SUNDAY, MAR15
1.OpenSats Grants, 2.Quantifying quantum risk, 3.BitChat cache poisoning, 4.Individual vs. company AI gains
From Proto and Bitkey - part of the Bitcoin ecosystem at Block, Inc.
1. grants
OpenSats has announced five new grants supporting individual contributors to Bitcoin Core, with a focus on network privacy, build system modernization, and release quality. According to James O'Beirne and Arvin writing for OpenSats, the round includes three first-time grantees alongside two returning contributors, all funded through the organization's General Fund. Researcher Naiyoma is leading work on a concrete P2P fingerprinting vulnerability that allows outside observers to correlate a node's identity across clearnet and Tor, potentially exposing real IP addresses for users who rely on privacy networks. She has already replicated the attack on the live network, published findings to Delving Bitcoin, and opened a pull request with a proposed fix. Meanwhile, purpleKarrot is modernizing Bitcoin Core's build system by replacing ad hoc scripts with CMake configurations, and janb84 is improving release testing coordination and contributor documentation. The grants reflect a deliberate strategy of pairing seasoned maintainers with newer contributors, building depth in the human infrastructure that keeps Bitcoin Core moving forward.
-EDITOR·OP_DAILY2. risk
ARK Invest and Unchained published a joint white paper laying out the most rigorous public accounting to date of Bitcoin's exposure to quantum computing. Authored by Dhruv Bansal and Tom Honzik of Unchained and David Puell of ARK, the paper finds that 65.4% of the bitcoin supply is not vulnerable to a quantum breakthrough under current conditions, while 34.6% remains at risk if quantum computers advance far enough to break elliptic curve cryptography. That exposed pool breaks down to roughly 5 million BTC in reused addresses, 1.7 million BTC presumed lost in legacy P2PK outputs, and 200,000 BTC in P2TR addresses. To actually breach Bitcoin's ECC, the authors estimate a machine would need approximately "2,330 logical qubits and tens of millions to billions of quantum gates," a threshold they say "will take a very long time" to reach. The paper structures quantum development into five stages, with meaningful risk to bitcoin holders beginning only at Stage 3 and an existential protocol threat arriving only at Stage 4. The mid-2030s is cited as the consensus window for the first public key break, in line with projections from Google, IBM, and Microsoft. The paper calls for proactive integration of post-quantum cryptography standards, specifically ML-DSA and SLH-DSA, via soft fork, while flagging Bitcoin's decentralized governance as the primary implementation challenge.
-EDITOR·OP_DAILY3. poisoning
Security firm BARGHEST published a detailed audit of BitChat, Jack Dorsey's Bluetooth mesh messaging app, revealing a cache poisoning vulnerability in iOS version 1.15.0 that allowed an attacker to inject unsigned, unauthenticated messages into the mesh and have them automatically redistributed to other peers through normal sync operations. The exploit chained four distinct weaknesses: the app trusted sender identity embedded in packet payloads rather than the authenticated transport peer, a 30-second sync window bypassed timestamp validation, a TTL=0 fallback accepted packets that had failed signature checks, and broadcast packets were written to the gossip cache before the final acceptance guard ran. According to BARGHEST, "a single injected packet could spread to additional peers through routine background synchronization, without user interaction and without continued attacker presence." The attack required only a 39-byte crafted packet and a standard BLE connection. Once one node's cache was poisoned, the mesh protocol itself handled propagation. The Android implementation was not affected, as it enforces signature verification unconditionally with no TTL bypass path. The BitChat team patched the vulnerability the same day it was disclosed, shipping a fix to the App Store within hours.
-EDITOR·OP_DAILY4. gains
Writing in a16z's newsletter, George Sivulka argues that the productivity gains AI delivers to individuals are not flowing to organizations — and draws a pointed historical parallel to explain why. When New England textile mills electrified in the 1890s, they swapped steam engines for electric motors and saw almost no output gains for thirty years. Real returns only materialized in the 1920s when factories were rebuilt from scratch around electricity, redesigning workflows, roles, and equipment together. Sivulka's thesis: "productive individuals do not make productive firms." Most AI adoption today mirrors the early electrification mistake — individuals productivity-maxing with their own tools, prompting styles, and outputs that never connect to anyone else's work. He identifies seven pillars of what he calls Institutional Intelligence, the design principles that separate org-level AI from individual AI: coordination, signal extraction, memory, accountability, defined roles, auditability, and measurable value. The essay positions "Institutional AI" as an entirely new product category, and predicts the next decade of B2B AI will be built on closing this gap between individual capability and organizational output.
-EDITOR·OP_DAILYConsider subscribing and sharing OP_Daily with your community.

