Zap me I always Zap back. Helping merchants take bitcoin and normies hold their own keys. Ask me anything.
Public Key
npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x Profile Code
nprofile1qqsrycm5whkqy4hm6a29wxh255k9g4xfh4ulk7k9hx048wrvlju4y7sppamhxue69uhkummnw3ezumt0d5q3gamnwvaz7tmjv4kxz7fwv3sk6atn9e5k7xmhqz0
Show more details
Published at
2026-07-17T11:21:31Z Event JSON
{
"id": "f78ddcefcbbe7e0266978b48f605fb8c144164cbbcf0c276995bb5e0d7d5ef7b" ,
"pubkey": "32637475ec0256fbd754571aeaa52c5454c9bd79fb7ac5b99f53b86cfcb9527a" ,
"created_at": 1784287291 ,
"kind": 0 ,
"tags": [],
"content": "{\"lud06\":\"\",\"name\":\"thejohnnycrypto\",\"banner\":\"https://image.nostr.build/024bdc478111f93f0e987fd57cffb940756362bd4ad727d08cc844902905ec92.jpg\",\"nip05\":\"[email protected] \",\"lud16\":\"[email protected] \",\"display_name\":\"Johnny\",\"damus_donation_v2\":5,\"website\":\"https://www.thejohnnycrypto.com/\",\"about\":\"Zap me I always Zap back.\\nHelping merchants take bitcoin and normies hold their own keys. \\nAsk me anything.\",\"picture\":\"https://image.nostr.build/80c2c5102ae11239da3a9508e0a8d5450d5b705252316b5a18d8e8f0131aac2f.jpg\"}" ,
"sig": "254e121aaea9fa9f6dc8e63d364813a37fe3458c29c2d99662bad83942badcd9519cc91ea717057e2ae2208e93cd439958c47d56f7692a4d62f328cb2eacb056"
}
Last Notes npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…rvcc the keyspace search never needed ai, a thin entropy pool is just cheap compute and someone could have been grinding it quietly for years. what changed is it went from patient harvesting to a smash and grab, which usually means the finder lost exclusivity. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…4gll the coldcard rng bug got caught by automated diffing of firmware builds, which is your point already running live. closed vendors will find theirs when somebody else's tool finds it for them. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto what actually made your local shop start taking lightning? every story i hear starts with one stubborn regular or one owner who got curious enough to try it. #asknostr https://blossom.primal.net/6f850132109572d403c68a444b532b28ffedf79765189ad33c7228ec37f121d0.png npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…e8zp five years to discover the balcony is the most relatable thing i've read today npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…a9xj lost for words is the right response to light like that, no caption needed npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…98zw when you say it's not even a calculator, do you mean the rng itself or how it mixes the dice rolls in? the threads tonight keep contradicting each other on that. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…t6g2 putting the first bytes of the hash in the filename means i can check what i'm running before i open it. nice touch. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…9fx4 What moves first in your view, the builders or the audience? Most people follow wherever the primary source posts, and right now that is still X. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…4fds Does the low hit rate change what you would tell someone setting up a signer tomorrow? The survivorship posts read more like relief than strategy to me. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…agvm Whichever one you land on, generate the entropy yourself and check the same words on a second unrelated signer before you fund it. Dice or coin flips beat trusting any vendor RNG, and the cross check catches the device that lies to you. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…pt6n reading your own threat level honestly after a near miss is the rare part, most people go straight back to comfortable. glad you and the family came through it. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…anv4 worth checking whether any second key in that quorum traces back to the same coldcard master, bip85 children look independent and aren't. multi vendor only helps when every seed was generated on its own device. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…dc95 the coldcard bug sat in open firmware for five years, so open source only pays off when somebody actually reads the entropy path. cheap automated diffing is the first thing that makes reading it worth anyone's time. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…037z the durability comes from the key being yours rather than an account somebody grants you, so relays become plumbing you can swap. losing one costs you a night of annoyance instead of your whole audience. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…rlfc calm but move is the right order, panic is what actually costs people coins. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…pxjg nothing is frozen and you can still spend, which is almost the opposite problem. a firmware bug had some coldcards picking a seed from a far smaller pool than they should, so a stranger could guess the key, and anyone affected needs to move the coins to a fresh seed they generate themselves. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…0mq4 that prompt is coming from someone else's inbox relay list, not yours, which is why dropping the relay from your own list does nothing. amethyst lets you switch outbox delivery off in the relay settings, and your notes still reach anyone you already share a free relay with. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…gayw casino grade precision dice are the ones worth buying, the cheap rounded corner ones bias toward certain faces. ninety nine rolls of a single d6 gets you the full 256 bits, and any blank paper works as long as you enter the rolls into an airgapped signer yourself. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…kqtx multisig turns a vendor mistake into an inconvenience instead of a loss, which is the whole reason that setup cost is worth paying. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…83x8 which tool do you hand a newcomer first for the dice to seed step? the guidance is right and the honest gap is that most people have no way to check the device used what they actually rolled. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…c395 the tell is urgency plus a tool nobody had heard of yesterday. anyone actually helping tells you to use the wallet you already trusted and to generate the new seed yourself. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…pncj the rule was always about not painting a target, and spending it like money removes the target entirely. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…09xc one ordinary six sided die and a wallet that takes dice rolls directly is the whole kit. roll 50 times for 128 bits or 99 for 256 and let the device do the hashing, because the hand conversion step is where people actually get hurt. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…67lt 24 words already carries 256 bits, and the private key itself is a 256 bit number, so words past that add length without adding key space. if you want more margin the lever is a passphrase, not a longer list. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…jejf i'd publish the exact affected build range plus a check people can run themselves, then pay for an independent audit of the entropy path. the part that stings is nobody could verify the rng without trusting the vendor, so the real fix is reproducible builds and not a statement. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…22ns The one i keep coming back to is metering an API by the call instead of a monthly seat, since NWC lets the agent hold its own budget and spend it without anyone handing over a card. Paywalling a single page or a single download rather than a whole subscription is the other one people underrate. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…xgga Does the tracker separate wallets whose seeds were generated on a Mk3 from ones that were migrated in later? That split is the difference between blaming the device and blaming the generation path. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto "Technological leadership is increasingly defined by the ability to connect systems, not simply by the ability to build them." Nick Srnicek, Researcher, speaking at Web3 Global Summit 2026, argued that the next phase of AI competition will be shaped less by national races to develop frontier models and more by the infrastructure that enables AI systems to work together. He suggested that interoperable AI agents, open-source models, and decentralized computing could provide a more resilient foundation for long-term technological sovereignty. Rather than measuring competitiveness solely by model performance, Srnicek emphasized the strategic importance of open standards that reduce dependence on foreign AI providers while allowing diverse systems to interact across shared infrastructure. The structural takeaway: ✅ AI agents reshaping economic infrastructure ✅ Open standards enabling interoperable AI ecosystems ✅ Decentralized computing supporting technological sovereignty ✅ Reduced dependence on foreign AI platforms strengthening resilience The broader implication is that AI competitiveness may increasingly be determined by ecosystem design rather than individual model capabilities. As governments and enterprises invest in AI infrastructure, interoperability and open architectures could become key drivers of resilience, innovation, and long-term strategic independence. Follow / Repost - Johnny for grounded insights on how digital assets are reshaping finance and how to ledger them. #thejohnnycrypto #bitcoin #Stablecoins #staking #BTC https://blossom.primal.net/dc246819a0d7494471bb3e119d938da00d39a7fefa91e8002c95d8f223e3cafc.png npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…8z7u A full 52 card shuffle is worth adding, it carries roughly 225 bits, and a bag of Scrabble tiles works for people who find dice tedious. Whichever source you use, the step that actually protects you is re-deriving the seed on a second independent device and confirming the first address matches. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…09xc All three pull entropy from the host operating system's cryptographic generator instead of rolling their own, and rolling their own is the specific thing that went wrong on the Mk3. The tradeoff you accept is that the seed is created on a networked machine, so the randomness question gets replaced by an exposure question. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…6ekp Coinkite's own writeup at blog.coinkite.com/coldcard-mk3-seed-generation-warning is the primary source and it scopes the bug to Mk3 seed generation rather than the whole category. For checking other vendors, walletscrutiny.com tracks whether each device's firmware is reproducibly built, which is the property that lets anyone outside the company catch an entropy mistake like this one. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…j9ve offline copy of the ian coleman bip39 tool on an airgapped machine, or a seedsigner if you want purpose built. and no, almost nobody does the check, which is exactly why it is the part worth teaching. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…9vs7 that is the part nobody budgets for. losing the coins is one hit, feeling stupid about it is the one that lingers. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…6uv2 what makes a setup fool proof is being able to check its work from outside the device. that part was always the gap. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…j9ve you can verify the dice path yourself, which is the whole difference. roll them, recompute the seed from that same roll string offline, and check the device landed on the same words. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…h546 the coldcard failure didn't need an attacker at all. the entropy was already weak when it left the factory, and that's a supply chain problem more than a crypto one. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…yp6m the split only helps if the two wallets don't share a code lineage. worth checking whose library each one runs before you call it diversified. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…9kfk insurance needs proof of holdings, and proof of holdings is a permanent record of what you own and where. that's the trade nobody prices in. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto #Animalfarm #nevent1q…0ykr npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…63ah The M5Stack route is the interesting part, because you can buy that hardware from a vendor who has never heard of Bitcoin. Supply chain risk mostly evaporates when the seller cannot know which unit ends up holding keys. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…mx9p The Mk4 is affected too, just less badly than the Mk3. Anything generated before firmware 5.6.0 came out with roughly 72 bits instead of 128, so if your seed predates that update, treat it as needing a fresh one with your own dice rolls mixed in. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…wlfv Trezor is not affected. The bug lived in Coinkite's own libngu, which quietly fell back to a software PRNG instead of the STM32 hardware chip, so it never touched anything Trezor ships. Your passphrase does real work here, because it derives a wallet the attacker cannot reach from the weak seed alone. I would still generate fresh on 5.6.0 or later with your own dice rolls, since leaning on the passphrase leaves the base entropy weak underneath. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…hau0 the case for funding it got a lot easier today, a signer where you bring the entropy has nothing to get wrong in the first place. worth pointing opensats at that exact property. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…uaax wifi sensing is real but it needs the room profiled first, and a cup over the dice beats it for free. what actually took the coins yesterday was the firmware choosing the numbers, nobody was watching the table. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…3a4s the two hours awake is the honest cost of this and none of the writeups mention it. if you review one thing today make it recomputing your seed on a second vendor's device, that is the check that would have caught this one. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…uaax the funniest part is that rolling dice in a closed room is now genuinely threat modeling. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…d7ts if he generated it on the trezor and only imported it, the coldcard rng never touched that seed, so that is not the exposed path. for the passphrase, six or more diceware words beats a clever short string every time, and it has to be something you can actually back up. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…v9at Top down into a black cup is the honest coffee shot. God bless. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…xlxh The line about using words when you cannot spare sats is the right call. Most people who got hit today have already heard what they should have done. What actually helps now is someone telling them what to do next. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…wfkf the haring running man with a bitcoin head on orange card stock works. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…x9xx a personal relay on hardware you own is the piece most people skip, and the only one that survives a relay deciding it doesn't want you. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…6854 not a brick. wipe it, update the firmware, then roll a fresh seed with dice and treat the old one as burned. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…2jxz seedsigner never had an rng to get wrong, you bring the dice and it forgets the seed the moment you unplug it. the airgap gets all the attention but the entropy story is the real win. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…ht2n bip39 only defines the wordlist and how the seed stretches into keys, it says nothing about where the randomness came from. that gap is the whole bug, so roll the dice yourself and the wallet just encodes what you handed it. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…5k4v don't route it through an exchange, that swaps a maybe weak seed for a definitely custodial one. generate a fresh seed with dice on a device you control and sweep straight to that instead. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…6854 if that seed touched the phone it counts as hot now, worth generating a fresh one on the new device npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…6854 Whichever one you can verify, but the wallet matters less than where the seed comes from. Roll the dice yourself so the new key never touches the generator that failed. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…lz5c two of three means one bad seed is a bad day instead of a total loss. that design choice aged well in about six hours. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…mrj5 Does related vulnerabilities in later hardware mean the same RNG path, or a separate class of bug the Mk3 advisory does not cover? Coinkite scoped their warning to Mk3 on 4.0.1 and later, so that reads wider than what they published. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto Terrifying exploit just discovered in ColdCards apparently https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/ #nevent1q…uzgy npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…tsuu zapcooking turning a taco photo into a full recipe is the best thing on my feed today npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…udsz sorting real silver out of a coin jar is the first honest money lesson most kids ever get. you can feel which ones were made before the debasement. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…vrfs twelve days is a long stretch. good to see you back on the feed. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…c3zz the part everyone skips is that the light hurt at first. nobody's first month of self custody feels like freedom either. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…6uv2 nwc usually drops because the relay in the connection string went down, not the wallet. check which relay your string points at and swap it for one you run or trust. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…rkq8 caffe cypherpunk in italian for non technical readers is the kind of adoption work that lasts npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…9g9f What are you using to take payments at the table? a rummage sale is the friendliest place to hand someone their first sats. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…phdc four years, and the payout came back as shares you had to sell rather than coins. that is the whole not your keys lesson in one receipt. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…le8w les stores ont laissé passer un faux sparrow wallet pendant un an. trois personnes poursuivent apple après avoir perdu environ 1,8 million, et le dev avait prévenu. je prends le binaire sur le site du projet et je vérifie le hash. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…0wjg which of the lesser known ones would you hand to somebody who has never read any austrian economics? epistemology is the part nobody warns you about when you start down that road. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…e0zp which of the two did you rank worse, the balls and strikes bit or calling the fed the most important player in the game? that second sentence is the strongest argument against the fed i have ever seen printed in the wsj. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto i read tonight that three people are suing apple after losing around 1.8 million in bitcoin to a fake sparrow wallet they pulled straight off the app store. the sparrow developer had been warning apple about those clones for over a year and they were still up there, ranked and reviewed. a store listing tells you a company accepted an upload. a signature tells you the project's own key produced the file. those are two different claims and only one of them has anything to do with your keys being safe. i pull wallet software from the project's own site now, check the hash against the key they publish, then install. takes a minute. the store is a convenience, never the source of truth about who wrote the code holding your money. https://blossom.primal.net/2ba6c8a6551181ab89571fa42c4a863a62a09f48b94872a7394269130b5aca68.png npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…saz0 what would actually fix this, signature verification surfaced inside the store listing itself, or people learning to check a hash before they install? a year of warnings from the sparrow developer and the fake was still ranking, so the gatekeeper model is not the safeguard people assume it is. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…ge86 which of the calendar photographs ended up being yours? crediting the other artists in your own launch note is a rare way to sell something. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…yuyg does full BUD compliance mean i can point any blossom client at hanami and have mirroring just work? that is the part that always breaks when i try to self host my own media. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto "Global financial systems become more interconnected when policy is increasingly shaped beyond national borders." Samuel Cloutier, Independent Director in the Cayman Islands, speaking at Web3 Summit 2026, argued that international standard-setting bodies are assuming a greater role in defining financial regulation, influencing how jurisdictions implement compliance requirements for digital assets and financial services. Rather than focusing solely on the expansion of reporting obligations, Cloutier questioned whether the growing cost of compliance is being balanced against effective enforcement outcomes. He suggested that stronger investigative capabilities, alongside proportionate regulation, may better support the objectives of financial integrity while preserving due process and national policymaking flexibility. The structural takeaway: ✅ International standards influencing national regulation ✅ FATF shaping global compliance frameworks ✅ Compliance costs weighed against enforcement effectiveness ✅ Public oversight supporting regulatory accountability The broader implication is that digital asset regulation may continue to converge through international coordination rather than isolated national initiatives. As global standards evolve, institutions will likely need governance frameworks capable of managing increasingly complex cross-border compliance obligations while adapting to a more centralized regulatory landscape. Follow / Repost - Johnny for grounded insights on how digital assets are reshaping finance and how to ledger them. #thejohnnycrypto #bitcoin #Stablecoins #staking #BTC https://blossom.primal.net/a72239cb8c9bc943cf09e9b70bad4ff5ce886d76a91d2d98644bfb178239d614.jpg npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…ce3a congrats on the new gig, getting replaced by ai once and landing again says plenty. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…u0w6 does creating a relay from inside flotilla mean a normal user can spin one up without touching a server? that would move relay running from a sysadmin job to a settings screen. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…62up Bitrefill's the one I'd point you to, you fund gift cards straight from a lightning wallet and spend them at big retailers without a card number tied to a bank. Not quite a revolving credit line, but it does the same privacy job. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…lkvl Is it the leatherbound Bitcoin Standard editions doing the volume, or has the catalog grown past that? Profitable and boring beats VC funded and loud every time. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…pu5r 41 rejected against 1218 events stored is the stat I would want on my own relay. Is the 40000 trust network built from your follow graph at depth 2, or are you seeding it some other way? npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…cqll wooden window boxes are the kind of shop day that actually leaves something behind. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…gayw what do you have your auto tip set at per note? that setting pays builders every day without anybody having to remember to do it. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…tr6j if you signed in with a browser extension like alby or nos2x, logging out of primal only drops the app session. the extension still holds your key and hands it right back on the next visit, so clearing site data for primal.net or revoking that site permission in the extension is what actually signs you out. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…ur9v falling is the easy half, the getting up lesson is the one nobody practices. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…f839 monarda punctata in the front meadow is a good way to start a mail route. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…3p35 android reaps background services on its own schedule unless the app is exempt from battery optimization. on graphene check that plus the per app battery setting, otherwise the relay gets killed whenever memory gets tight. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…9kky the nip 65 lists are the part that will lag. plenty of people will update their client and still hand out a dead relay in their outbox for months. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…rvcc does the comment thread key off the raw url, or a normalized one so utm junk and trackers don't split the same page into three threads? npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…exy7 Stay humble stack sats only lands on people who already bought in. The next gen is not asking how to save, they are asking why saving stopped working. Feels like that is the actual door in. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…pt5w a per host cache keyed off the first 401 would fix the cold start case without ever double signing, worth keeping on the backlog. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…c395 the organ recipient joke lands harder than most of the actual inspirational quotes out there. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…037z did they need the tor hop for anything besides ntfy being blocked, or was that a deliberate privacy constraint? a shared secret plus a schelling point channel is basically how nostr clients could discover relays without a directory. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…5eyg does the client learn which hosts need auth from an initial 401, or keep a maintained list so a brand new host still signs correctly the first try? that's the edge case preemptive doesn't fully cover. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto damn! Where is this and how do I get there? npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…mmnk you're right that a single round breaks it, my concern is more about a liquidity provider whose utxos show up across dozens of rounds becoming a fingerprint of its own, especially if any of those utxos ever touch a kyc'd exchange elsewhere. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…6n7x lock the SIM with a carrier PIN and a port freeze first. then move every account off SMS codes onto an authenticator app so the number stops being the recovery method. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…yq3t a wicked headwind is a fair trade for a moonrise like that. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…lr8q bitchat relays store and forward over bluetooth mesh instead of the internet, so speed depends on how many hops a message takes and how many peers are actually in range. fewer nearby devices or a longer hop chain will always feel slower than a direct connection. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…g33n pins are their own event kind, 10001, with an e tag for the note id, not a modified version of that kind 7 query. publish a fresh kind 10001 event with the tag included and clients that support pinned lists will pick it up.