Joined January 2011
168 Photos and videos
We solve point #1 and #2, for #3… make sure to pay your bill and avoid clicking “destroy enclave” accidentally x.com/afilini/status/2065104…

Thoughts on unruggable Cashu mints in trusted execution environments (TEEs). Sharing current research and looking for feedback. Idea: Generate Bitcoin reserve keys and Cashu signing keys inside a TEE so operators never access them. Goals: - Minimize rug risk (ideally to ~0) - Push operators toward non-custodial status # Risk 1: Malicious mint updates Users can verify the software running inside a TEE, but operators could later deploy a malicious fork. Potential mitigations: - Infrastructure provider enforces which software may be deployed. - Separate KMS with policies from the TEE allowing only audited/signed software to access keys. - Immutable mint: disable updates entirely. Upgrades require deploying a new mint and users migrating funds, similar to smart contracts. # Risk 2: Rollback attacks ("time travel") An operator could restore an old database snapshot, allowing previously spent ecash to be spent again and inflating supply. Possible mitigations: - Append-only storage enforced by the TEE/provider so spent notes can never be erased. - Seal the database inside the enclave and prevent external access. Combined with update protection, this appears to eliminate rollback attacks. # Risk 3: Mint shutdown The operator can always turn the mint off, making reserves inaccessible. Potential solution: @lukechilds proposed an elegant emergency exit mechanism. Reserve UTXOs contain a secondary spend path that activates after a period of mint inactivity. A third party (e.g. a multisig) holding a copy of the mint database could continue honoring withdrawals. During normal operation the mint periodically rolls reserves forward, extending the timeout. If it stops, the emergency path activates. A more ambitious direction is committing the spend book as a Merkle/nullifier tree. With the right scripts, users may be able to withdraw unilaterally by proving their ecash has not been spent. This could largely solve risks 1-3 simultaneously. # Conclusion We haven't cracked this nut completely yet, but the progress over the last few weeks has been remarkable. The mere existence of plausible solutions is incredibly exciting. Imagine if we could pull this off. David Chaum invented ecash in the 1980s, and researchers spent decades trying to make it trustless. Then Satoshi invented Bitcoin, and the world largely moved to the blockchain paradigm. It would be an enormous achievement if we could finally solve the trust problem of Chaumian ecash by rebuilding it on Bitcoin and its more expressive L2s, combining the best of both worlds: a scarce, immutable base layer with trust-minimized ecash on top, offering strong privacy, instant payments, near-zero fees, offline transactions, and amazing UX.
1
1
7
2,062
I've been talking about Enclavia but I never spelled out what we solve. So I wrote it down: six ways a trusted enclave can break, and how we abstract them away for you
3
6
18
2,898
Alekos Filini retweeted
Thoughts on unruggable Cashu mints in trusted execution environments (TEEs). Sharing current research and looking for feedback. Idea: Generate Bitcoin reserve keys and Cashu signing keys inside a TEE so operators never access them. Goals: - Minimize rug risk (ideally to ~0) - Push operators toward non-custodial status # Risk 1: Malicious mint updates Users can verify the software running inside a TEE, but operators could later deploy a malicious fork. Potential mitigations: - Infrastructure provider enforces which software may be deployed. - Separate KMS with policies from the TEE allowing only audited/signed software to access keys. - Immutable mint: disable updates entirely. Upgrades require deploying a new mint and users migrating funds, similar to smart contracts. # Risk 2: Rollback attacks ("time travel") An operator could restore an old database snapshot, allowing previously spent ecash to be spent again and inflating supply. Possible mitigations: - Append-only storage enforced by the TEE/provider so spent notes can never be erased. - Seal the database inside the enclave and prevent external access. Combined with update protection, this appears to eliminate rollback attacks. # Risk 3: Mint shutdown The operator can always turn the mint off, making reserves inaccessible. Potential solution: @lukechilds proposed an elegant emergency exit mechanism. Reserve UTXOs contain a secondary spend path that activates after a period of mint inactivity. A third party (e.g. a multisig) holding a copy of the mint database could continue honoring withdrawals. During normal operation the mint periodically rolls reserves forward, extending the timeout. If it stops, the emergency path activates. A more ambitious direction is committing the spend book as a Merkle/nullifier tree. With the right scripts, users may be able to withdraw unilaterally by proving their ecash has not been spent. This could largely solve risks 1-3 simultaneously. # Conclusion We haven't cracked this nut completely yet, but the progress over the last few weeks has been remarkable. The mere existence of plausible solutions is incredibly exciting. Imagine if we could pull this off. David Chaum invented ecash in the 1980s, and researchers spent decades trying to make it trustless. Then Satoshi invented Bitcoin, and the world largely moved to the blockchain paradigm. It would be an enormous achievement if we could finally solve the trust problem of Chaumian ecash by rebuilding it on Bitcoin and its more expressive L2s, combining the best of both worlds: a scarce, immutable base layer with trust-minimized ecash on top, offering strong privacy, instant payments, near-zero fees, offline transactions, and amazing UX.
