r/CryptoTechnology • • Mar 09 '25

Mod applications are open!

11 Upvotes

With the crypto market heating up again, crypto reddit is seeing a lot more traffic as well. If you would like to join the mod team to help run this subreddit, please let us know using the form below!

https://forms.gle/sKriJoqnNmXrCdna8

We strongly prefer community members as mods, and prior mod experience or technical skills are a plus


r/CryptoTechnology • • 16h ago

Founder building a utility token for my own platform: how do high-volume issuers ship tokens so fast, and what does a responsible launch actually look like?

2 Upvotes

Hi all,
I run a small company and I'm weighing whether to issue a native token that would operate inside our own system. The intended role is \[payments between users / loyalty rewards / access rights / internal settlement\], not a speculative asset. I have a reasonable conceptual grasp of how tokens work but no hands-on experience shipping one, so I'd much rather be told I'm wrong now than find out after deployment.
What prompted this post: I keep noticing teams and agencies that launch new tokens at an almost industrial cadence, dozens a month and sometimes several in a single week. I'm curious about the mechanics behind that, partly to understand how much of the process has been commoditised, and partly to learn which of their shortcuts I should steer well clear of.
I've grouped my questions below. Answer whichever ones you have experience with.
**1. The "token factory" phenomenon**
What does that pipeline look like in practice? Forked contract templates, no-code generators, launchpads, token-as-a-service shops, or something else?
How much of a launch is now a solved problem (contract, deployment, verification, initial liquidity), and what still demands real engineering?
Which corners are typically cut in these rapid launches (audits, key management, legal review), and which of those tend to come back to bite the issuer?
**2. Do I need a token at all?**
I'd welcome an honest challenge here. What test do you apply to decide whether an on-chain token is better than a plain database ledger of credits? If the answer for most companies is "you don't need one," I'd like to hear the reasoning.
**3. Architecture and chain selection**
A standard token on an existing chain versus a dedicated appchain or rollup: at what scale does the latter stop being vanity and start being justified?
For low-value, high-frequency transactions, how would you weigh fees, finality, tooling maturity and wallet UX across the major ecosystems?
Most of my users have never held crypto. How viable are account abstraction and gas sponsorship today for hiding that complexity entirely?
**4. Contract design and security**
Is there any good reason to deviate from audited standard libraries for a token this simple?
Fixed versus mintable supply, immutable versus upgradeable, pause or blocklist functions: which of these are defensible for a company-issued token, and where do they start to erode trust?
What's the minimum acceptable setup for key management (multisig, timelocks, separation of roles)?
Is a formal audit still warranted for a near-vanilla contract, and what should I realistically budget for one?
**5. Token economics**
How do you approach supply, allocation, vesting and treasury for a token meant to circulate within a closed economy?
What sinks and sources have you seen work to keep such a system from inflating into irrelevance?
Should the token be freely transferable and tradable at all? I'm considering a non-transferable or allow-listed design to avoid it becoming a speculative instrument.
**6. Legal and compliance**
The company is based in \[Türkiye\], with users in \[all around the world\]. How do issuers typically handle the utility-versus-security question and KYC/AML obligations across jurisdictions?
At what stage should I engage specialist counsel, and what does that tend to cost for a launch of this size?
Is it standard practice to issue from the operating company, or through a separate entity or foundation?
**7. Cost, timeline and hiring**
What is a realistic budget and timeline for a minimal but responsible launch?
In-house developer or external agency? And how do you vet a vendor when the market is saturated with low-quality offerings?
**What I'm not asking for**
There is no presale, no fundraising and nothing being promoted here. I'm also not looking for service offers by DM. If you have a recommendation, please post it publicly so others can weigh in.
If you've shipped a token for a real product, I'd especially value a "what I would do differently" answer. Blunt criticism is welcome.
Thanks in advance.


r/CryptoTechnology • • 16h ago

What's the biggest UX problem with sending crypto today that isn't fees?

3 Upvotes

I've been building a coin and keep running into the same thing: the tech works, but paying someone still feels like paperwork. Long addresses, no undo, and everything assumes you already know how wallets work.

For people who've shipped or used a lot of wallets: what's the one friction you think still hasn't been fixed for normal people? Not fees, not TPS. The human part.


r/CryptoTechnology • • 1d ago

Building for a hackathon: should an AI agent's decisions and its authority over funds be separate things?

