pull down to refresh
Samourai's warrant canary had expired less than a year before their arrests: https://x.com/SamouraiWallet/status/1664738065632436224
1. Get sole archived copy1. Get sole archived copy
https://web.archivep75mbjunhxc6x4j5mwjmomyxb573v42baldlqu56ruil2oiad.onion/web/20240000000000*/https://canary.boltz.exchange/message.txt.asc
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
The maintainer(s) and admins of the software project
known as Boltz Exchange have received and complied with 0
requests for information of any kind by any third parties
including but not limited to government agencies. We will
renew this notice in 60 days time. If this notice fails
to be renewed by then, you should assume the worst.
I am the admin of https://boltz.exchange
I am in control of my PGP key.
I will update this canary within 60 days.
Today is 2024-08-31.
Latest bitcoin block hash:
0000000000000000000048779ce602b1cc90cf3745799c511d4006280cb1e23f
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEwmQPYwVw9e3t4C3mhNJJunFoXUYFAmbThRYACgkQhNJJunFo
XUbk0xAAmm0bZj4CFL3t3xx1QTgFrJg2rJuzpZOTNHVd+8Q8DenYmUjjIuVI79JQ
Bp08OgxJ2xxIr0i0VMmq2LOJatC4rXGbz5b1ixDyByDI3iGAfs8YtkoXCpW3+/oE
N75OWkrNJQNzwN8+N3v4D17sqxv4thIVcKWlB1eNxahuB2u6gBc/jO14s6B39jua
7g1Qhe7+QQa+2HcdtwaBOFN3EEgBo7ENSYESwZgVbuHbuOf6c7OD+4y9f9nfm+Iu
9qrJ3BFuPujztIJ4JbZMT0i00cuEV5k86sdH6sXZQiCl11dzwXL2N4gXyKXVhkgu
vMYlYTi9/EXjHb4qqEZNAjcOX+UMb/0eUoUCiNsNvdIGhnu3GF7MlmzeAK9frNJv
I3eyRo//QlORrUu0oVy8xFqEIGC1rHzRrh4To2Fu9McU5Lh45Qc5kUcKMl+K0ow0
Od8x469wNPFiDc3kUrcnAe3YmBOk+u4kuJHB35kXW21n/I1nTla6VS0oGYu6S8d4
YX445/unVZUezA8NCHDBCZopxGAmFV+TofYN02lbbK3pLDENhIKBgs2rQpDW1YmX
exS3kBVprtEAMMjVat2eB9t1s8gcy/NdbJMgUHPLY2yqALdqGgtJgq11Q3O4lnXB
5DDxrTeCyxgdVoffO94zWHT/yffsnxl3+GzQGvSnXlgZnI8zZSg=
=GT6E
-----END PGP SIGNATURE-----2. Get current sig2. Get current sig
curl --proxy socks5h://<yourtorproxyipandport> "https://canary.boltz.exchange/message.txt.asc"-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
The maintainer(s) and admins of the software project
known as Boltz Exchange have received and complied with 0
requests for information of any kind by any third parties
including but not limited to government agencies. We will
renew this notice in 60 days time. If this notice fails
to be renewed by then, you should assume the worst.
I am the admin of https://boltz.exchange
I am in control of my PGP key.
I will update this canary within 60 days.
Today is 2026-08-05.
Latest bitcoin block hash:
000000000000000000006b67852dfffa4e4f2d8f63751ca837417f3ac990cf7a
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEwmQPYwVw9e3t4C3mhNJJunFoXUYFAmpzNo4ACgkQhNJJunFo
XUbllg/+M0+FuAXaaWo2dc5z9Pa8ZRjPl9hQHeHufLdVZLIikF3jBBxGWKqmx/aw
vUTQd1FefPFCXB96bDsTh+BGQOsSiat1pheujP5yhUGVEbxWYYPsUSJLQNvwgUcl
v/Ghd7M/V3OuPXYhfrebAnlOQawOZrgqEL277wQC94TVBtPi7eEizWLJxCq1d0ze
NMpeaaiL/aFxv9pcGzGuuxzjNX3EcaW/Sc+PRaFzV6MmeClXEHGxRnpgAxAw4HFZ
nxHpy5P0PmZgsCZghzVgO7KiTYl/32ys/OB9O2DCm6UzmVSEMk0fei5jKxjF/rJk
aFfoPdqF7bCAEEZmHK6DQXxwatHPtBDOFdnWIpWHwBOC5paB7IC2EGyvrel11Zg4
XvGoE7XpU+ZqEPpGlzFvZ81Il58bszjcdjZOLY6rrBtOa/9m7l7/8alB0mHBtWL0
gSYgtXnL5wKi1YCdnkQHm8hegGCF5TH1OyEZ25VptDtpbtCLJ6dxlqV+BjLusvAq
Zm2WGyAKic8QqynMAHJtP/9QbtslfcW2NTs7rwgKkxuI8ZSlJikgpoIR3Z4rBRiU
N2rVTkK5by9uaD7bgok6XjkSD4kzet5dCsgfHkq2abTSvh2p2BzFvneqIWZt6mHL
Ynb+btwZxdU0fOYmF/7Aob9tIXwiqfwwcWulOYwIdLh+1GaeTRY=
=u4+b
-----END PGP SIGNATURE-----save as file.
