Skip to content
Satoshi Gazette

The Satoshi Brief

No. 003

Weekly edition · Sep 15, 2026

Read the ledger. Keep the keys.

This week's argument

Why are we still being asked to trust?

This week’s Brief follows the trust we place in Bitcoin businesses and a president’s promise of $5,000, asking what we can verify before depending on either.

One argument from the desk, with the reporting underneath it.

The read

We spend a lot of time telling people to keep their own keys, and we should, because being able to use your money without asking a company for permission is worth defending. But after working through this week’s security stories, I don’t think we can leave the advice there and pretend we have answered everything.

A person can keep their keys while a company keeps their address, purchase history or payment records. They can recognize the sender of a security email because it really did come through infrastructure the company used. And they can choose a service because it says “non-custodial” without knowing that somebody else holds a payment before it reaches their wallet.

That is what bothers me about these cases. People are being asked to understand arrangements that the reassuring description does not explain, and when something goes wrong, telling them they should have been more careful is far too convenient.

How much could the customer actually verify?

The Trezor phishing email is a good place to start, because the usual advice about checking the sender would not have resolved this one. Trezor’s September 10 disclosure described attackers abusing its newsletter account to send a false security warning, while Brevo’s post-mortem explained that the messages travelled through legitimate infrastructure and passed ordinary email-authentication checks. The request for a wallet backup was fraudulent despite those familiar signs. Read

Of course we should refuse a request to hand over a wallet backup. But that does not let the companies responsible for the sending system off the hook. Someone trusting an email from a business they already deal with is not an adequate explanation for why an attacker was able to send it.

Swiss Bitcoin Pay raised another question in its September 14 disclosure. The company paused its servers after suspected unauthorized access and said that internal records might have been exposed, while also saying funds were safe. That last part was its assurance, not something we independently established. Its follow-up explained that it temporarily holds incoming Lightning payments before batching on-chain payouts, which matters if you understood “non-custodial” to mean that nobody else would hold the money at any point. Read

This is why we put together the wider security timeline, rather than calling every incident a Bitcoin hack and moving on. The eight selected cases fail in different places, and although they make an uncomfortable read, they are not a count of every attack or proof that attacks are becoming more frequent. Read

They also stop us from giving ourselves an easy answer. The Coldcard weak-seed case belongs in that discussion because keeping a key does not help if somebody else can reconstruct it. Running a node lets you verify Bitcoin’s rules; it cannot tell you that your wallet generated an unpredictable secret, and mining cannot repair stolen keys. If we want people to take self-custody seriously, we need to explain those limits as carefully as we explain its advantages.

Would you still choose it if the dependency was clear?

Block sells Bitkey for self-custody, yet its September application for Builders Bank & Trust proposed a federal trust-bank structure for custody. There is nothing impossible about one company offering both, but the distinction should be clear to the person deciding where to keep their bitcoin. The proposed institution was uninsured and non-depository, and the application we covered was not an approval. Read

Supervision and enforceable obligations can matter, so dismissing the proposal simply because it involves a bank would miss part of the story. Nevertheless, supervision does not give you the signing authority that a custodian holds. I want to know what protection the arrangement provides and what the customer still has to ask permission to do, rather than treating the charter itself as the answer.

Liquid makes that concern harder to ignore. In our September 11 Wire, Blockstream refused a ransom demand involving 598.5 BTC, with the demand also recorded in a Bitcoin transaction. That was a record of the demand and refusal, not confirmation that recovery had been completed. Read

You can hold the keys to L-BTC and still depend on a federation to redeem it for BTC. That is a different arrangement from holding bitcoin directly, however familiar the wallet experience feels. People can choose that trade-off, but they deserve to understand it before the exit becomes the part they care about most.

And who is paying for the $5,000?

Trump’s September 9 pledge moved that question from a company to the government. He promised $5,000 to every adult American citizen if Republicans won both chambers of Congress, comparing the payment to a successful company distributing cash to shareholders. Our Story put that promise beside the public accounts and estimated a cost of roughly $1.23 trillion using the Census Bureau’s 2024 adult-citizen count. That is an estimate under the stated universal promise, not the cost of an enacted payment programme. Read

Line chart on a cream ground of total U.S. public debt outstanding, daily, from September 2025 to September 2026. The black line rises from 37.4 trillion dollars to 40.1 trillion dollars with a shaded area beneath it. A dashed vermilion vertical line marks 9 September 2026, labelled as the day of the 5,000 dollar pledge with 40.07 trillion dollars on the books.

Historical context from the Trump Dividend Story: total U.S. public debt outstanding from September 2, 2025, to September 9, 2026. This is the stock of debt, not the cost of the proposed payment or a current debt reading.

Satoshi Gazette chart; data from the U.S. Treasury and Census Bureau · As of 2026-09-10

Source 1Source 2

Methodology and limitations

Every daily Debt to the Penny record from 2 September 2025 to 9 September 2026 read through the Fiscal Data API on 10 September 2026 and plotted without smoothing. The per-day figure divides the change by 372 calendar days; the per-adult figure divides the 9 September total by the ACS 2024 count of citizens aged 18 and over.

I understand why someone would want the money. The problem is being invited to treat it as a gift before being shown how it would be paid for. Calling a transfer a dividend does not tell us whether it comes from revenue, additional borrowing or cuts somewhere else, and therefore it does not tell us who ultimately carries the cost.

This is where Bitcoin belongs in the argument, without pretending it solves a government’s budget. A politician cannot authorize extra bitcoin issuance within the rules our nodes enforce just because an election promise would be easier to keep that way. Those rules are something we can check ourselves, rather than a funding assurance we are asked to accept.

That is also what I want the Satoshi Brief to do. We should be able to ask where a promised payment comes from, just as we ask who controls a withdrawal, without first deciding whether we like the person making the promise. Keeping our own keys and running our own nodes matters because it gives us something we can do beyond hoping the right people remain in charge. The companies and politicians we agree with should expect us to ask questions too.

Read

Evidence behind this edition

Direct records used by the reporting in this edition. Gazette Story and Wire links remain beside the relevant argument.