
Trusted by 20,000 Bitcoiners
The future won’t wait for you.
Bitcoin, AI, and the ideas reshaping the world, delivered daily.
Free, daily. Unsubscribe anytime.


Is Bitcoin Mining Worth It in 2026? Home vs. Hosted, Honestly

Best Bitcoin Mining Hosting Companies (2026): Who to Trust With Your Miner

Bitcoin's Red Team Hit the Outreach Wall
Bitcoin's Red Team logged 1,029 high-or-critical findings across 425 projects in 55 hours. Now comes the hard part: reproducing the bugs and reaching the maintainers.
BTCPay Server published their full security advisory. The vulnerability allowed "an unauthenticated remote attacker to obtain .macaroon credential files for LND" which could be used to "take control of an LND node and move funds." The risk is specific to LND users. After further review, BTCPay confirmed "only LND is impacted" and on-chain wallets are not affected. The 2.4.2 update also upgrades LND to 0.21.1 and automatically regenerates macaroons. They are "not publishing technical details yet because operators still need time to update." BTCPay credits Craig Raw for the responsible disclosure and Bitcoin Red Team for analyzing the exploit. "We are deeply sorry to everyone affected by this incident. In the coming days, we will work on a full postmortem and share it when it is ready."

"Digital detectives are going sleepless after Bitcoin wallet hack." Bloomberg profiles the community response to the $130M Coldcard exploit. @intangiblecoins, who's spoken with 100+ victims: "These are average everyday people saving their money in Bitcoin. They were true believers." Becca Rubenfeld on the developers working around the clock: "It's like they're off at war. That's the vibe."
Skip the KYC exchange. Own an ASIC, @simpleminingio hosts it, freshly mined sats go straight to you. simplemining.io/tftc
Umbrel pushed BTCPay 2.4.2 to their App Store. Update now, but make sure you also follow BTCPay's additional steps: refresh macaroons, reset LN backend auth strings, and move funds from any BTCPay-generated hot wallets. x.com/umbrel/status/…

University of California professors are asking the school to bring back the SAT after dropping it in 2020 to promote "equity." Turns out their new students can't do high school-level work.

All 8 Flock surveillance cameras in Winona, Minnesota were cut down and removed over a few days. Poles sawed at the base, cameras gone. It's part of a growing nationwide backlash against automated license plate surveillance. Multiple cities have now shut their Flock systems down entirely.
Conor Brown on the gap between Bitcoin's open-source security teams and the tools available to attackers: "It's time to do something about that. More to come soon from BPI." x.com/BitcoinConner/…

Senator Lummis after the Clarity Act vote delay: "We've come too far to quit. This fight is far from over."
Bitcoin Red Team found and responsibly disclosed the critical BTCPay Server vulnerability. Update to 2.4.2, refresh macaroons, reset LN auth strings, and move any BTCPay-generated hot wallet funds. x.com/BtcpayServer/s…
Stay ahead of the curve. Subscribe to the Bitcoin Brief: tftc.io/the-bitcoin-br…

Bitcoin's Red Team started as an emergency response to the Coldcard disaster. Less than 3 days later: 24 people, 425 projects scanned, ~6,700 findings, and 1,029 classified as high or critical. Moving at 7.7 projects per hour. But the real bottleneck isn't discovery. It's disclosure. Only ~19.5% of scanned projects had a SECURITY.md. Only ~13.1% listed a security email. By hour 55, the team had produced thousands of findings but had only contacted ~130 projects. The scanners move at machine speed. Responsible disclosure is still hunting around for an email address. @OpenSats stepped up and gave the effort a home. Code RED will prioritize support for red-teaming critical Bitcoin software and reimburse past LLM token costs. The dedicated Red Team Fund is live. This week exposed how cheap vulnerability discovery has become and how unprepared most open-source projects are to receive the results. If your code touches bitcoin, publish a security contact. If you can reproduce and triage findings, the Red Team needs you.

Galaxy Research now confirms $111 million in bitcoin stolen from Coldcard users through the RNG exploit. 1,719 BTC confirmed so far with total losses likely exceeding $130M. 88% of stolen coins had been dormant for over a year. Median victim lost about 1 BTC.
BTCPay Server published their full security advisory. The vulnerability allowed "an unauthenticated remote attacker to obtain .macaroon credential files for LND" which could be used to "take control of an LND node and move funds." The risk is specific to LND users. After further review, BTCPay confirmed "only LND is impacted" and on-chain wallets are not affected. The 2.4.2 update also upgrades LND to 0.21.1 and automatically regenerates macaroons. They are "not publishing technical details yet because operators still need time to update." BTCPay credits Craig Raw for the responsible disclosure and Bitcoin Red Team for analyzing the exploit. "We are deeply sorry to everyone affected by this incident. In the coming days, we will work on a full postmortem and share it when it is ready."

"Digital detectives are going sleepless after Bitcoin wallet hack." Bloomberg profiles the community response to the $130M Coldcard exploit. @intangiblecoins, who's spoken with 100+ victims: "These are average everyday people saving their money in Bitcoin. They were true believers." Becca Rubenfeld on the developers working around the clock: "It's like they're off at war. That's the vibe."
Skip the KYC exchange. Own an ASIC, @simpleminingio hosts it, freshly mined sats go straight to you. simplemining.io/tftc
Umbrel pushed BTCPay 2.4.2 to their App Store. Update now, but make sure you also follow BTCPay's additional steps: refresh macaroons, reset LN backend auth strings, and move funds from any BTCPay-generated hot wallets. x.com/umbrel/status/…

University of California professors are asking the school to bring back the SAT after dropping it in 2020 to promote "equity." Turns out their new students can't do high school-level work.

All 8 Flock surveillance cameras in Winona, Minnesota were cut down and removed over a few days. Poles sawed at the base, cameras gone. It's part of a growing nationwide backlash against automated license plate surveillance. Multiple cities have now shut their Flock systems down entirely.
Conor Brown on the gap between Bitcoin's open-source security teams and the tools available to attackers: "It's time to do something about that. More to come soon from BPI." x.com/BitcoinConner/…

Senator Lummis after the Clarity Act vote delay: "We've come too far to quit. This fight is far from over."
Bitcoin Red Team found and responsibly disclosed the critical BTCPay Server vulnerability. Update to 2.4.2, refresh macaroons, reset LN auth strings, and move any BTCPay-generated hot wallet funds. x.com/BtcpayServer/s…
Stay ahead of the curve. Subscribe to the Bitcoin Brief: tftc.io/the-bitcoin-br…

Bitcoin's Red Team started as an emergency response to the Coldcard disaster. Less than 3 days later: 24 people, 425 projects scanned, ~6,700 findings, and 1,029 classified as high or critical. Moving at 7.7 projects per hour. But the real bottleneck isn't discovery. It's disclosure. Only ~19.5% of scanned projects had a SECURITY.md. Only ~13.1% listed a security email. By hour 55, the team had produced thousands of findings but had only contacted ~130 projects. The scanners move at machine speed. Responsible disclosure is still hunting around for an email address. @OpenSats stepped up and gave the effort a home. Code RED will prioritize support for red-teaming critical Bitcoin software and reimburse past LLM token costs. The dedicated Red Team Fund is live. This week exposed how cheap vulnerability discovery has become and how unprepared most open-source projects are to receive the results. If your code touches bitcoin, publish a security contact. If you can reproduce and triage findings, the Red Team needs you.

Galaxy Research now confirms $111 million in bitcoin stolen from Coldcard users through the RNG exploit. 1,719 BTC confirmed so far with total losses likely exceeding $130M. 88% of stolen coins had been dormant for over a year. Median victim lost about 1 BTC.
The Bitcoin Brief
Marty's daily dispatch. The most-read issues of the last 30 days.
Podcasts
The latest episodes. Watch right here, or wherever you listen.
The Round Table
The room is open.
Where Bitcoiners stop reading about the future and start building it — monthly AI-implementation calls, a vetted network of operators, and research that actually matters.
$100/ mo · or $1,000 / yr
Level up- Live AI implementation calls and workshops
- A vetted network of operators and builders — no tourists
- Research briefs when they matter, not on a treadmill
- An always-on private Discord
- Ad-free podcast with post-interview recaps
The Bitcoin Brief
Bitcoin, markets, energy, and the tech reshaping all three.
A daily brief on the freedom tech building a parallel economy, written for the curious and the convicted alike. Signal, not noise. Truth for the Commoner.
Free, daily. Unsubscribe anytime.