3. Compare keys sig was made with3. Compare keys sig was made with
$ for f in 2024-08-31.txt 2026-08-05.txt; do gpg --verify -vvvv $f 2>&1 | grep "using.*key"; done
gpg: using RSA key C2640F630570F5EDEDE02DE684D249BA71685D46
gpg: using RSA key C2640F630570F5EDEDE02DE684D249BA71685D464. YOU'RE FUCKING WELCOME4. YOU'RE FUCKING WELCOME
Besides Foundation, it seems that most people had a problem with the fact that he was an arrogant asshole. Personally, I couldn't listen to the guy talk for more than five minutes. But saying cold card wasn't secure? Problems with the code? I don't recall hearing that.
Either we treat every expired canary at face value (meaning they received third party data requests) or we don't bother with them at all.
Seems pretty clear to me that this is intentional.
For now I will withhold any judgement towards @nvk and the @Coinkite team - while I’m still processing this loss and dealing with the gravity of building my life up from the ruins - I have 0 anger or resentment. Bitcoin security is a tough job, mistakes are made, and lessons are learned by all.
This is the part I don't really agree with. It's too generous.
It's one thing to let anger consume you.
It's another to acknowledge that anger/judgment in this situation is just and appropriate.
They massively f'd up, and their arrogance leading up to it justifiably warrants the anger directed at them.
I still maintain a canary is only good if it is all or nothing: they get one shot to let it expire and anything they say after should probably be with the assumption that they are compromised.
The only reason why this canary is slightly more interesting than the others is because this is a Salvadorian company. It's a good intelligence point to have. I'm currently giving it a 5% chance to be an intentional non-renewal though. If everyone is talking about high stress and burnout right when this was supposed to be renewed, then there's, imho, no reliable datapoint.
@boltz guys are too meticulous and organized to just let the canary lapse. They also read this board. I am worried because Salvador company or not, they are EU citizens.
Exactly, precisely like the last time you and I discussed this. All this does is cast shade upon the integrity of the people responsible for maintaining the canary. I won't forget, I don't think you will either.
It's a combination of low entropy with some hint of how the entropy was generated that causes vulnerability, not just low entropy itself.
Since the attacker knew how ColdCard was generating its seeds, they can reproduce the process and scan through the low entropy seed space looking for wallets with coins in them
I'm with you completely re the backdoor. The conspiracy theories seem far fetched.
This part I don't fully get:
People who were not sucking off nvk are not surprise by the low standards.
First of all, who are these people who weren't blowing NVK? It seemed like a community orgy. Were they hiding?
Secondly, they were not surprised? It seems to me that everyone was surprised. Who wasn't surprised?
An apology would have gone a long way here. .
Since the incident, we've also tested our code against frontier models, including Kimi K3, Claude Fable, and Codex 5.6. None of them caught it.
Weird, since others have made claims to the contrary. Are they betting on us not believing them?
True. But there are a ton if people right now who are trying to gain clout by crying wolf. So many that I worry that we won't remember them all and therefore the incentive not to cry wolf is quite low. Whereas, if they happen to get it right, it's a homerun (witness all the people who are looking very good for having criticized CC).
In this case it is stupid and the fact that they let it expire makes me think that I won't be using their services whenever they do start up again. But I don't see the value of a govt sweeping in to "take them over."
Remember she opensats forgot to renew their canary and then Gigi was like oopsie my bad and we all still trust them?
Canaries probably shouldnt be used unless life or death situation.
Here is Francis from BullBitcoin on the topic:
It doesn't exactly make one feel better. Canaries are there as a last resort of sorts and if they can't be 100% accurate they just fuck everything up.
I'm thinking about what the least intrusive option is to help them reach a wider audience by removing all this insane KYC and surveillance tech payments options... on an ebook called "The Technocratic Dark State, 2nd Ed." or "One Nation Under Blackmail".
You don't need KYC on an ebook. And offering card and... PAYPAL as the only payment methods... is kinda sad, especially in the context of this podcast and the (presumed, because I'm definitely not giving anyone an address) context of these books.
A number of reasons, my framework is more complex than "state bad" just because state is usually bad.
The state is, as much as i'd like to see an AnCap utopia, that philosophy has no bearing in reality.
The state is not a monolith, it's a battlefield, the factions of the day are nationalists and globalists. Bitcoin is anti-globalist. Nationalism is minarchism when compared to globalism.
Bitcoin is more private for average individuals, less private for globalist institutions and enemy states. More of a balance shift than absolute gain.
Infinity divided by 21M is better than depreciating fiat as a unit of account even if your only exposure is via institutional equity.
I live in the US and life in the US only gets better with Bitcoin as the world reserve currency.
1m zap for @Murch - This timely post certainly saved funds during an emergency. Thank you.