advocacy — now is the moment. Join us! image
Lyudmyla Kozlovska's avatar
lyuda_kozlovska 2 months ago
2/3 Why you should work with parliamentarians from the OSCE Parliamentary Assembly as a constituent? Because the OSCE Parliamentary Assembly is one of the few tables where the EU, the US, Canada and Central Asia sit together — and transnational financial repression does not respect any single jurisdiction. As result, our personal data, access to financial services, our security under real threat. What one parliament alone cannot fix, European, American and Canadian parliamentarians can address together. That is where the resolution comes from on countering transnational financial repression and the weaponisation of INTERPOL, FATF AML/CFT laws and cybersecurity regulations, initiated by Italian parliamentarian Mauro Del Barba. It maps the impact on the rights of citizens and entities in Western societies, and sets out remedies and accountability for the abuse of these tools. We have been working on this with Mauro for a long time. It started in 2013, with our first recommendation that INTERPOL provide clear remedies for refugees. This time it reaches Russia and other adversary states abusing inter-state mechanisms to collect the data and attack the rights of citizens, entities and officials of Western countries — including officials of the EU and NATO. I’m very grateful to Euractiv for covering this, especially the INTERPOL dimension. Euractiv reports the OSCE is "alarmed" that INTERPOL's Purple Notices and its newer Silver Notices can be used without giving targeted individuals a clear way to appeal or request review. INTERPOL tightened scrutiny of Russian requests after the full-scale invasion of Ukraine. But concerns remain around the Silver Notice — an international alert that lets member countries track, identify and recover assets. A German law official told Euractiv the mechanism gives Russia "an excellent tool" to make discreet inquiries into the assets of the people it targets: bank accounts, real estate, companies held abroad. Several of these reforms mirror provisions already moving through the US Congress. Legislators on both sides of the Atlantic can now reference a common standard. Link: https://www.euractiv.com/news/exclusive-osce-warns-against-russias-weaponisation-of-interpol/ image
Lyudmyla Kozlovska's avatar
lyuda_kozlovska 2 months ago
TRANSNATIONAL FINANCIAL REPRESSION: WHAT THE OSCE PA IS ASKING FOR 1/3 Close to vacation time, the European Commission is pushing on Chat Control and age verification — measures that erode the privacy of communication and of access to the internet, and put citizens and entities in the EU at serious risk. At the same time, parliamentarians across the transatlantic space are calling for something the EU has not done: a proper assessment of how third countries weaponise INTERPOL, AML/CFT and cybersecurity tools against citizens and entities in the West. These two things cannot be separated. Every mechanism built to see more of what people do gets abused, eventually, by states or their proxies that mean them harm. For the first time in the transatlantic space, an OSCE PA resolution defines who the victims of transnational financial repression actually are. Not only civil society and diaspora — but entrepreneurs, donors, judges, MPs, scientists, and officials of the EU and NATO. The resolution says an attack on any of these categories has to be treated as an attack on the democratic, economic and security architecture of the OSCE area as a whole. It also calls for neutral regulatory language on privacy-preserving tools. AML/CFT and cybersecurity frameworks should describe end-to-end encryption, secure messaging, donation platforms ensuring donor privacy, digital payment tools and VPNs in terms respectful of fundamental rights — and must not treat the use of these tools as an intrinsic indicator of suspicious or criminal activity. Overbroad application of international cooperation mechanisms hits journalists, donors and human rights defenders who rely on them legitimately, for their own security. As a victim of transnational financial repression and president of the Open Dialogue Foundation I'm very grateful for OSCE PA and Mauro Del Barba for introducing this important reporm.
Lyudmyla Kozlovska's avatar
lyuda_kozlovska 3 months ago
#Nostr resists relay-level censorship — but not a digital-ID gateway, which moves the chokepoint below the protocol, to the connection itself. You can’t sign your way past a network you’re not allowed to reach. Unfortunately, if governments want to block access to Nostr - they can. Which is exactly why the privacy safeguards we advocate to be included in laws matter more than ever. Do you agree?
Lyudmyla Kozlovska's avatar
lyuda_kozlovska 3 months ago
Are you in #Prague and want to know how your voice can make a difference in protecting the privacy of payments, communications, and internet access in general? Let's meet and talk. Come join our panel tomorrow at the amazing BTC Prague conference. Seriously. We have no time for further delays. #Bitcoin and #freedom #tech need you, just as you need #privacy tools in the digital age. Privacy is your human right—defend it or lose it.
Lyudmyla Kozlovska's avatar
lyuda_kozlovska 4 months ago
Age verification for the internet is the end of human rights and freedom of speech for generations to come: not only in the EU, UK - also in the US. We are watching the freedom values of Western civilization collapse — adopting the same digital cage that others are already trapped in. Human rights are taken away every single day — all because too many of us are still not ready to defend them, mistakenly believing these rights are simply given. Generations fought for these freedoms, high standards of values, and paid with their lives so that we could enjoy and live in a free Western society. Ask yourself: what have you done, and what are you doing every day, to protect this heritage?
Lyudmyla Kozlovska's avatar
lyuda_kozlovska 5 months ago
How can philanthropy be better protected in an era of growing data collection, AI-driven analysis, and geopolitical risks? At the Open Dialogue Foundation, we are currently conducting a joint research project with the Democratic Futures Project at the University of Virginia to explore that question. As part of this work, we are speaking with people across philanthropy and civil society about experiences with banking, compliance, financial access, privacy, and the broader pressures, including transnational repression, that can affect charitable and democratic work. We know these issues can take many different forms, from administrative burdens to concerns about data, visibility, and how organizations and their partners are treated. Our goal is to listen, learn from those working in this space, and help inform practical recommendations for stronger protections. If you work in philanthropy, civil society, donor advising, digital rights, or a related field and would be open to a short conversation, we would be very grateful to connect. If you know someone whose perspective would be valuable, we would also greatly appreciate any introductions. Please feel free to message us directly if you would be open to a brief conversation or know someone we should speak with. #Philanthropy #CivilSociety #Privacy #DigitalRights #HumanRights #Democracy #AI image
Lyudmyla Kozlovska's avatar
lyuda_kozlovska 6 months ago
European Parliament has just rejected the Chat Control proposal again! 🫶🚀 Your voice always matters! Stay ready and keep standing up for your rights!🫶 As a follow-up, ask your MEP to investigate: 📌 Why are EPP MEPs following the agenda and timelines set by Google, Meta, TikTok, and other big platforms, instead of defending the fundamental rights of EU citizens? 📌 On what legal and political basis was this vote reopened, and who requested it — was it driven by the public interest or corporate lobbying? Ask EPP’s MEPs to show their proposal publicly! 📌 If this vote can be reopened once, does that mean it can be reopened again whenever the outcome pleases powerful actors — but not when citizens and civil society are dissatisfied with the result? image
Lyudmyla Kozlovska's avatar
lyuda_kozlovska 7 months ago
For years ago speed and permissionless of bitcoin helped me collect, buy and deliver protective and medical equipment to Kyiv and Lviv, while the world was wondering how send humanitarian aid to Ukraine. Thank you #satoshi 💙💛