WEDNESDAY, AUG05
1. bitcoin's volunteer red team, 2. Boltz goes dark, 3. Nvidia's open road-robot brain, 4. disclosure norms under strain, 5. BitMEX signs off, 6. Texas audits the grid queue
From Proto and Bitkey - part of the Bitcoin ecosystem at Block, Inc.
1. redteam
Rob Hamilton has published a progress report on the Bitcoin Red Team, the volunteer effort scanning the ecosystem’s open-source code in the wake of the Coldcard exploit, according to his post on X. The numbers: roughly $20,000 spent across services, 150 repositories scanned, and more than a dozen coordinated disclosures, with funding secured and donations declined. Hamilton has built a first-pass agent harness that needs only an opencode zen API key, using Kimi K3 for the heavy lifting and GPT Sol, Fable, Opus and GLM5.2 for supporting documentation, and he is also running OpenAI’s more expensive Cyber Harness against load-bearing parts of the ecosystem, where it has already yielded results. “Our goal is to open source the harness so it can be pointed at internal repositories,” he writes, so hardening can go deeper than public code. The choke points are now human: request staging and report handoff. This is the counterweight to agentic attackers — the same models that broke the review asymmetry are being drafted to close it.2. boltz
Boltz has suspended its swap service indefinitely, taking a core piece of non-custodial Lightning infrastructure offline, according to the company’s post on X. The team says the shutdown is not a reaction to a single incident but to a months-long rise in automated, AI-assisted probing that produced several contained exploits — and a drastic acceleration in recent days from what appear to be multiple resourceful groups. The asymmetry is the stated reason: “attackers now iterate faster than a team our size can find and patch,” and Boltz does not believe that reverses. The company stresses that no user funds were ever at risk, its API remains available for cooperative refunds, unilateral refunds work without its infrastructure at all, and as a bootstrapped firm the losses were its own. It calls the moment a paradigm shift for bitcoin services running on open-source stacks. The design held — non-custodial architecture meant users lost availability, not money — but availability is exactly what agentic attackers are now able to take.3. alpamayo
Nvidia has launched Alpamayo 2 Super, a frontier open reasoning model for autonomous vehicles, released for commercial use under the OpenMDW-1.1 license, according to CEO Jensen Huang's post on LinkedIn. The design goal moves past perception — the model reasons through complex driving scenarios before it acts, and Huang positions it as a backbone for robotaxis, trucks, shuttles, delivery vans, tractors and the long tail of mobile robots, a market he sizes at billions of autonomous machines someday. The architecture pairs a large Cosmos-based reasoning model with compact distilled versions that run in-vehicle on DRIVE AGX Thor hardware, so frontier-scale reasoning happens in training while real-time inference stays at the edge. The licensing is the strategic tell, with Nvidia publishing the model "so teams can inspect it, fine-tune it and deploy it — open models advance safety and security." Huang calls robotics the next wave of AI, and open weights are becoming its trust layer: when software drives two tons of steel, inspectability stops being a philosophical preference and becomes a safety requirement.4. disclosure
Bitcoin maintainers are drawing a line on how AI-discovered vulnerabilities should be reported, after a researcher posted claimed proof-of-concept exploits publicly rather than disclosing privately, according to Miles Suter’s post on X, amplified by Matt Corallo. Suter welcomed frontier models being pointed at open-source code — more eyes, better ecosystem — but was blunt about method: “this should be done over email, and not in public where unverified claims can lead to false narratives and unnecessary panic.” He acknowledged the researcher’s claim within thirty minutes and said the team is investigating, while noting that even cyber-focused models can produce slop. Security engineer rot13maxi compressed the norm into one line — tweets are not responsible disclosure. The context is a community on edge, with Coldcard sweeps ongoing and Boltz dark. The disclosure pipeline is becoming the scarce resource: AI has multiplied the rate of plausible findings, and the ecosystem’s safety now depends on routing them through verification rather than through engagement algorithms.5. bitmex
The team behind BitMEX Research has published a farewell accounting as BitMEX prepares to wind down in September, closing the research desk after almost ten years, according to the Farside Insights post on X — the renamed BitMEX Research account. The retrospective is unusually candid about why the exchange faded: slow stablecoin adoption, regulatory friction, the March 2020 downtime, a management layer beneath the founders that lacked domain expertise, and clients lost to fraudulent platforms faking superior backends. It is equally clear about what BitMEX refused to compromise — a manual once-per-day three-of-four multisig wallet and real-time audits and reconciliations. The grant program donated over $2 million to open source developers, and “BitMEX was the first profitable operating company in the space to give no-string attached grants to Bitcoin developers,” a model now continued by Maelstrom, Arthur Hayes’ family office, while Localhost Research takes over bitnod.es and ForkMonitor sponsorship. The public goods outlive the exchange — grants, node monitoring and a research archive headed for a CC BY 4.0 release.6. moratorium
Texas Governor Greg Abbott has directed the state’s Public Utility Commission and ERCOT to audit every data center seeking a grid connection, and Bernstein argues bitcoin miners come out ahead, according to Robert Lakin in Cointelegraph. Most Texas miners already hold approved capacity under contract, so the freeze on new connections falls on speculative entrants instead. “This audit throttles speculative data center pipeline and makes genuine sites with development history more valuable,” wrote the research team led by Gautam Chhugani, noting mining sites carry the longest gestation, self-funded infrastructure and local community management. Fully grid-approved operators like IREN and Riot Platforms benefit most, while Cipher, Core Scientific and CleanSpark face more exposure where pipeline assets still need ERCOT conversion. The directive lands amid rising public backlash to data center build-out across the state. This inversion is notable — after years as the grid’s scapegoat, miners’ approved megawatts just became scarcer assets precisely because the AI wave behind them is now the political problem.Thanks for reading Tangents Daily, the front row for frontier tech. Please share & subscribe:


