THE SIGNAL

Someone spent about nineteen dollars on Saturday to move 600 bitcoin.

The precise figure is 24,000 satoshis, roughly $19.28, across twelve transactions that each spent an input of exactly 50 BTC. Every one paid the same fee: 2,000 satoshis, to the satoshi. The coins are worth around $48 million.

The sequence, from the chain rather than from anyone's press release. Twelve transactions across three blocks. One in 965,639, at 17:27:32Z. One in 965,645. Then ten together in 965,646, with the last confirmation at 17:57:16Z. Twenty nine minutes and forty four seconds, start to finish. One move, a pause, then everything at once.

What was being spent matters more than what it cost. All twelve inputs were P2PK, pay to public key, the original output format from Bitcoin's earliest days, in which your actual public key is written onto the blockchain in the clear for anyone to read. Everything since uses an address, which is a hash of the key. The key itself stays hidden until the moment you spend.

That difference is the entire quantum question. A machine capable of attacking Bitcoin would have to derive a private key from a public key. If the public key is already published, the attacker starts a step ahead of where it would otherwise have to begin. P2PK is the most exposed class of coin that exists, and roughly 1.7 million bitcoin still sit in it.

Every one of Saturday's outputs went to a fresh bc1q address. Native segwit, key hashed, nothing published until spent. Whoever holds those keys performed the quantum migration by hand, on a Saturday afternoon, and paid less to do it than dinner.

Now the vintage, because the framing everywhere else this weekend was Satoshi. Whale Alert flagged the movement and told Cointelegraph that "none of the blocks can be connected to Satoshi based on our research." We can be more precise than that, because the coins date themselves. The twelve outputs being spent were mined at heights 43,361 to 43,928, which puts every one of them in a single week: 2 to 5 March 2010. Satoshi-era, one specific stretch of it, and nothing tying it to Satoshi.

One more detail makes the fee stranger rather than less strange. They did not lowball it. Each transaction ran 154 bytes at 12.99 sat/vB, roughly thirteen times the 1 sat/vB mempool.space was recommending across every tier on Sunday. They paid up to jump a queue that was not there, and it still came to $19.28.

Bitcoin's developers have a proposal to retire the signature scheme these coins depend on. What it says about this particular class of coin is the FILTER, and it is the reason this is the lead.

Three metrics.

Metric 1, Fear and Greed: 71. Greed, per alternative.me. The run since 31 August reads 62, 69, 63, 65, 74, 73, 73, 71, so the level is up on the week and down three from Friday's peak. That is a plateau rather than a climb, and we would rather say so than draw a line through it. The complication sits one screen away in the derivatives data. Perpetual funding is close to nothing: Deribit's eight hour rate is plus 0.00048% and OKX's USDT swap is minus 0.00058%. A 71 with nobody paying to be long is sentiment without positioning, which is the cheap kind.

Metric 2, ETF flows: September is plus $770.0 million through four sessions. The prints run minus $236.5 million on 1 September, plus $101.1 million on the 2nd, plus $730.8 million on the 3rd, the largest single day since January, and plus $174.6 million on the 4th. That is Farside's published daily table, cross-checked against SoSoValue on all four days. Our 7 October test asks whether September closes net positive, and it is currently tracking Branch A. Underneath the total, Friday was odd: exactly two of the twelve US spot bitcoin funds saw a single dollar move in either direction. IBIT and FBTC. Ten of them printed zero. On 1 September it was three. Today is Labor Day, so there is no print at all.

Metric 3, BTC dominance: 59.2%. Bitcoin was $80,050 late on Sunday evening, close to unchanged on the day, against a total crypto market of about $2.72 trillion that fell over the same window on CoinGecko's measure. Bitcoin held and the rest did not, which is what dominance grinding higher looks like from the inside. Worth noting it spent most of last week under $80,000 and only reclaimed the level on Sunday evening, so this is a level regained rather than a level held. Bitcoin trades through the holiday; nothing else on this list does.

The book is flat for a tenth consecutive issue. The STACK says exactly what would end that, and it is not close.

