Bitcoin Magazine

BTC++, