It's All So Tiresome | THE BITCOIN BRIEF 81
A bi-weekly news show informing you on the latest in Bitcoin, privacy and open source tech hosted by Ungovernables, Max and Q.
AOB
- All aboard the vibe train
- FTF with Max T
- Q got some holidays coming up
-
https://x.com/keonne/status/2052066547561070671NEWS
- Bisq v1 trade protocol exploit: 11.59 BTC drained, fully reimbursed, hardening shipped in 1.10.0 (
https://bisq.community/t/psa-trade-protocol-exploit-discovered-investigations-ongoing/13664,
https://x.com/bisq_network/status/2050206753246363819, reimbursement plan on
https://github.com/bisq-network/proposals)Disclosed: 2026-05-01Bisq's v1 trade protocol had a missing validation check on taker-side input. Because maker and taker were supposed to use the same miner fee, a malicious taker could push a bad fee value through the transaction math and shrink the multisig output to 0.001 BTC while sweeping the rest into the taker's change. Attacker drained 11.59 BTC from 10 users, all on altcoin trades. Maintainer Henrik Jannsen filed a reimbursement plan on GitHub on May 3, payouts in BTC (with BSQ as optional), DAO vote scheduled around May 25. The hotfix landed as
https://github.com/bisq-network/bisq/releases/tag/v1.10.0 on 2026-05-16 with broader hardening: trade protocol checks, network message validation, release verification, supply-chain hardening. The Bisq team explicitly flagged the incident as a likely AI-assisted exploit, though they did not detail how AI was used.
- Sterlingov Appeal: The Criminalization of Privacy (
https://www.therage.co/sterlingov-appeal-the-criminalization-of-privacy/)Published: 2026-05-12The appellate court reviewing Roman Sterlingov's Bitcoin Fog conviction openly suggested that mixers remain "legal in theory but not practice" once criminals use them. Judges questioned whether running an internationally accessible service forces compliance with every jurisdiction's licensing regime.
- Pro-law-enforcement CLARITY Act advances out of Senate Banking (
https://www.therage.co/clarity-act-senate-banking/)Published: 2026-05-15The Digital Asset Market Clarity Act passed committee with expanded surveillance provisions: Bank Secrecy Act integration sixteen times over, new PATRIOT Act special measures. Privacy advocates flagged the breadth of data collection on Americans who haven't done anything.
- CVE-2024-52911 disclosed in Bitcoin Optech
#405, fix has been in Bitcoin Core 29.0+ since release (
https://bitcoinops.org/en/newsletters/2026/05/15/)Published: 2026-05-05Use-after-free in parallel script validation between Bitcoin Core 0.14.0 and 28.x. Required attacker-supplied proof-of-work, so practical attack window was narrow, but the bug sat unannounced across many versions.
- Bitcoin Knots 29.3 enables BIP-110, fork-off countdown started (
https://github.com/bitcoinknots/bitcoin/releases/tag/v29.3.knots20260508) + Lopp's
https://jlopp.github.io/knotzi-death-march/Published: 2026-05-09 (release)Knots 29.3 ships RDTS soft-fork enforcement on by default. Nodes running Knots with this flag set will fork off the network in August unless they change behaviour. Lopp set up a countdown.
- Bybit exploit post-mortem (Blockstream): enterprise multisig + hardware wallets did not save them (
https://blog.blockstream.com/what-the-bybit-exploit-reveals-about-enterprise-custody/)Published: 2026-05 (week of 5-12)$1.5B drained despite multisig and hardware. Failure was process, not key custody, a UI / signing-flow compromise.
- Poland passes EU MiCA-aligned crypto bill while Zondacrypto fraud probe deepens (
https://bitcoinmagazine.com/news/poland-passes-crypto-bill-as-fraud)Published: 2026-05-15Polish lawmakers ratified the MiCA framework ahead of the July EU deadline. The vote landed alongside an investigation into Zondacrypto's collapse, roughly $96M of user losses, with Prime Minister Tusk floating possible foreign-influence angles.
- Claude helps retrieve lost 5BTCX user '
https://x.com/cprkrn/status/2054586810475364536' has Claude check over whole file system and match a wallet file to an old password
- Spiral and Block ship Loupe, an AI-powered vulnerability scanner for open-source Bitcoin (
https://spiralbtc.substack.com/p/meet-loupe-ai-powered-vulnerability)Published: 2026-05-12Uses LLMS to surface security weaknesses in code repositories and requires demonstrable test cases for any vulnerability report so false positives are minimised. Spiral and Block are funding scans themselves; reports go to maintainers confidentially before any public disclosure.
RELEASES
-
https://bitcoincore.org/en/releases/31.0/ (release index entry) — 2026-05-12Operator review required before production rollout. Major version landing.
-
https://github.com/bitcoinknots/bitcoin/releases/tag/v29.3.knots20260508 — 2026-05-09RDTS soft-fork enforcement on by default, fork-off risk in August. New configuration changes, bug fixes.
-
https://github.com/ElementsProject/lightning/releases/tag/v26.06rc1 — 2026-05-12Adds graceful command for clean shutdown, new sendamount RPC, BOLT12 payer-proof support, plus 211 commits since v26.04.
-
https://github.com/proto-at-block/bitkey/releases/tag/app/2026.9.1 — 2026-05-15Security patch from Block.
-
https://github.com/trezor/trezor-suite/releases/tag/v26.5.1 — 2026-05-15Legacy labeling migration, WalletConnect insufficient-balance warnings, side-by-side trade comparisons, new DeFi Tokens section.
-
https://github.com/BitBoxSwiss/bitbox-wallet-app/releases/tag/v4.51.0 — 2026-05-12Bundles BitBox02 firmware v9.26.1, address formatting in 4-char groups, iOS haptic feedback on charts, account-summary perf.
-
https://github.com/LedgerHQ/ledger-live/releases/tag/%40ledgerhq/live-desktop%404.4.0 — 2026-05-13Hardens Live App handling of external-protocol URLs (itms-apps:, ms-word:, file:, etc.) across Chromium navigation vectors.
-
https://github.com/LedgerHQ/ledger-live/releases/tag/live-mobile%404.4.0 — 2026-05-13Adds an addresses section to asset detail screens, device-card management menus with removal confirmations.
-
https://github.com/SatoshiPortal/bullbitcoin-mobile/releases/tag/v6.10.1 — 2026-05-18Onboarding redirect fix on wallet creation failure.
-
https://github.com/SatoshiPortal/bullbitcoin-mobile/releases/tag/v6.10.0 — 2026-05-11Major release: Ledger hardware-wallet integration, FSS hybrid storage strategy, real-time WebSocket notifications, new onboarding wizard, Payjoin privacy enhancements, 11 new translations.
-
https://github.com/SatoshiPortal/bullbitcoin-mobile/releases/tag/v6.9.101-Internal-Release (display name v6.9.108-Internal) — 2026-05-09Pre-6.10.0 testing build, Android migration / startup wizard / secure storage fixes.
-
https://github.com/andreasgriffin/bitcoin-safe/releases/tag/2.0.0rc0 — 2026-05-17Comprehensive redesign of the wallet setup wizard, added support for Coldcard mk5 and Trezor 7, plugin architecture via external repos, fiat-balance category column.
-
https://github.com/sparrowwallet/frigate/releases/tag/1.5.0 — 2026-05-14Low-latency mempool ingestion via Bitcoin Core's ZMQ sequence publisher, auto-discovers the bitcoind ZMQ endpoint when unconfigured. Useful for operators running Sparrow Frigate alongside Core.
-
https://github.com/Blockstream/green_ios/releases/tag/release_5.4.0 — 2026-05-11Aggregate fiat balance across all wallet assets, updated Send flow for Lightning, migrates Lightning backend from Breez to Greenlight (Blockstream's own LSP).
-
https://github.com/Blockstream/green_android/releases/tag/release_5.4.0 — 2026-05-08Same redesign as iOS: aggregate fiat balance, redesigned Send flow (recipient → asset → account), transaction pagination, also the Breez-to-Greenlight migration.
-
https://github.com/Blockstream/green_qt/releases/tag/3.3.0 — 2026-05-06Total fiat balance in wallet header, AMP ID exposed in settings, GDK 0.77.3, Qt 6.11.0, Wayland fixes.