MARKET RADAR
📰 THE STORIES THAT MATTER

  • A US Spot Bitcoin ETF Filed Its Deregistration Papers on 3 September. Hashdex filed a Form 15-12G under Rule 12g-4(a)(1), signed by Bruno Sousa, for the Hashdex Bitcoin ETF. The fund had already stopped trading on 17 August, so the filing is the paperwork rather than the decision. Ten spot funds began trading on 11 January 2024 and twelve trade today, and this is the first of them to switch off the lights. One line will get quoted badly all week: "approximate number of holders of record: less than 300." Holders of record counts DTC as a single entity, so that number tells you nothing about how many people owned shares, and anyone presenting it as a headcount is misreading a legal artifact. What the filing does tell you is duller and truer. Being a small sleeve in a category where one issuer takes most of the flow is not a business, and Friday's tape says the same thing from the other end: two funds saw money move and ten did not.

  • The SEC Proposed New Transfer Agent Rules and Said "Bitcoin" Zero Times. Voted out on 1 September, published on the 4th, 116 Federal Register pages, Release 34-106246, comments close 3 November. It is a proposal, not a final rule, which is exactly why the comment window matters. We counted the words across the full text. Tokeniz-anything appears 64 times. Distributed ledger 38. Blockchain 26. Crypto 4. Stablecoin once. Bitcoin, not at all. The release contemplates registering "blockchain-native, or 'onchain' transfer agents," and gives wallet whitelisting as an example of an activity that would pull a firm into registration. Question 113 asks whether stablecoins and tokenized deposits should count as "funds" for the segregated account requirement, and whether that account "could be a bank's custodial wallet." This is what crypto regulation looks like when nobody is fighting about it on television: recordkeeping rules, a comment period, and a question about where the money legally sits. The window is open until November and almost nobody in this industry will use it.

  • A Swiss Brokerage Lost Customer IDs and Bitcoin Addresses in the Same Breach. Pocket Bitcoin says its investigation into both categories is complete, in a post published 31 August and updated 3 September. Two groups: 291 customers whose stolen data spans names, postal addresses, bitcoin addresses used for transactions, identity documents and source-of-funds paperwork, and a further 5,120 with a narrower set. Read the company's own qualifier carefully, because it matters: those fields came "in varying combinations. For most people, it is only some of these details." So this is not 291 complete dossiers. It is 291 people who do not yet know which parts of their file are now in circulation, which is its own kind of problem, because you cannot mitigate what you cannot enumerate. The advisory is unusually blunt about what comes next, warning about "forged letters and other mail" and that "fraudsters could refer to a real earlier transaction." Read that with a specific relative in mind, one who would find a letter convincing precisely because it mentions a purchase they actually made. The generalisable part: every KYC file you have handed over is a bet on somebody else's security budget, and you never get to see the odds.

  • Strategy Told Its Preferred Holders the 12% Is Partly Their Own Money Coming Back. The 1 September 8-K holds the STRC dividend at 12.00% from 16 September, and says that, as previously announced, management will recommend to the board that it stay there "until STRC has demonstrated sustained, healthy trading near $100 per share." Then the part that did not travel. As of 1 September the company "expects that the dividends payable on September 30, 2026, and October 15, 2026, will be characterized as non-taxable returns of capital to the extent of a shareholder's tax basis," with the customary advice to consult your own tax adviser. A return of capital is not income. It reduces your cost basis and defers the tax rather than removing it. The disclosure is clean and the instrument is doing what it was built to do, which is why this is a RADAR line and not a scandal. But a 12% coupon that is partly your own principal handed back to you is worth understanding before you buy it for the number on the front.

📣 THIS SPOT IS OPEN

Baseline Crypto reaches nearly 7,000 Bitcoin-focused readers every Monday and Wednesday morning, opening just under half of what we send. Direct sponsor placements are open, premium position, top of the issue, one per send.

Reply to this email for rates.

NO BULLSH*T FILTER

"The quantum thing is decades away, and the people who write Bitcoin's code have it handled."

Both halves of that are defensible. Nobody has broken secp256k1. The credible estimates for a machine that could are measured in years, the people working on the migration proposals are competent and largely unpaid, and Bitcoin has survived every previous emergency by being slow and conservative about consensus changes. Slow is the feature, and the person saying this has been right about the last five scares.

The problem is not the timeline. It is that the rescue plan says, in its own text, that it cannot rescue these particular coins.

BIP-361, "Post Quantum Migration and Legacy Signature Sunset," is the proposal to retire legacy signatures. Its second phase would encumber ECDSA and Schnorr spends with a quantum-safe rescue protocol, so a holder who can still prove ownership has a route back. The document notes that over 34% of all bitcoin have revealed a public key on chain, which is the scale of the problem it is built for.

Then there is the sentence almost nobody quotes:

"it's not currently believed possible to construct a rescue protocol for P2PK UTXOs."

The single most exposed class of coin on the network is the one class the plan explicitly cannot save. P2PK is carved out and deferred to a separate proposal that does not exist yet. So the roughly 1.7 million bitcoin sitting with their public keys already published, the coins in the most danger from exactly the machine this whole effort anticipates, are outside the rescue.

Which is why Saturday is worth more than a $19 fee normally would be. For P2PK there is no plan except moving the coins yourself, and on Saturday somebody did it in twenty nine minutes.

Run the incentives lens over the rest of that population and the shape of the problem gets clearer. Ask who is in a position to move a P2PK coin. Only someone who still holds a fifteen year old private key and knows it. Nearly all of that 1.7 million has not moved since it was mined, and the most economical explanation is that the keys are gone. The rescue protocol is being designed for the holders who can already rescue themselves. The holders who cannot are the ones with no protocol at all.

And the code underneath is thinner than the confidence around it. On 2 September somebody opened pull request 2273 against the bitcoin/bips repository, reporting two defects in the reference implementation for BIP-360, the new output type this migration would move coins into. It is a separate document from BIP-361, by different authors, and it is the consensus change of the two.

The first defect: the function that builds the control block applies no depth bound, so a deep enough script tree produces a control block of 4,129 bytes, which consensus rules require every node to reject. Code that constructs a commitment no node will accept does not fail loudly at the time. It fails later, when someone tries to spend.

The second is smaller and worse in a different way. Tree validation is implemented as a Python assert. Run the same code with the -O flag, which strips asserts out and which plenty of production tooling sets by default, and a script leaf drops silently out of the commitment. No exception, no warning. Just a different tree than the one you believed you had built.

The reporter did not stumble into this. They built an independent implementation, matched it against the reference byte for byte across all 16 official test vectors and 2,000 randomly generated trees, mailed the authors first, and filed publicly at the request of one of BIP-360's own co-authors, noting that "issues are disabled on this repo, so a PR is the closest equivalent." Five days on it has zero review comments.

That is not a scandal and we are not going to inflate it into one. Deliberate adversarial testing found two defects at proposal stage and the authors asked for them to be filed where people could see them. That is the process working. What has not happened yet is the review, on the consensus half of a change that would eventually touch every coin on the network.

What we are not claiming. We have not audited the pull request's findings ourselves, and we are not telling you that either BIP is unsafe. Two defects in a reference implementation at proposal stage is ordinary, and catching them is what review is for. The narrower claim is the one in the middle of this section: the plan has an explicit hole where the most exposed coins are, and the only thing that currently fills it is a holder with working keys deciding to spend $19.

New dated test, grades in the Monday 21 September issue. The published number is the percentage change in network difficulty at the block 967,680 retarget, as reported by mempool.space. Branch A: plus 4.00% or more. Branch B: 0.00% up to but not including plus 4.00%. Branch C: below 0.00%, a decrease of any size. One number, three ranges, no gap between them and nothing outside them. It is not the coin flip it looks like: the current estimate is above 6%, and Branch A's line sits at 4.00%, so the question is whether the hashrate response is sustained rather than a fortnight of lucky blocks. That is the standard we committed to after voiding two tests in three weeks.

BEYOND THE CHARTS
📡 REAL TIME ALPHA

Three numbers that define the next two weeks.

Block 967,680, the next difficulty retarget, on or about 19 September. The last one landed at block 965,664 on Saturday at 20:32 UTC, about two and a half hours after the P2PK sweep in the lead, and came in at plus 1.3065%, taking difficulty to 127,450,789,715,843. Retargets fall every 2,016 blocks, and 2,016 times 479 is 965,664, so the next one is 967,680. The estimate for it on Sunday evening was plus 6.1%, with the epoch under 10% complete, so expect it to move. Trailing hashrate is 944.5 EH/s. Worth correcting a thing you will read elsewhere: the network has already been above a zettahash this year, repeatedly. It crossed on 79 separate days in 2026 and peaked at 1,242 EH/s on 16 February. What is actually happening is the opposite of a milestone approaching. Hashrate has fallen back below a level it cleared all through the first quarter, even as hashprice sits at $39.63 per PH/s per day, up 22.24% over thirty days. Miners are being paid better and are running less machine, and the retarget estimate says that is starting to reverse.

