Fedimint. Decentralised #Bitcoin custody for the world. Read more at fedimint.org

Fedimint ๐Ÿ”† retweeted
Happy ecash coffee day from Dark Prague! โ˜•
1
3
37
1,913
Federate all the ecash! ๐Ÿš€
The FROST basis for this new design enables composability across the ecosystem, with @bitcoindevkit to power onchain, and Bark (@secondhq) to power the Lightning! @callebtc @btcplusplus
5
13
1,903
Fedimint ๐Ÿ”† retweeted
Just caught @joschisanbtcโ€™s talk in BTC++ Berlin on @fedimint and am blown away. As someone who is ecash-agnostic I donโ€™t think thereโ€™s another project in bitcoin thatโ€™s using as much cutting edge black magic tech in pursuit of their goals. Incredibly impressed.
2
6
29
2,040
Today at @btcplusplus @joschisanbtc explained all the engineering that went into Fedimint over the last years ๐Ÿ˜Ž Missed it? Watch out for the recordings!
8
21
779
Fedimint ๐Ÿ”† retweeted
Had a great time at Ecash Hackday in Berlin, got a Fedimint running with 3 different implementations by @thesimplekid, me and the Fedimint team! ๐Ÿš€ Already got 3 Fedimint implementations now, who will build the 4th one? ๐Ÿ˜
Why multiple implementations make sense for security beyond a certain point:
2
6
38
4,589
Fedimint ๐Ÿ”† retweeted
Fedimint now has a native Android SDK ๐ŸŽ‰ org.fedimint:sdk 0.1.0-beta.1 is live on Maven Central, the first native Android SDK for Fedimint. Join a federation, send and receive ecash, and pay over Lightning, all from Kotlin, in one dependency. central.sonatype.com/artifacโ€ฆ @fedimint
2
8
17
1,737
Fedimint ๐Ÿ”† retweeted
Multiple Fedimint implementations were part of the original vision, now with the help of AI the dream is becoming reality ๐Ÿฅน Time to call the fedimint repo minimint again? Has my holding out finally paid off? ๐Ÿ˜
3
5
15
1,422
Another Fedimint implementation just dropped! ๐Ÿš€
3
16
1,848
We found a bug in our legacy Lightning integration and are contacting public gateway operators. User funds, federations, and ecash are not affected. Gateways using LDK Node or our newer LNv2 protocol are also not affected. We still recommend staying up to date. ๐Ÿงต
5
35
82
10,280
If we havenโ€™t reached out, please update to v0.12.1 ASAP, or shut down your Lightning gateway in the meantime if thatโ€™s not feasible. Users of federations without an active Lightning gateway will still be able to make ecash and on-chain transactions. github.com/fedimint/fedimintโ€ฆ
1
2
12
801
The bug results from an interaction between misunderstood HTLC interception behavior and our LN-ecash swap validation logic that evaded previous scans. We continue to do our own AI-accelerated security research and appreciate external research findings at security@fedimint.org
2
11
455
Fedimint ๐Ÿ”† retweeted
ecashmeshโšก๏ธ evidence-aware routing for Ecash across @CashuBTC , @fedimint and eventually @lightning beyond fees: liquidity, reliability, proof freshness and route risk which Ecash route should I use, and why? building for @bitshala boss battle 2026 ๐Ÿ”— github.com/bansalayush247/ecโ€ฆ
2
7
20
2,133
Fedimint ๐Ÿ”† retweeted
Why multiple implementations make sense for security beyond a certain point:
Calling on fellow cypherpunks to build alternative Fedimint implementations. The Liquid hack shows once again that single points of failure are what will break our systems and that includes the code we write. Security is an asymmetric game: an attacker has to find one weakness, while defenders have to find all. AI has permanently changed the attacker-defender balance for the worse. This is a fundamental problem for the entire freedom tech space and only mitigatable by aggressively reducing single points of failure. Federations are meant to do exactly that, but just like Liquid, Fedimint shares the โ€œsingle implementationโ€ problem. If we still want to bring privacy and freedom to the world we need to work together more than ever to reduce these single points of failure. For me that means seeking help to bootstrap independent Fedimint implementations. We are still early, but I've started extracting a specification that others could build off and would love to collaborate with any fellow cypherpunks who want to join us in that mission. In particular, Iโ€™d love to work with @callebtc and the @CashuBTC team, who have much more experience with a multi-implementation ecash protocol while the Fedimint team brings federation experience to the table. While AI exposes existing vulnerabilities and wreaks havoc in our ecosystem, it is also an opportunity for talented engineers to be far more productive than ever before. Iโ€™ve been talking with @fedibtc and there is funding for a small, crack team to pull this off. If this sounds interesting as a funder, please reach out! The idea is for the teams to be purposefully disconnected from the existing Fedimint implementation and to work autonomously, communicating mainly through the spec process. If you too believe that privacy and freedom are needed more than ever, please join us!
1
5
16
4,829
Fedimint ๐Ÿ”† retweeted
Using @fedibtc and a self-hosted @fedimint federation to make Bitcoin everyday money! This is Good Hope federation, running on 7 @start9labs devices, spread out across the Western Cape province of South Africa. We use it every day. But it's still mind blowing. Every single time.
1
13
40
3,343
Fedimint ๐Ÿ”† retweeted
Calling on fellow cypherpunks to build alternative Fedimint implementations. The Liquid hack shows once again that single points of failure are what will break our systems and that includes the code we write. Security is an asymmetric game: an attacker has to find one weakness, while defenders have to find all. AI has permanently changed the attacker-defender balance for the worse. This is a fundamental problem for the entire freedom tech space and only mitigatable by aggressively reducing single points of failure. Federations are meant to do exactly that, but just like Liquid, Fedimint shares the โ€œsingle implementationโ€ problem. If we still want to bring privacy and freedom to the world we need to work together more than ever to reduce these single points of failure. For me that means seeking help to bootstrap independent Fedimint implementations. We are still early, but I've started extracting a specification that others could build off and would love to collaborate with any fellow cypherpunks who want to join us in that mission. In particular, Iโ€™d love to work with @callebtc and the @CashuBTC team, who have much more experience with a multi-implementation ecash protocol while the Fedimint team brings federation experience to the table. While AI exposes existing vulnerabilities and wreaks havoc in our ecosystem, it is also an opportunity for talented engineers to be far more productive than ever before. Iโ€™ve been talking with @fedibtc and there is funding for a small, crack team to pull this off. If this sounds interesting as a funder, please reach out! The idea is for the teams to be purposefully disconnected from the existing Fedimint implementation and to work autonomously, communicating mainly through the spec process. If you too believe that privacy and freedom are needed more than ever, please join us!
A topic this critical deserves my first long-form post. The real question is not trusted vs trustless. It's how many independent things have to go wrong before you lose money. @TheBlueMatt said it in one sentence. Run the same software, suffer the same bugs. โฌ‡๏ธ Think about what actually happened. Liquid was an 11-of-15 multisig. Fifteen independent signers. No keys were compromised. Nevertheless, eleven honest signers approved a withdrawal that emptied 95% of the reserves, because every one of them was running the same code, and the code had the same bug. A few weeks before that, one firmware flaw swept thousands of Coldcard cold wallets. Different product, same lesson from the other side.โ€จ Before anything else, none of this is abstract. Coldcard victims lost savings they stacked over years. LBTC holders woke up to frozen funds through no fault of their own. And anyone who has ever shipped code that holds other people's money can and should empathise with the engineers at Blockstream. I do. But we have to be honest with ourselves here. The world has changed. AI tooling is surfacing bugs that sat dormant for years, a point Matt also made after Coldcard. Five year old vulnerabilities are getting weaponised. Supply chains are getting attacked. "Secure so far" doesn't mean much anymore. So let's also retire a comforting fiction. There is no such thing as โ€œtrustless.โ€ There never was. It was always shorthand for trust-minimised. Every system puts trust somewhere: in code, in firmware, in the people who write, ship, and run both. Liquid users trusted Elements. Coldcard users trusted a random number generator they never saw. Don't get me wrong. We should keep doing everything possible to make our code, our systems and the people behind them as trustworthy as we can. Audits, reviews, security culture, all of it. But trustworthiness is not the same thing as fault tolerance, and we need both. Fault tolerance only comes from having independent failure domains. In other words, no single point of failure. So what does this look like in practice: 1. Multiple implementations of every protocol that holds funds, with the power to reject and not just observe. 2. Multiple wallet implementations. We mostly have this already. 3. Keys generated on hardware from different vendors. 4. Multiple independent, trustworthy humans behind every system that holds money. 5. Geographic and jurisdictional distribution as one jurisdiction's rules can change overnight.ย  And to be clear, Matt's sentence currently applies to @Fedimint too. Fedimint was designed to remove single humans and single institutions as points of failure. That's the whole point of a constellation of federations. But today there is only one implementation of the protocol: every guardian runs the same software. Federated humans, monoculture code, and it's not good enough. So I'm calling on the Fedimint community to lead by example and fix this as quickly as we can. And to everyone else, tell me where I'm wrong. If I am, propose something better. If I'm not, then let's stop debating trusted vs trustless and start demanding independence at every layer. Software, hardware, humans, jurisdictions. All the way down. That's how Bitcoin stays worth the highest confidence as we enter this new age.
2
26
58
6,894
Fedimint ๐Ÿ”† retweeted
Congrats to the team for this huge milestone. Years of feedback and research to make this major upgrade to the protocol. Super excited to see the result and incorporate it into the Fedi app for a faster, smoother, and even more scalable offering. ๐Ÿ‘€โœ…๐Ÿš€
Fedimint v0.12.0 "Second Nature" is here! ๐Ÿš€ The highlights: * v2 modules (lnv2, mintv2, walletv2) now the default for new federations โœจ * Much lower Lightning payment latency โšก๏ธ * @iroh_n0 1.0 networking ๐ŸŒ * Wallet recovery without downtime ๐Ÿ”„ github.com/fedimint/fedimintโ€ฆ
3
9
1,632
Fedimint v0.12.0 "Second Nature" is here! ๐Ÿš€ The highlights: * v2 modules (lnv2, mintv2, walletv2) now the default for new federations โœจ * Much lower Lightning payment latency โšก๏ธ * @iroh_n0 1.0 networking ๐ŸŒ * Wallet recovery without downtime ๐Ÿ”„ github.com/fedimint/fedimintโ€ฆ
1
14
33
3,299
For app developers: UniFFI bindings bring the client to Kotlin & Swift ๐Ÿ“ฑ, new fee APIs show costs before you commit ๐Ÿค‘, and clients stay fully usable while recovering โ€” no more waiting for restore to finish. ๐Ÿ”„
1
2
189