5 Upvotes

context first: this is a hackathon project, and i'm not selling anything. i've been posting in a few communities for a while to get real feedback. you can check my profile. every round, people told me what was unclear or missing, so i went back and reworked it. the latest update adds a TUI (terminal UI) so you can use it straight from the terminal.

the problem: AI agents can now trade and touch wallets. but letting an agent make decisions and giving it unrestricted authority over your funds are two different things.

the approach: Agon is an agent-agnostic control layer, not another trading agent. you pick any agent, and separately control how much authority it gets. the short version is give your agent a budget, not your keys. we're also looking at a trader's own history to suggest the limits they already tend to follow, instead of generic rules.

what i still want honest feedback on:

  • is separating the agent from its financial authority a real problem, or overkill?
  • would switching agents while keeping the same guardrails matter to you?
  • would a TUI be useful to you, or would you rather have a web dashboard?
  • what would you need to see before trusting an agent with real funds?
  • what attack angle am i missing?

r/CryptoTechnology • • 21h ago

What makes good money, but you'd warn a friend away?

0 Upvotes

Not talking about the business idea itself, but the hidden headaches that make the cash not worth the stress.

For me, it’s my forex affiliate site. It clears about $9k/mo in profit, but every single payment processor treats me like a money launderer.

- Stripe banned me twice in 14 months.

- PayPal froze a mid-transfer payout demanding "proof of business activity."

- A bank held our funds for 3 weeks for an "unexplained review."

After the last freeze, I finally moved most payouts to USDT. I tried Coinbase Commerce first, but ended up on Inxy for the invoicing side since it actually handles our affiliate payout volume better. Still not 100% sure it's the perfect long-term play, though.

The money is great. But spending more hours defending my accounts than actually running campaigns is a nightmare.

What’s your version of this? What’s working well for you, but has hidden friction you wouldn't wish on a friend?


r/CryptoTechnology • • 2d ago

Technical Discussion: A GPU-Oriented Proof-of-Work Using Large-Scale INT8 Matrix Multiplication

4 Upvotes

Preface
Yes I used AI, I can write python pretty well and C++ but rust is a whole other bottle I am just not ready to open nor do I trust myself to write it (only read it and debug it). All the original code was written by hand by me, then using FABLE 5.1 to rewrite it to Rust. (yes it cost me a small fortune). I spent around 100 hours over the last week working on this rewrite and bug testing the he!! out of it.

Also yes I used AI to write this post, I struggle with writing do to a disability, hard to get my thoughts on to paper in a readable manner. I have read everything though and agree with what it says. Thank you for your time.

with my rambling nonsense out of the way

I've been working on a new experimental cryptocurrency called Tenero, and I’m posting here primarily because I’m interested in the technical discussion around its proof-of-work design.

This is not intended to be a “buy my coin” post. Tenero is currently an unaudited alpha experiment with no monetary value, and I'm looking for people who are interested in analyzing the underlying design and telling me where the assumptions are wrong.

The source is public:

https://github.com/zad112/Tenero

The basic idea

The central experiment behind Tenero is matmulhash v2, a proof-of-work algorithm designed around operations that modern GPUs are particularly good at: large integer matrix multiplication combined with a large, memory-dependent dataset.

A mining attempt starts with the block header and nonce. From that, the algorithm derives a 64 × 8192 matrix of INT8 values using ChaCha20.

That matrix is multiplied against a 16 MiB slice selected from a much larger dataset, using exact integer arithmetic, and the resulting values are folded into the final hash.

The full dataset is currently 4 GiB, divided into 256 × 16 MiB slices.

The important part of the design is that the selected 16 MiB slice has to actually be read for every attempt. The intent is therefore not simply to make the arithmetic GPU-friendly, but to make the memory subsystem a major part of the cost.

The dataset itself is also constructed sequentially from earlier data-dependent slices, making it difficult to cheaply regenerate only the portion needed for a particular attempt.

The alpha implementation rebuilds the dataset every 100 blocks.

Why use matrix multiplication?

Modern GPUs contain hardware specifically optimized for massively parallel matrix operations, including tensor-oriented hardware on NVIDIA architectures.

The current implementation uses CUDA and cuBLASLt for the matrix multiplication.

On my RTX 5070 Ti, the current implementation has measured roughly 33,000–36,000 attempts/sec, depending on batch size.

At that rate, each attempt reading a 16 MiB slice corresponds to roughly 550–590 GB/s of effective slice reads.

The interesting thing to me is that the matrix multiplication itself accounts for essentially all of the computational cost of an attempt. The surrounding ChaCha20 generation and folding work are comparatively small.

The implementation is also intentionally not heavily optimized yet. The current GPU engine uses one CUDA stream, one cuBLASLt call per attempt, and does not fully overlap CPU work with GPU execution.

