Price:

Bitcoin developers denounce Blockstream over closed patch

Sep 2, 2026Summary from 2 podcasts.
  • Blockstream patched a Core Lightning flaw using closed-source binaries under a two-week code embargo.
  • Developers argue withholding source code breaks community trust without stopping attackers from decompiling binaries.

Blockstream broke an unwritten rule of Bitcoin development.

When a critical vulnerability hit Core Lightning, maintainers instructed node operators to shut down immediately. Two days later, Blockstream released version 26.06.7 - not as open-source code, but as compiled, closed-source binaries. The team placed the underlying source code under a strict two-week embargo, claiming the delay prevents attackers from reverse-engineering the exploit against unpatched nodes.

Open-source purists met the move with swift condemnation. Discussing the patch on Presidio Bitcoin Jam, Steve argued that withholding source code fundamentally violates developer trust. Worse, he warned the strategy fails against modern threats, noting AI-equipped attackers easily decompile binaries to isolate vulnerabilities regardless of source availability.

Days later on Ungovernable Misfits, host Q echoed those concerns, calling the embargo a dangerous precedent. Q pointed out that motivated attackers routinely decompile signed binaries anyway. By forcing node operators to run unverified executable code, Blockstream stripped away the core auditability of open-source software without providing real security.

The controversy unfolded amid broader friction across the Lightning network. ACINQ recently rushed out Eclair version 0.14.2 to address critical security exploits from malicious nodes, which Q noted likely targeted Eclair's remote procedure call connections to the Bitcoin daemon.

The backlash highlights a fundamental divide over emergency stewardship in decentralized systems. While Blockstream prioritized corporate risk containment over transparency, independent researchers demonstrated that protocol resilience relies on open execution. Researchers Avihu Levy and Tom Giladi recently proved this by mining a quantum-resistant transaction on mainnet using existing opcodes, bypassing Core developers entirely.

In Bitcoin, security depends on auditability, not corporate paternalism. Running closed-source binaries asks node operators to trade verified code for blind trust - a deal the developer ecosystem rejects.

Source Intelligence

- Deep dive into what was said in the episodes

The AI-Pocalypse Continues | THE BITCOIN BRIEF 88Sep 1

  • Core Lightning maintainers issued a two week embargo on a critical vulnerability, releasing version 26.06.7 as closed source signed binaries. Q criticizes this precedent, arguing motivated attackers can easily reverse engineer binaries to target unpatched nodes anyway.
  • Eclair version 0.14.2 released a critical update to address security exploits from malicious nodes. Q suggests the vulnerability likely targets Eclair's remote procedure call connection with the Bitcoin daemon.
Also discussed on this episode: (10)

Protocol (2)

  • Starkware researchers Avihu Levy and Tom Giladi mined the first quantum safe Bitcoin transaction on mainnet in block 964199. Using existing script opcodes without consensus changes, the transaction is five times larger and more expensive than standard transactions.
  • Luke Dashjr launched a hard fork on the Bitcoin Knots breakaway chain to swap the SHA-256 hashing algorithm for Blake2b. This change aims to eliminate the ASIC boost efficiency edge but lacks support from major exchanges or implementations.

Custody (4)

  • Coinbase partnered with Better Mortgage to offer bitcoin backed mortgages, allowing borrowers to pledge digital assets as collateral and bypass taxable selling events. Q notes that borrowers must surrender custody of their keys to high interest loans.
  • Kraken accounts were frozen after receiving thousands of dust transfers from wallets tied to the sanctioned exchange HTX. While user access has been restored, Kraken continues to hold millions of dollars in funds categorized as tainted.
  • Sparrow Wallet version 2.5.4 introduced mandatory anti klepto protection for BitBox02 hardware wallets. The protocol prevents compromised USB signing devices from secretly leaking private keys over time through transaction signatures.
  • Envoy version 2.3.3 resolved Bluetooth pairing issues with Passport Prime hardware wallets. The update specifically corrects a clock drift defect on the Passport Prime that previously degraded connection stability.

Open Source (1)

  • The Human Rights Foundation distributed development funds across sixteen global open source projects. Funded initiatives include the 256 Foundation, My First Bitcoin, and privacy tools like Wallet Scrutiny and Xerox Chat.

Regulation (1)

  • Peach Bitcoin paused its peer to peer escrow model due to pressure from Swiss regulators seeking to reclassify the business. Without escrow protections, non-KYC sellers are limited to one active trade, and buyers face increased risk of counterparty rug pulls.

Coding (1)

  • Developer GG built a MiniScript fork of SeedSigner along with a standalone bridge tool for Liana. The bridge allows users to scan QR codes and load file based PSBTs without requiring a complete rewrite of Liana desktop software.

Media (1)

  • Q launched an interactive archive search feature on the Ungovernable Network website, organizing over 500 episodes into searchable topics with timestamped links. The release includes progressive web app support suggested by Jordan and mobile full screen video optimization.

Nvidia Bets Big on Open-Source AI, AI Finds Core Lightning Bugs, Aluminum-Powered Data CentersAug 28

  • Core Lightning patched critical vulnerabilities by releasing binaries while embargoing the source code for two weeks to prevent immediate exploitation. Steve criticizes this approach, arguing that withholding source code violates open-source trust and fails to stop AI-equipped attackers.
Also discussed on this episode: (10)

Models (3)

  • Ashu built the PBJ Topic Explorer tool, which uses AI to visualize transcript topic distributions over time. The tool's historical trends show that AI topics consistently accounted for 10 to 15 percent of show discussions back in early 2025.
  • Particle launched Radar, an AI-powered podcast search engine designed to index global audio content down to timestamp granularity. Radar has already ingested thousands of shows, including at least 10 episodes of the Presidio Bitcoin Jam.
  • Max cautions that the private AI frontier is likely two generations ahead of public models. This rapid advancement supports Sam Altman's claim that OpenAI will achieve artificial general intelligence by the end of 2025.

Energy (2)

  • Max highlights Avoya Energy's Series A fundraise to develop aluminum-based metal fuels for long-duration, transportable energy storage. The system uses an electrochemical process to extract electricity from aluminum reacting with oxygen, offering a silent alternative to diesel generators.
  • Google acquired Intersect Solar in a multi-billion dollar deal to power AI compute sites. Intersect Solar originally built these massive solar farms in the early 2020s for green hydrogen production, which failed to gain market traction.

Chips (1)

  • Nvidia secured crucial open-source AI infrastructure by acquiring Hugging Face for 12.9 billion dollars and licensing Poolside technology for 6 billion dollars. These moves ensure open-source models remain competitive, which directly drives long-term demand for Nvidia chips.

Agents (2)

  • DK uses the slash goal feature in Codex and Claude to run autonomous, multi-hour background development tasks. Additionally, DK leverages GrokBot's native Twitter integration to autonomously track and summarize video generation workflows from specific content creators.
  • Steve warns that multiplayer agent environments introduce systemic security risks where a compromised agent can infect trusted peers. This vulnerability is underscored by ongoing social engineering campaigns where North Korean attackers trick crypto professionals into installing malware disguised as podcast software.

AI Infrastructure (2)

  • Max details Sale Research's plan to build decentralized solar-powered clouds that run background tasks on cheap, depreciated GPUs during peak solar hours. This model relies on flexible, low-uptime workloads rather than demanding continuous power availability.
  • Steve highlights Darkbloom, an Eigenlabs-affiliated project that enables users to monetize idle hardware by hosting local AI inference. This platform provides a decentralized inference marketplace, allowing users to earn direct dollar payments for contributing Mac compute.