UPDATED OCTOBER 2, 2026
UPDATED OCTOBER 2, 2026

The Frontier

Your signal. Your price.

Include
Lookback
||
Bitcoin Optech
  • · 16h ago

    Ahmet Kirk argues that even if Bitcoin receives an on-chain post-quantum upgrade, Lightning's off-chain components like gossip and onion routing remain vulnerable. Decoupled upgrades are necessary because attackers could record current traffic to decrypt it later.

    +3 more
    +1 more
  • · 16h ago

    Ahmet Kirk's proposal distributes post-quantum node identities via gossip, upgrading two of three gossip messages while leaving channel announcements classical. The transport layer relies on BIP 8 to integrate post-quantum primitives next to classical ones.

    +3 more
    +2 more
  • · 16h ago

    Ahmet Kirk states that Bolt 11 post-quantum signatures fit within QR code limits using MLDSA-44 signatures. Because Rust Lightning has a 639-byte message limit, PQLN splits the signature across four tag fields.

    +3 more
    +5 more
  • · 16h ago

    To keep onion packets under the 1,300-byte limit, Ahmet Kirk's design avoids sending 1,088-byte MLKEM ciphertexts inside the onion. Instead, per-hop secrets are made hybrid and travel alongside the onion in a fixed-size list of 20 slots.

    +3 more
    +2 more
  • · 16h ago

    Ahmet Kirk reports that PQLN adds 11,000 lines of Rust code and 100 tests. MLDSS signing adds a negligible 0.33 milliseconds of overhead, but gossip bandwidth increases tenfold with MLDSA-44 or fourfold with Falcon.

    +3 more
    +5 more
  • · 16h ago

    Jan explains that Bitcoin Core 32.0 release candidate 2 is feature-complete ahead of its October 10th target. The associated testing guide covers 10 tests across four groups on Regtest, focusing on new RPCs and the HTTP server rewrite.

    +3 more
    +1 more
  • · 16h ago

    Jan highlights key Core 32.0 features, including getopenrpcinfo for machine-readable RPC diffs, PSBT version 2 by default, and exportwatchonlywallet for phone tracking. The HTTP server is rewritten from scratch to remove libevent and enforce stricter RFC compliance.

    +3 more
    +2 more
  • · 16h ago

    A Stack Exchange contributor explains that Taproot commits to every individual input amount rather than just the sum. Committing only to the total allows a malicious machine to shuffle amounts between inputs to steal funds in a coinjoin.

    +3 more
    +2 more
  • · 16h ago

    Bitcoin Knots nodes that split off during the failed BIP 110 activation in August do not need a full re-sync. Because the minority chain quickly stalled, pruned nodes still hold the last common block and can reorg automatically.

    +2 more
    +1 more
  • · 16h ago

    Core Lightning 26.06.8 acts as a security release that temporarily withholds certain tests to prevent attackers from finding vulnerabilities. PR 9507 caps peer-proposed fee rates at 4,000 sats per vB to prevent overflow bugs that crash restarting nodes.

    +3 more
    +1 more
  • · 16h ago

    Core Lightning fixed vulnerabilities where peers could trick nodes into ignoring force-closed revoked commitments by sending a decoy shutdown message. Other fixes address nodes losing splice signature memory across restarts and limit peers to three concurrent negotiations.

    +3 more
    +1 more
  • · 16h ago

    Core Lightning PRs 9510 and 9511 mitigate crash risks by capping JSON nesting to 256 levels and rejecting oversized DNS hostnames. PR 9513 now validates that Bolt 12 fetched invoice amounts do not exceed requested or offered parameters.

    +3 more
    +2 more
  • · 16h ago

    LDK 0.3 release candidate 2 introduces RBF fee bumping for stuck splices, defaults to negotiating anchor channels, and invalidates older Bolt 11 invoices. The LDK project has also migrated its repository off GitHub to a self-hosted mirror.

    +3 more
    +2 more
  • · 16h ago

    LND updated its Atomic Multipath Payments (AMP) logic to prevent whole-invoice cancellations when a single path fails. Additionally, LND introduced validation logic ensuring returned Bolt 12 invoices are signed by the actual receiver.

    +3 more
    +2 more
  • · 16h ago

    LND restored Bolt 1 compliance by ensuring it replies to all valid ping messages. This fix preserves the inbound rate-limiting and bucket protections against ping-based denial of service attacks introduced in a previous release.

    +3 more
    +1 more
About The Frontier
15 results
End of 7-day results — 15 results