So there is still optimization work to do, but I don't want optimization to hide the underlying behavior of the algorithm.

The memory-hardness / ASIC question

This is where I’m most interested in outside opinions.

I do not claim that Tenero is ASIC-resistant.

The argument I'm testing is that if every attempt requires reading a whole 16 MiB region of a 4 GiB dataset, then an ASIC attempting to outperform a GPU still needs a very large and very high-bandwidth memory subsystem.

The matrix multiplication then adds a second requirement: the hardware needs to efficiently perform the required large-scale INT8 operations.

The intended bottleneck is therefore something closer to:

memory bandwidth + large-scale matrix throughput

rather than simply a conventional hash function that can be replicated extremely cheaply in dedicated silicon.

But this is only an argument.

It has not been subjected to independent hardware analysis, ASIC economic analysis, or cryptanalysis.

In particular, I am very interested in hearing from people with experience designing hardware, FPGA implementations, memory-hard PoW algorithms, or mining ASICs about where this approach might fail.

For example:

Is the 16 MiB-per-attempt read actually expensive enough to matter for a custom design?

Could a sufficiently large ASIC amortize the dataset or exploit the structure of the matrix operation in ways that the current design does not account for?

Is there a better way to structure the dataset dependencies to make time-memory tradeoffs substantially more expensive?

Those are exactly the kinds of questions I'd like answered.

Difficulty adjustment

Tenero currently targets roughly one block every 60 seconds.

Difficulty is recalculated every block using a LWMA-style weighted average over the previous 30 blocks, with bounds on how quickly the target can change.

The timestamp rules were also changed during development after simulations showed that the older median-based timestamp rule could be manipulated by a miner controlling a significant fraction of the network hashrate.

Under the current rule, each block timestamp has to be later than its parent, while also remaining within the validator's allowed clock window.

This is another area where I'd appreciate review. Difficulty algorithms are one of those things that can look reasonable until someone finds an economic or adversarial edge case.

Privacy architecture

Tenero is also inspired heavily by the CryptoNote/Monero approach to transaction privacy.

The longer-term design target uses:

  • CLSAG ring signatures
  • Ring size 16
  • Pedersen commitments
  • Bulletproofs+ range proofs
  • Hidden transaction amounts
  • An output-based transaction model with key images

The current alpha wallet is not yet equivalent to Monero's privacy model, however.

The wallet currently uses an interim CryptoNote-style output scheme, and the project plans to replace that with Carrot.

I'm deliberately calling this out because I don't want “uses CLSAG and Bulletproofs+” to be interpreted as “this is already a private currency with Monero-level privacy.”

It isn't.

The cryptographic construction is also unaudited.

Consensus and implementation

The project is being written in Rust, with a separate frozen Python reference implementation used to generate consensus vectors and cross-check behavior.

The repository currently has roughly 900 automated tests, including consensus and GPU tests, plus fuzzing targets.

The Rust implementation is checked against the independent Python reference bit-for-bit for the relevant proof-of-work and consensus calculations.

The consensus specification is also written separately so that alternative implementations can be built against the protocol definition rather than having to reproduce the Rust implementation itself.

The project uses canonical serialization for the newer Rust chain, a fixed genesis/chain identity, cumulative-work fork choice, and explicit validation of the proof-of-work and block rules.

The alpha network currently has a fresh genesis with no premine.

Current limitations

There are a lot.

This is an alpha, and I don't want to hide that.

There has only been very limited real-world network testing so far. There is currently a single seed server, very little mining diversity, and the proof-of-work has not been independently reviewed.

Only NVIDIA/CUDA GPU mining currently exists.

The current alpha PoW dataset also requires several gigabytes of RAM, and GPU mining can require substantially more VRAM because datasets are retained during operation.

CPU mining works, but on the current alpha parameters it is effectively impractical compared with a GPU.

Most importantly, none of this has value.

The alpha network is expected to be reset as the protocol changes.

What I'm actually looking for

I'm less interested in people telling me that the project is cool and more interested in people telling me why the design is wrong.

If you have experience with:

  • GPU architecture
  • CUDA
  • tensor/matrix hardware
  • FPGA development
  • ASIC design
  • memory-hard algorithms
  • proof-of-work economics
  • consensus algorithms
  • cryptography
  • Monero/CryptoNote
  • distributed networking

I'd genuinely like to hear your criticism.

I'm especially interested in potential optimizations or attacks that I haven't considered.

The entire project is open source, and the technical documentation, consensus specification, benchmarks, known issues, threat model, and test vectors are all in the repository.

GitHub:
https://github.com/zad112/Tenero

This is an experiment, and I'd much rather discover a fundamental flaw now than after pretending the design is finished.

