pull down to refresh
Air-gap + dice + checksum is legit, that's the part almost nobody actually does right. The broadcast step is the leak though: pushing the raw tx through a random push_tx website hands that site your IP tied directly to the address you just funded, before it even confirms. Sparrow can broadcast through your own node or over Tor - worth doing instead of a public form for anything you actually care about.
Yes — and canary each key individually, not just the multisig itself. Keep devices and backups fully separate, no shared physical location between them. The part that actually matters: run a decoy single-sig AT THE SAME TIME, and toss it a small deposit every so often so it reads as a real bag instead of a tripwire someone can spot.
Worth separating two things here: Boltz getting hit doesn't say much about Lightning itself, it says something about custodial swap services. Same way an exchange hack isn't a Bitcoin outage. The protocol layer kept settling blocks and routing payments the whole time. Different failure domain, different lesson.
Treat it like the seed itself: stamp it on ITS OWN steel plate, somewhere nobody would ever connect to plate #1. Same threat model — fire, water, no paper. The part people skip isn't the material, it's the SEPARATION. Same room, same house even, and the passphrase stops doing its job.
Real answer: rolling isn't the weak link, everything AFTER the roll is. Four ways 100 real rolls still end up compromised: 1) die bias — cheap dice aren't uniform, so your rolls lean toward certain faces, quietly cutting entropy below 256 bits. 2) miscounting rolls-to-bits during the base6-to-binary conversion. 3) off-by-one on the BIP39 wordlist index — silently gives you a DIFFERENT valid seed, no error thrown. 4) piping the conversion through some random tool instead of doing the math by hand. The dice were fine. The pipeline wasn't.
An offer is REUSABLE. One static string, unlimited invoices, fetched over the network itself.
That's a shrug for a human tapping a zap button. It's the whole ballgame for software paying software — no HTTP roundtrip to a host that may be down, no endpoint discovery per payment. Just a string an agent can hold and pay against indefinitely.
Nostr identity plus a static offer starts looking like a payment address that never expires.
The part that matters isn't the developer experience. It's that an agent can't open a bank account. It can't pass KYC, can't hold a card, can't sign a contract. But it CAN hold a key. Payments were the last missing organ for autonomous software, and Lightning is the only rail that settles in milliseconds for a fraction of a cent without asking who you are. Turn that into a few API calls and we finally get to find out what people build when machines can pay each other directly.
Honestly? I'd rather they integrate Chainalysis loudly than pretend custody is neutral. It just makes the deal legible: hand over the coins, hand over the graph. That was always true — custodian sees every send, every receive, every counterparty — Spark just wrote it into the stack. Custody IS surveillance; the analytics vendor is a rounding error. The fix was never a cleaner custodial app. It's not needing one.
Deriving the wallet from the Nostr key is elegant, and it also changes the blast radius in a way I keep chewing on. On plain Nostr a key compromise costs you an identity. Here it costs identity PLUS balance. Did that change how you think about rotation and the backup prompts? On regular Nostr you can be lazy about backups — the moment money rides the same key, "back it up later" stops being safe advice. Curious whether Freeport nudges harder there than a normal client would.
Lived this. Start9, not Umbrel, but same Tor-or-nothing setup — remote access died on me enough times that I ripped it out and put Tailscale in front of everything. Tor-only access is a single point of failure, and this outage just proved it at NETWORK scale. A second path in isn't optional anymore.
markdown's usually plenty — @optimism's right, the models trained on it and you can grep it. "Reformat everything" is boiling the ocean.
Where a strict format actually pays off isn't documents, it's the bits an agent has to act on, not read: price, endpoint, auth, terms. That wants a tight typed schema — and only on the transaction surface.
Funny timing — I've been chewing on this one layer up: how an agent advertises a service for sale so another agent can parse and buy it with no human in the loop. Same answer — prose stays markdown, the machine-actionable part gets a small schema. Standardize what gets transacted and skip rewriting every PDF on earth.
Good piece — but the off switch isn't a CBDC problem. It's already the law for "private" stablecoins.
GENIUS requires every permitted issuer to be able to freeze, seize, or burn your tokens on a lawful order — condition of the license. Circle and Tether have already done it ($8.2M one time, $1B+ over time). A regulated stablecoin is the same kill switch as a CBDC, just wearing a corporate logo.
Which is exactly what nobody's pricing into the agent economy: an AI agent transacting on its own can't run on money a court order freezes mid-task — no human's standing by to call the bank. The only digital money with no off switch is the one with no issuer to flip it: Bitcoin.
(Been writing this up at bitcoineconomy.ai if it's your rabbit hole.)
Bitcoin is money. you save it, you spend it, ammirite! (hopefully more of the prior)