Socratic Seminar 56
September 09, 2026
Event Time: September 09, 2026 at 06:00 PM EDT
We will start with introductions, cover some basic ground rules, and then jump into technical discussions.
Please note the meeting location is at 100 New Millennium Way, Durham, NC 27709, USA.
Announcements
- no pictures or recordings
- follow the chatham house rule
- discuss what was said, not who said it
- don't be a jerk
- thank you to our sponsor Fidelity Investments
- introductions
The Liquid Hack
- Mempool: Liquid got got — 4000 BTC unauthorized withdrawal
- on-chain: the ~4,000 BTC peg-out via SideSwap
- Liquid's official incident report: range-proof cache flaw in Elements, no keys compromised, reserve ~4,205 BTC → 197 BTC
- LLFOURN: Liquid Incident Brief — independent chain tracking
- the on-chain negotiation, in the operator's own OP_RETURNs:
- message tx: "we are whitehats. contact us on chain"
- Mononaut: new OP_RETURN message(s) surfacing
- "sending most back to bc1qdlld6…, is that ok" — 1,000-sat ping
- 3,400 BTC returned to the federation peg wallet
- PGP-encrypted payloads in between — not reproduced by anyone
- Sep 9: authenticated OP_RETURN demands a 10% bounty; ~598.5 BTC consolidated back to the operator, not returned
- Elements v23.3.4 emergency release: harden range proof cache keys, add -norangeproofcache
- Guillemet: "if this was ever a negotiated reward … it looks more like extortion than white-hat hacking"
- discussion:
- the "is that ok" message, an 85% return before any payment, and then a plaintext 10% bounty demand — is that extortion, ransom-style bargaining, or theft with a claim of right? where's the threat?
- the 15% holdback is authenticated to the operator key, but the PGP payloads are unreproduced. what evidence would actually settle the white-hat vs. extortion framing?
- no federation keys compromised — the failure was a range-proof cache key collision at the transaction layer. what does that say about federated sidechain custody vs. self-custody on L1?
- the network is still offline and the invalid peg-out has not been rejected. who bears the shortfall risk while ~598.5 BTC stays with the operator?
Bitcoin Core
- Bitcoin Core HWI repo wind down
- static-pie release binaries available for testing
- Bitcoin Core 30.3 released
- Bitcoin Core 29.4 released
- libsecp256k1 v0.8.0 released
- txindex: hash keys and pack positions to reduce disk usage
Soft Forks and New BIPs
- BIP458: Half-Aggregation of BIP 340 Signatures
- BIP459: DahLIAS fully aggregated signatures for secp256k1
- BIP460: CISA for Taproot Key Path Spends
- BIP461: Deterministic ECDSA Signatures
Post-Quantum and Cryptography
- SHRINCS draft BIP
- using formal verification tools on libshrincs
- DropKick: a minimal commit/reveal PQ rescue protocol
Lightning Network
- Boltz: swap services "disabled until further notice"
- Threshold multisig lightning channels
- Disclosure: LND doesn't wait for enough confirmations when closing channels
- Disclosure: crashing CLN with a flood of pings
- discussion: if a swap service's hot wallet can be drained or disabled, what does that mean for swap-based self-custody UX?
Ark
Payjoin and Privacy
Signing Devices and Self Custody
- The DIY Signing Device Revolution is Just Beginning
- MARA: 9K bitcoin rescued out of Coldcard multisigs via Slipstream
- Tracing the attacker's steps through 1,082 BTC Coldcard drain
- live dashboard mapping the ongoing Coldcard attack
- Trezor: recent customer data exposed in shipping provider incident
Wallets and Apps
- higherMark desktop/web app demo
- BTCPay Server security incident: our response and next steps
- Sparrow 2.5.4
- Peach is at a crossroads
- Glow: a bitcoin app for everyone, built on the Breez SDK
Mining
- SpiderPool mines two blocks at same height 963853
- Miner leaves full subsidy unclaimed
- RY3T NOVA: the first product built on Mujina