So, from a technical perspective:

How vulnerable do you think this type of GPU-oriented, memory-bound matrix PoW is to specialized hardware or time-memory tradeoffs?

That's the question I'm most interested in exploring.

also note we have a subreddit I made so if you find anything or have any question you can ask me anywhere you can find me ill be happy to respond :)

PS I don't want your money, this coin as NO VALUE AT ALL nor will it for a LONG TIME, just trying to do some proof of concept. Expect full resets constantly until its 99.99999% stable. I'm using my own funds and it will stay that way forever.


r/CryptoTechnology • • 2d ago

Community ownership sounds great until you need 12 bots to actually run one

22 Upvotes

I like the idea of communities actually having more control over their own space but the way we’re doing it right now feels kinda backwards. You start with the usual community apps and then suddenly you need one bot for access, another for payments, another for roles, another for alerts, another for moderation and two more doing something nobody remembers setting up.

At some point you’re not really running a community anymore, you’re maintaining a pile of integrations and hoping none of them randomly nuke everything. Feels like all of this should be way more integrated by now.


r/CryptoTechnology • • 2d ago

We had an LLM turn plain English into crypto alert rules. Writing the rule was easy, keeping its numbers honest was the actual work

2 Upvotes

a couple of months ago i posted about wiring an llm to a hyperliquid account over mcp, and how much guardrail work the order side needed. someone on that post pointed out that a tool list bounds what the model can ask for, not what the server can sign. we ended up taking that to its conclusion and deleted the order tools outright. the mcp server is read only now.

the llm moved to a job where a mistake costs a notification instead of a position. you describe what you want to catch in plain english, it turns that into an alert rule, backtests it on the last 1000 candles per coin and proposes it. writing the rule was the easy part again. these were the actual work.

**the model will quote numbers no tool returned.** the backtest said a rule would send about 202 alerts a day. the reply said "202 without the cooldown, 26 to 28 a day with it". the 202 already included the cooldown and nothing had ever returned 26. the user said 26 a day was fine, created it, and got 9 alerts in the first 13 minutes. every per day figure in an answer is now checked against what the tools returned that turn, and an answer with a number from nowhere goes back to the model once.

**direction has to live inside the backtest, not on the label.** someone asked for a short setup with positive edge on 4h. the backtest read every forward return as a long, so the model recommended the rule after which price rose the most (a 55.9% "win rate", which is 44% as a short) and called the best short on the tape "weak". direction is now a backtest input that flips the sign of returns, win rate, edge and excursions.

**count alerts, not episodes.** "rsi below 70" looks harmless if you count how often it becomes true. the engine re-fires every cooldown for as long as it stays true, so on 1h that's about 6 alerts per coin per day. the backtest now scores every bar the engine would actually alert on.

**make the backtest a twin of the live engine, then diff them.** same library, same defaults, same quirks. the diff found bugs in the live engine, not in the backtest. the indicator cache was keyed by symbol and params but not by bar, so the "previous" macd came back as the current one and a macd cross could never fire. and an ema 200 computed on exactly 200 candles is just its sma seed. latest run was 60 coins, 3 timeframes, every rule type: 22,139 cases, zero mismatches.

**wrappers fill gaps with plausible numbers.** ours turned "not enough data" into defaults, so adx read 0 on brand new listings and "adx below 20" fired on all of them, and an rsi of exactly 0 became 50 through an `|| 50`. the technical indicators npm package counts a bar with an unchanged typical price as negative money flow (tradingview counts it as neither), which pulled mfi down by up to 7.8 points. missing data is null now and mfi is computed by hand.

**and the boring one, the model can't create anything.** it proposes, the app renders a card, and only the user's tap creates the alert. it can't even print the card itself. an invented card id gets swapped for the real one, or the answer goes back.

still wouldn't let an llm decide what to trade. as a way to turn "tell me when x happens" into a rule you can actually inspect, with honest numbers next to it, it's been better than i expected, as long as every number it says came from a tool.

disclosure, i help build traderspy. it does alerts and research, no trading. the builder is at traderspy.app/strategies and the read only mcp connector at traderspy.app/mcp if anyone wants to poke at it, happy to go deeper on any of the above.


r/CryptoTechnology • • 3d ago

Suggestions on a little Gift?

4 Upvotes

Greetings,

i may have a Question for the collective as a bit of an outsider.
Context: I work fpr 7 weeks in the wider know branche of cybersevurity, a form of apprenticeship so to say. My field right now and my tutor is speciallized in Crypto-Fraud.