17
23
151
13,214
Alekos Filini retweeted
The BDK Foundation is happy to announce two new corporate members for Q2 2026 - @SatoshiPacioli and @mempool ! A big thanks to our new and continuing members @spiralbtc, @OpenSats, @AnchorWatch, @CleanSpark_Inc, and @ProtonPrivacy for their support. bitcoindevkit.org/blog/2026_…

2
13
40
3,044
Alekos Filini retweeted
Antidote Inside, episode 4! We sat down with @afilini to discuss his company, Enclavia, which enables any developer to benefit from radically better security, easily. With use cases across Bitcoin, FinTech, Healthcare and Defence, we' loved diving into his business.
1
2
8
487
🥳🥳🥳
Running attested rust code in an enclave in 10 minutes, thanks Enclavia!
1
15
1,978
Alekos Filini retweeted
loupe [NOUN] 1) A small magnifying tool used by jewelers to detect imperfections in gemstones. 2) An AI-powered vulnerability scanner for open-source bitcoin projects, designed by Block and Spiral to surface flaws before attackers do. spiralbtc.substack.com/p/mee…
13
37
174
74,575
Most companies handling sensitive financial transactions, private keys or healthcare data are one compromised employee, one misconfigured cloud database or one subpoena away from exposing everything. Enclavia is fixing this. enclavia.io/blog/introducing…
1
6
22
872
1
264
In today's episode of "helping Alekos choose the right thing": does anybody know of a good bare metal hosting provider? I love Hetzner but it looks like they have a 500 EUR setup fee on AX-102 servers now ??
6
1
1,095
Working on docs for enclavia.io now, what do you guys suggest to make them super accessible to AI? I want people to be able to point Claude at the docs and get everything working automatically
4
12
826
GF: let’s take a cute picture here Me, in full @AntidoteBTC swag: sure!
2
2
23
974
Alekos Filini retweeted
This week’s update by @TumaBitcoiner features an interesting PR in ldk-node (@lightningdevkit) which aims to introduce support for applying Replace-By-Fee (RBF) to a splice transaction. We also cover the latest movements in the BIP repository. Notably, a new BIP proposal for disposing of dust UTXOs has been assigned number 451. We finally propose some more interesting news, such as recordings of @btcplusplus Villain Edition, where developers discussed the most controversial things in Bitcoin, a new announcement by @afilini, and the new path forward for LDK.
3
6
473
I’m genuinely overwhelmed by the response to this, looks like we are onto something 🚀 Sorry if I’m a bit slow with the replies this bank holiday weekend, I’ll be back to the office on Tuesday and I’ll make sure to sort everything out
Replying to @TFTC21 @callebtc
Wasn’t really ready to announce yet but fuck it: we’ve been working on enclavia.io to bring enclaves to every bitcoin company. Private beta launches in the next couple of weeks, DM me if you want to try it out
2
2
30
2,305
Alekos Filini retweeted
Alekos as the founder of @bitcoindevkit getting into secure enclaves is something people should take note of. No idea if he is fundraising, but I'd back him!
Replying to @TFTC21 @callebtc
Wasn’t really ready to announce yet but fuck it: we’ve been working on enclavia.io to bring enclaves to every bitcoin company. Private beta launches in the next couple of weeks, DM me if you want to try it out
4
5
53
9,046
Alekos Filini retweeted
This is good for Cashu 👀
Replying to @TFTC21 @callebtc
Wasn’t really ready to announce yet but fuck it: we’ve been working on enclavia.io to bring enclaves to every bitcoin company. Private beta launches in the next couple of weeks, DM me if you want to try it out
2
42
4,931