180,870 BTC, the 25 September options expiry. Deribit bitcoin options open interest is 416,656 BTC, about $33.4 billion at Sunday's price. The 25 September expiry alone accounts for 43.4% of it. The 18 September expiry, the first one after the FOMC, holds 9,196 BTC. Read that ratio twice. Almost nobody is positioned for the meeting itself. The positioning sits nine days past it, which is the options market saying the decision on the 16th is not the event. Whatever gets said around it is.

$903,928 million, the Treasury General Account on 3 September. It closed 31 August at $1,023,554 million and was down to $903,928 million three business days later, a $119.6 billion drawdown. Before anybody reads policy into it: 1 September alone carried three HHS trust fund lines, Medicare Prescription Drugs among them, totalling $67.35 billion, which is 83% of that day's fall, and 3 September was Social Security day at $26.45 billion. Month start mechanics, not a decision. It still moves the test we set five days ago, which grades the 30 September closing balance in the 5 October issue. Branch C, under $950 billion, is live in a way it was not last week, though the mid-September corporate tax date sits between here and the measurement and pushes the other way. No update today: Monday is Labor Day and the Daily Treasury Statement does not publish.

POLYMARKET STACK
🎯 WHAT REAL MONEY IS BETTING

Forget analyst predictions. Polymarket is a real-money prediction market, where traders put actual dollars on outcomes. Scorecard first, then the board. Not financial advice. Our read. Disclosure: we hold personal positions in Polymarket itself and may earn a commission from Polymarket referrals. These markets are thin and the odds below move, so read direction over ticks.

Scorecard: no position for a tenth consecutive issue, and the entry condition got no closer.

The trade we have published and not taken is high yield spreads widening through 3.00% into the late October Treasury cash peak. HY OAS was 2.65% on 3 September, the latest print FRED has posted. That is 35 basis points away. Across 31 August to 3 September the series reads 2.63, 2.65, 2.66, 2.65, a three basis point range that spans a payrolls beat, a large move in oil and Japanese government bond yields at multi decade highs. Credit did not blink. We are not going to write that up as coiled tension or a market waiting to reprice. It is a market that disagrees with us, and until it moves we do not have a trade.

Ten issues flat deserves a plain statement rather than a shrug. A permanently idle book turns a scorecard into theatre, and we know it. The condition above is the only thing that puts us back on the board, it is published in advance, and you can check whether we honour it.

Three dated tests are open. September's ETF total grades 7 October and is tracking Branch A at plus $770.0 million through four sessions. The 30 September Treasury cash close grades 5 October, and Branch C came alive this week; the arithmetic is in BEYOND THE CHARTS. The new one, set in the FILTER, grades in the 21 September issue on the percentage change in difficulty at block 967,680. All three are built the way we said they would be after voiding two tests in three weeks: one published number, ranges with no gaps.

One market we are deliberately not quoting. Polymarket's September bitcoin price ladder has had legs re-created mid month with a "from September 3" start, so those quotes are not comparable to the ones we printed earlier in the month. We are leaving it off the board rather than publishing numbers that look like a continuous series and are not one.

Fed decision in September, 25 bps increase | Market: 49.5% NO TRADE, it is a genuine coin flip and we do not trade coin flips
No change sits at 50.5% against 49.5% for the hike, with 50 basis points or more at 0.55% and the two cut legs adding to 0.5%. These are five separate binaries quoted at midpoints, so they sum past 100 and are not a distribution. We quoted the hike at 57.5% on Wednesday. What happened in between is worth more than the level. It fell to 40.5% by Thursday morning after Governor Waller said on the 3rd that "if there is continued progress toward our 2 percent goal, then I am willing to support holding the policy rate at its current level," adding that "if inflation comes in hot, I would consider a rate hike." Note that is a conditional hold rather than a dovish one. It sat at 42.5% Thursday evening, then recovered to 49.0% on Friday when payrolls came in at plus 162,000 against a consensus near 53,000. A seventeen point fall and a nine point recovery in four days, all of it driven by one speech and one release. That is not a market with an edge, it is a market with a news feed. Resolves 16 September. What would put us in: a move back under 40% with the Fed's stated position unchanged, which would mean the market pricing a path the Fed has not signalled.

CLARITY Act signed into law in 2026 | Market: 16.5% EXITED at roughly 33 to 37%, and the re-entry condition is still unmet
A correction first, because we got this wrong in the last issue. Wednesday's STACK said we exited this at 41%. We did not. 41% is where the position opened, and we exited on the published cloture rule at roughly 33 to 37%. That is a loss, it is recorded as one in the ledger, and describing the entry price as the exit turned it into something cleaner than it was. The ledger has always had it right and the issue did not.
On the market itself: it was 13.5 to 14.5% on Wednesday and is 16.5% now, so it has firmed slightly into a week that made the bill less likely rather than more. Here is the calendar arithmetic almost nobody priced. On Thursday, House leadership cancelled the weeks of 21 and 28 September. The House returns on 14 September and leaves on the 17th, and the Senate's cloture vote on the motion to proceed is the 15th. That leaves two House session days after the Senate even starts moving, for a bill that has to clear both chambers and be signed inside this calendar year. A scheduling memo did what two years of lobbying could not. The one real improvement came on 3 September, when the National Sheriffs' Association was reported to have moved from opposition to neutral, which takes a durable objection off the table for whenever this comes back. Our published re-entry condition has three legs: the merged text survives markup and cloture, and the contract is still under 30%. None of the first two has happened. We stay out.

Track the whole board live at polymarket.com, free, no account required.

PULSE CHECK
💬 YOUR TURN TO WEIGH IN

Wednesday's question is not due yet, and we are not going to pretend otherwise.

We asked which of two things you would stop believing if both were still true on 31 October: Treasury draining tens of billions more, and credit pricing none of it. That date is eight weeks out. What we can report is that neither side has moved much. Credit went 2.63% to 2.65%, which is noise. The Treasury account fell $119.6 billion, and almost all of it was trust fund plumbing rather than anything anyone decided. The question stands, unresolved, as written.

This issue's is smaller and harder.

Roughly 1.7 million bitcoin sit in P2PK, with their public keys already published on the chain. The migration proposal states that it cannot build a rescue protocol for them. On Saturday one holder solved it for 600 coins in twenty nine minutes, for $19.28, because they still had the keys. Almost nobody else does. So: if a machine capable of deriving those keys eventually arrives, would you rather the network froze those coins before it does, or left them spendable by whoever gets there first?

Both answers cost something real. Freezing means Bitcoin's rules can render coins unspendable at an address that broke none of them, which is the exact property most holders think they are buying. Not freezing means the largest single transfer of wealth in the network's history goes to whoever builds the machine first, and it will not be somebody who needs the money.

We do not have a settled answer, which is why it is the question rather than the argument. If you have one, we want the version with the cost accounted for rather than waved off.

Hit reply. We read every response, and the best calls run Wednesday.

See you Wednesday, with the first post-holiday ETF prints, the difficulty estimate as it firms toward the retarget, and whether anybody has reviewed pull request 2273.

The Baseline Crypto Team

HELP YOURSELF

Three tools we built because we wanted them and could not find them. Free, no signup, no accounts, and nothing you type ever leaves your browser.

Is your hardware wallet screwed? Check your device and firmware against every logged advisory, including the ones where updating your firmware does not save you, because the seed itself is already weak.

How fragile is your self-custody? Nine questions, scored out of 27. Every question exists because of a documented loss.

Our track record, losses and voids included. The public ledger of every dated call. It is running behind the last few issues and we are fixing that this week, so today the STACK above is the live record and the page is the archive.

Everybody knows somebody who bought early, moved the coins somewhere safe years ago, and has not looked at the address format since. That person is not going to read a BIP and should not have to. Send them the wallet check. And if they were one of the 5,411 Pocket Bitcoin customers who got a letter this week, send them the custody audit too, because the thing that turns a data breach into a loss is never the breach.

DISCLAIMER: None of this is financial advice. This newsletter is strictly educational and is not investment advice or a solicitation to buy or sell any assets or to make any financial decisions. Please be careful and do your own research.