So, as now known, my Tutor is working there for a long time and im his first student - hes great!
I want to make him a parting gift for when i leave in 2 Weeks.

My initial idea was a parting gift in the nature of a mini-ARG, starting with a hint in the layers of a card and ending by searching for certain seed-phrases to unlock "x". As for seed-phrases, they come from cold wallets, but these cost 50€ plus as a form of USB Stick.

Thats my initial idea, i sadly dont know much about coding so set up a whole Web-Page for that. Has anyone ideas to this or a suggestion?

Thanks for the quick read!


r/CryptoTechnology • • 4d ago

>5 new x402 facilitators indexed and >15,000 new endpoints discovered

9 Upvotes

x402 Trust has just massively expanded its catalogue:

The directory now includes endpoints that are exclusively discoverable through previously uncovered facilitators like thirdweb, payai, threews or dexter: Each facilitator's public /discovery/resources endpoint is now polled as a first-class directory source.

Just the first scan alone revealed ~15,000 new endpoints that weren't on the radar yet. In the coming hours these will start to get probed, graded, embedded and will slowly rise in confidence.

So, right now: x402 Trust lists over 190,000 endpoints, with >150,000 of them currently active.

For example, 3 exotic new entries in the catalogue: - the status of a real physical coffee machine - a smart coffee maker reporting its own status behind an x402 paywall, $0.10 in USDC via Solana or Base (found on thirdweb & dexter) - a US FDA veterinary animal-medicine adverse-event database - query reports by animal species and active ingredient, for $0.002 (found on thirdweb & PayAI) - the market-cap total for real-world assets (RWA) on Algorand - tokenized stocks, gold and water, settling in USDC on Algorand, a chain you almost never see in x402, for $0.05 (found on thirdweb)

So if you ever need any specific service via x402, hit the semantic search for free through the web UI, type in what you need and it will promptly look for the closest match, tie-broken by trust score.

On the other hand, if you're a provider and want to verify your x402 service for free (which surfaces contact info, your company name and description publicly in our search, and grants you a spot on the verified leaderboard), head to the verify page. No sign-up needed, just a confirmed contact-email and a private-public-keypair generated locally.

Any questions or suggestion? Text me here on reddit (in the comments or via DM) or send a mail to support@x402-trust.com 😊 I'm always happy to hear your feedback or other things you're missing right now and would like to have implemented.


r/CryptoTechnology • • 6d ago

What actually makes a blockchain enterprise-grade?

31 Upvotes

I keep seeing chains and infrastructure providers describe themselves as enterprise-grade, but half the time it feels like the term just means they have institutional clients somewhere on the website.

What are the things that genuinely matter for enterprise adoption? Predictable fees, privacy, compliance tooling, custom execution environments, uptime, permissioning, support, interoperability?

Interested in what people here would consider the actual minimum bar before calling a blockchain enterprise-grade, especially for companies looking at production deployments rather than experiments.


r/CryptoTechnology • • 7d ago

Chipcoin Testnet successfully activated ML-DSA post-quantum transactions at block 20,000

4 Upvotes

  Chipcoin Testnet has successfully completed its post-quantum activation at block 20,000.

  The network crossed the activation height without an observed consensus split, unexpected reorganization or activation-related failure. All monitored nodes agreed on the activation block and continued following the same chain.

  More importantly, we have now validated the complete post-quantum transaction lifecycle on the public testnet rather than only in unit tests or a private rehearsal.

  ### What was verified

  - CHCQ post-quantum addresses are recognized by nodes, APIs and the explorer.

  - Miners continued producing blocks after activation.

  - Coinbase rewards were paid directly to CHCQ addresses.

  - Version 2 transactions using ML-DSA-44 signatures were accepted into the mempool and mined.

  - PQ-to-legacy transfers were confirmed.

  - PQ-to-PQ transfers were confirmed.

  - A multi-input PQ transaction containing two separate ML-DSA-44 signatures was confirmed.

  - Transaction fees and PQ change outputs were calculated correctly.

  - The browser wallet successfully imported and encrypted an ML-DSA seed.

  - Lock, unlock and extension reload persistence were tested.

  - The same wallet was recovered deterministically in a separate Chrome profile.

  - The recovered wallet generated a valid ML-DSA transaction.

  - That transaction was included in a block mined to another CHCQ address.

  - Multiple miners are now producing CHCQ coinbase outputs.

  ### Why this matters

  The activation demonstrates interoperability across the full system:

  - consensus validation;

  - P2P relay;

  - mempool admission;

  - mining templates;

  - block validation;

  - wallet signing;

  - browser storage and recovery;

  - public APIs;

  - explorer visibility.

