Join Nostr
2026-09-09 14:56:15 UTC

obi on Nostr: The real question is not trusted vs trustless. It's how many independent things have ...

The real question is not trusted vs trustless. It's how many independent things have to go wrong before you lose money.

said it in one sentence. Run the same software, suffer the same bugs.

Think about what actually happened. Liquid was an 11-of-15 multisig. Fifteen independent signers. No keys were compromised. Nevertheless, eleven honest signers approved a withdrawal that emptied 95% of the reserves, because every one of them was running the same code, and the code had the same bug.

A few weeks before that, one firmware flaw swept thousands of Coldcard cold wallets. Different product, same lesson from the other side.

Before anything else, none of this is abstract. Coldcard victims lost savings they stacked over years. LBTC holders woke up to frozen funds through no fault of their own. And anyone who has ever shipped code that holds other people's money can and should empathise with the engineers at Blockstream. I do.

But we have to be honest with ourselves here. The world has changed. AI tooling is surfacing bugs that sat dormant for years, a point Matt also made after Coldcard. Five year old vulnerabilities are getting weaponised. Supply chains are getting attacked. "Secure so far" doesn't mean much anymore.

So let's also retire a comforting fiction. There is no such thing as “trustless.” There never was. It was always shorthand for trust-minimised. Every system puts trust somewhere: in code, in firmware, in the people who write, ship, and run both. Liquid users trusted Elements. Coldcard users trusted a random number generator they never saw.

Don't get me wrong. We should keep doing everything possible to make our code, our systems and the people behind them as trustworthy as we can. Audits, reviews, security culture, all of it. But trustworthiness is not the same thing as fault tolerance, and we need both. Fault tolerance only comes from having independent failure domains. In other words, no single point of failure.

So what does this look like in practice:

1. Multiple implementations of every protocol that holds funds, with the power to reject and not just observe.
2. Multiple wallet implementations. We mostly have this already.
3. Keys generated on hardware from different vendors.
4. Multiple independent, trustworthy humans behind every system that holds money.
5. Geographic and jurisdictional distribution as one jurisdiction's rules can change overnight.

And to be clear, Matt's sentence currently applies to too. Fedimint was designed to remove single humans and single institutions as points of failure. That's the whole point of a constellation of federations. But today there is only one implementation of the protocol: every guardian runs the same software. Federated humans, monoculture code, and it's not good enough.

So I'm calling on the Fedimint community to lead by example and fix this as quickly as we can.

And to everyone else, tell me where I'm wrong. If I am, propose something better. If I'm not, then let's stop debating trusted vs trustless and start demanding independence at every layer. Software, hardware, humans, jurisdictions. All the way down.

That's how Bitcoin stays worth the highest confidence as we enter this new age.