-
https://github.com/Peach2Peach/peach-app/releases/tag/v0.69.0(346) — 2026-05-06Signature validation for backed-up payment details, encrypts custom refund addresses, removes invalid backed-up data.
-
https://github.com/Peach2Peach/peach-app/releases/tag/v0.69.0(345) — 2026-05-05Percentage filtering on offers, encrypted server backup syncing for payment methods, advanced offer-creation options, GrapheneOS camera-permission fix, Buy Offer creation restricted to experienced users.
-
https://github.com/ZeusLN/zeus/releases/tag/v13.0.2-rc3 — 2026-05-18Third RC for 13.0.2. New RGS server at
http://rgs.zeusln.com providing graph updates every 15 minutes instead of every three hours. Clipboard and NFC UX improvements.
-
https://github.com/ZeusLN/zeus/releases/tag/v13.0.1 — 2026-05-07Stable release: fixes recovering Embedded LND wallets from seed (was stalling out), payment retry logic, false-positive offline detection. Cashu token sweeping to self-custody continues to land.
-
https://github.com/getAlby/hub/releases/tag/v1.22.2 — 2026-05-11Adds Core Lightning support (their most-requested feature), new AI & Agents page, integrated on-chain wallet mode, custom transaction labels, redesigned settings, improved budget selection for app connections.
-
https://github.com/BoltzExchange/boltz-backend/releases/tag/v3.13.0 — 2026-05-08Full Arkade swap support, EVM commitment-swap lockup flow, multi-LND support in backend and sidecar.
-
https://github.com/BoltzExchange/boltz-client/releases/tag/v2.12.0 — 2026-05-12Final removal of the GDK wallet library.
-
https://github.com/arkade-os/arkd/releases/tag/v0.9.5 — 2026-05-11Client-lib wallet interface updates, breaking-changes documentation, single-key wallet signing fixes.
-
https://github.com/arkade-os/ts-sdk/releases/tag/v0.4.25 — 2026-05-07Maintenance bump for the Arkade JavaScript SDK.
-
https://github.com/Elenpay/NodeGuard/releases/tag/0.24.2 — 2026-05-14Fixes invoice-expiry calculation in rebalance flows. Check logs if rebalance operations have been timing out.
-
https://github.com/apotdevin/thunderhub/releases/tag/v0.18.3 — 2026-05-15Bug-fix release in the 0.18.x line. (Subsequent 0.18.1-0.18.3 are CI/docker polish after the headline 0.18.0.)
-
https://github.com/apotdevin/thunderhub/releases/tag/v0.18.0 — 2026-05-05Adds Taproot Assets support to the dashboard. The actual show story for ThunderHub this fortnight.
-
https://github.com/blinkbitcoin/blink-mobile/releases/tag/2.4.44 — 2026-05-06Upgrades protobufjs (CVE-2026-41242 mitigation). Security patch.
-
https://github.com/fedimint/fedimint-sdk/releases/tag/canary — 2026-05-14React Native transport fix, persistent callback, RPC payload flattening. Canary channel.
-
https://github.com/getumbrel/umbrel/releases/tag/1.7.3 — 2026-05-12DirtyFrag security patches: CVE-2026-43284 + CVE-2026-43500 in the Linux kernel. Mandatory.
-
https://github.com/getumbrel/umbrel/releases/tag/1.7.2 — 2026-05-05CopyFail patch: CVE-2026-31431 in the Linux kernel. Mandatory.
-
https://tails.net/news/version_7.7.3/ — 2026-05-12Emergency release: critical Linux kernel CVE fix (kernel 6.12.86 ships the Dirty Frag fix), plus Tor Browser and Tor client security fixes.
-
https://github.com/vibrant-btc/whirlpool-observer/releases/tag/v1.0.1…https://op3.dev/e/dts.podtrac.com/redirect.mp3/pdcn.co/e/pscrb.fm/rss/p/serve.podhome.fm/episode/df3c7f87-bdab-41fe-1438-08dbf068e250/639148448474390988a7e26e42-557e-4bc6-b021-288872c3a4d1v1.mp3https://serve.podhome.fm/episodepage/ugmf/its-all-so-tiresome-the-bitcoin-brief-81