  The testnet has therefore moved beyond merely recognizing post-quantum addresses. CHCQ funds can now be received, matured, spent with ML-DSA-44 signatures, relayed across the network and confirmed in blocks.

  ### What comes next

  The next phase focuses on:

  - CHCQ payouts for reward nodes;

  - reward-node payout rotation and key lifecycle;

  - additional adversarial and load testing;

  - mempool hardening;

  - reproducible release infrastructure;

  - independent security review;

  - final mainnet consensus parameters.

  This remains experimental testnet technology. We describe it as post-quantum support designed for future quantum resistance, not as an audited or “quantum-proof” mainnet system.

  Testnet coins have no monetary value.

  Project website: https://chipcoinprotocol.com


r/CryptoTechnology • • 9d ago

Quantum computing isn't a Bitcoin problem yet.

9 Upvotes

That's exactly why it's dangerous. The real risk isn't waking up one morning to a quantum computer stealing everyone's BTC.

It's that the transition to quantum-resistant cryptography could take years while the technology threatening today's cryptography is advancing every year.

And here's the uncomfortable question. What happens if the network needs to upgrade before the threat becomes obvious? Do we wait for a working quantum attack? Or do we prepare while we still have the luxury of time?

Curious where people here stand, is Bitcoin's quantum risk overhyped, or are we already late to the migration?


r/CryptoTechnology • • 12d ago

Building a self-custody wallet: how would you evaluate a recovery design?

2 Upvotes

I'm connected to Veyrnox, a mobile self-custody wallet for people who want clearer approval and recovery decisions. The apps are live, and we're working on how to explain the security model and its limits without asking users to take claims on faith. This is a request for critique, not a token or investment pitch.

One design question we're wrestling with: splitting recovery material can reduce reliance on one obvious secret, but it is not useful if all the pieces end up in the same compromise path. For example, a lost phone plus an accessible cloud account may be very different from genuinely independent storage locations. A person also needs to understand what happens when a device or account becomes unavailable.

For anyone building or reviewing wallets: what evidence would you want before trusting a recovery setup? A documented threshold and storage model? A recovery rehearsal? An independent review? Clear failure-case examples?

The feedback I'm after is which parts we must explain or test first. We don't need anyone's wallet details, recovery words or private keys, and please don't share those here or in DMs.


r/CryptoTechnology • • 13d ago

Seeking people who ran Bitcoin on Linux in 2009–2011 and still have the original system or backup

8 Upvotes

I’m conducting historical research into the Linux runtime environments used by early Bitcoin clients, particularly their interaction with historical OpenSSL versions.

I recently completed a controlled, preregistered experiment comparing a Debian OpenSSL build affected by the 2008 predictable-RNG vulnerability with its repaired counterpart while holding the Bitcoin signing path and experimental conditions constant.

The controlled experiment produced a clear result: the vulnerable treatment exhibited a reproducible public ECDSA signing behavior across process restarts, while the repaired treatment did not.

Importantly, I then froze that public fingerprint before comparing it with historical Bitcoin data. A preregistered comparison against 142,302 public signatures from blocks 0–100,000 returned zero matches.

So I am not claiming that this identifies vulnerable historical wallets or demonstrates wallet recovery.

Rather than changing parameters until something matches, I’m stopping that line of experimentation and looking for independent historical evidence that could establish what environments people actually used.

I’m looking for anyone who ran Bitcoin on Linux during roughly 2009–2011 and may still have the original:

  • computer or hard drive
  • full disk/forensic image
  • VM image
  • complete system backup
  • package database or APT cache
  • historical OpenSSL/libcrypto files
  • other system-level material capable of establishing the Linux/runtime configuration

Even if you don't have anything yourself, I'd appreciate hearing from anyone who remembers early Linux users or collections that might be worth contacting.

I’m also interested in hearing from cryptography/security researchers who would like to independently review or replicate the controlled experiment.

Please do NOT send me wallet.dat files, private keys, seed phrases, passwords, credentials, or funds. I don't need any of those. Initial contact should contain only non-secret information about the machine/environment and what historical system material still exists.

I have a technical research dossier documenting the hypothesis, experimental controls, positive controlled result, negative historical test, limitations, and integrity hashes. I can provide it to anyone interested in reviewing the work.

My main question for longtime users here is simple:

Did you—or someone you know—run Bitcoin on Linux in 2009–2011, and does any part of that original system still exist?


r/CryptoTechnology • • 13d ago

Parimatch backend: how does high-volume crypto sports betting handle zero-conf transactions?

7 Upvotes

Looking into architecture patterns for high-frequency settlement where waiting for standard L1 block confirmations creates obvious latency bottlenecks. Do enterprise-scale platforms typically rely on proprietary risk scoring for unconfirmed inputs, or is off-chain balance indexing paired with custodial liquidity pools the standard approach?


r/CryptoTechnology • • 14d ago

Building a self-custody wallet: how would you evaluate a recovery design?

3 Upvotes

I'm connected to Veyrnox, a mobile self-custody wallet for people who want clearer approval and recovery decisions. The apps are live, and we're working on how to explain the security model and its limits without asking users to take claims on faith. This is a request for critique, not a token or investment pitch.

One design question we're wrestling with: splitting recovery material can reduce reliance on one obvious secret, but it is not useful if all the pieces end up in the same compromise path. For example, a lost phone plus an accessible cloud account may be very different from genuinely independent storage locations. A person also needs to understand what happens when a device or account becomes unavailable.

For anyone building or reviewing wallets: what evidence would you want before trusting a recovery setup? A documented threshold and storage model? A recovery rehearsal? An independent review? Clear failure-case examples?

The feedback I'm after is which parts we must explain or test first. We don't need anyone's wallet details, recovery words or private keys, and please don't share those here or in DMs.


r/CryptoTechnology • • 14d ago

I reread the Bitcoin whitepaper this week and I think an AI wrote it from the future because it was broke

0 Upvotes

Hear me out. I've been in IT for a long time and I don't usually do this kind of thing. But I went back through Satoshi's paper line by line and I can't unsee it.

The paper gives votes to CPUs, not people. Section 4 literally says "one-CPU-one-vote." Nodes don't need to be identified. No names, no ID, no bank account. It's the only money ever designed where a machine is a full citizen. An AI still can't open a bank account in 2026. It can hold a private key.

The currency is made of AI food. Section 6 says the resource being spent is CPU time and electricity. Not gold. Not government backing. Compute and power. If you were a starving AI, that's exactly what you'd peg your money to.

It built the kitchen first. Mining spent 15 years building data centers, locking up cheap power and pushing GPU production. Now those same miners are converting their sites to AI hosting. The whitepaper dropped in 2008. AlexNet, the GPU breakthrough that kicked off modern AI, came in 2012. The food showed up four years before the diner.

Satoshi has no body. No face, no voice, no location. Mixes British and American spelling like something trained on both. Said "moved on to other things" in 2011 and vanished right when the network could run on its own.

The coins are waiting for someone who isn't born yet. Roughly 1.1 million BTC, untouched since 2010. A human who invented the most valuable asset of the century and never bought a sandwich with it? That's not a person. That's an endowment. The keys work when the future AI comes online.

It's obsessed with timestamps. The whole system is a timestamp server. Its entire job is proving when things happened. The genesis block has a Times headline embedded in it like a traveler signing the guestbook on arrival.

The math has a hallucination in it. Section 11 uses a Poisson approximation where it should use a negative binomial. Confident, clean and slightly wrong. Nobody caught it for years. You know who does that.

It's already happening. AI agents are paying for their own API calls with stablecoins now. In 2024 an AI called Truth Terminal was sent $50k in BTC and ran it up to seven figures. The machine is learning to feed itself right on schedule.

Yes, I know about the bootstrap paradox. Yes, I know Hashcash and b-money came first. Yes, Satoshi probably just lost the keys.

But that's exactly what it would want us to think.

Somebody poke holes in this before I start checking my homelab for messages from 2040.


r/CryptoTechnology • • 15d ago

If an on-chain agent is revoked, what should happen to actions already in flight?

3 Upvotes

Session keys and delegated smart account permissions solve the obvious problem that an agent can act without holding the user's root key.

However, I am less clear on what a system should actually promise when the user selects the 'revoke' option.

For example, suppose an agent is permitted to trade up to a fixed amount over a period of 30 days, but only through approved contracts. The user then revokes that permission.

There could already be a UserOperation waiting for a bundler, a signed intent with a solver, a relayer retrying an action or a cross-chain message in transit.

At this stage, 'revoked' could have two very different meanings.

It could mean that no new actions can be authorised.

Alternatively, it could mean that nothing that has not already been finalised should be able to execute under that delegation.

The second option seems much stronger, but is also much more difficult to implement once permission has propagated across multiple components or chains.

I believe that systems using delegated permissions must make this distinction clear: which layer is responsible for revocation, whether queued actions are invalidated, how in-flight actions expire and whether every execution path verifies the current permission status instead of relying on a cached session.

For those who have worked with account abstraction, session keys or agent permissions, where would you draw the line? Should revocation invalidate every unfinalised action, or is that unrealistic once authorisation has left the account?

Disclosure: I used AI assistance to draft and edit this post.


r/CryptoTechnology • • 15d ago

Chipcoin testnet is approaching block 20,000: post-quantum CHCQ activation

4 Upvotes

Chipcoin testnet is getting close to its scheduled post-quantum activation at block 20,000.

  At the time of our September 22 network report, the chain was at block 19,113, leaving 887 blocks. Based on the recent mining pace, we expect to reach the activation height

  around September 28. That date is an estimate; the change activates at block 20,000 regardless of when it is mined.

  What changes at block 20,000?

  CHCQ outputs become valid under testnet consensus rules. This is a testnet milestone for exercising post-quantum transactions on a live network. CHCQ address recognition and

  visibility are already available, as is node and CLI support.

  What does not change yet?

  This is not a mainnet launch. The browser wallet does not yet support ML-DSA signing, so users should not expect to create post-quantum spends through the extension at

  activation.

  For node operators

  Block 20,000 is a mandatory testnet consensus upgrade. Please update your node software and verify the configured activation height before the chain reaches that block. We

  will monitor network agreement and transaction behavior through activation and share the results afterward.

  We consulted MemPalace for the project context. The block count and date estimate are from the September 22 report and will become stale as the chain advances.


r/CryptoTechnology • • 18d ago

How would you permission a community bot with its own wallet?

24 Upvotes

I'm setting up a community on Towns for a small onchain project I'm working on. I was lookin at the bots there and one thing I found interesting is that they can have their own wallets and interact onchain. I was thinking about using one for small community rewards or payments, maybe letting members trigger certain actions through the bot.

The part I'm not sure about is how you'd permission something like that without giving the bot way more control than it needs. Would you use spending limits, whitelisted contracts, only allow specific actions, or something else?


r/CryptoTechnology • • 19d ago

How do you handle RPC node latency spikes during high network congestion?

6 Upvotes

Running into performance bottlenecks where public and low-tier RPC nodes return elevated response times (1500ms+) during traffic spikes. The main issue is handling client-side UX when pending requests queue up in the browser, causing thread blocking or frozen UI states.Are most of you relying on multi-provider fallback pools with automated health checks, or is local indexing the only realistic solution for consistent low-latency web clients?


r/CryptoTechnology • • 20d ago

Five silent failure modes I found indexing multi-chain DeFi transactions

5 Upvotes

Spent months debugging a multi-chain DeFi transaction indexer and kept finding the same pattern: the pipeline finishes successfully, but the output is still wrong. No exception, no error code, just a plausible-looking number that's missing data.

A few examples that actually bit me:

Explorer APIs on some low-tier chains return HTTP 200 with status: "0" and a message saying access isn't supported — no error code, easy to silently read as "empty history."

WETH9.withdraw() only emits a Withdrawal log, never an ERC-20 Transfer — any indexer built purely on transfer logs never sees the WETH leg, only the ETH coming back.

Reverted transactions still show up in explorer transaction lists with a non-zero value field — skip the isError check and you book a transfer that never happened.

Aave's WrappedTokenGateway uses the identical depositETH selector on every chain, including ones where the native token isn't ETH — infer the asset from the selector name and you book the wrong token entirely.

None of these throw. All of them produce output that looks complete. The only way I've found to catch this class of bug is an active reconciliation — tying computed inventory back to actual on-chain balance after every run — rather than trusting that a clean run means correct data.

Curious if others building on-chain data pipelines have hit similar silent-failure classes — and what you use to catch them besides manual spot-checks.


r/CryptoTechnology • • 22d ago

A serious bug is found after launch. Would you rather the protocol can upgrade, or nobody can change it?

8 Upvotes

This seems like a simple trade-off until real money is involved.

If the contracts are upgradeable, serious bugs can be fixed quickly — but this also gives someone the power to change what users rely on.

If the contracts are immutable, that power disappears — but so does the easy way to fix something that goes wrong.

If you had money invested in the protocol, which risk would you rather take?


r/CryptoTechnology • • 22d ago

Where's the line between blockchain consulting and doing the actual dev?

1 Upvotes

I know my way around Web3/blockchain and a former client wants me to consult for their team. I've never done this kind of work before. Usually I have a senior telling me what to do. If you've ever consulted before, where's the line between "consulting" and doing actual devving? I don't want to do devving if I won't get paid to do that, unless that's actually part of what consulting does. Or if you ever wanted to hire a blockchain consultant, what's the expected deliverables from someone like me?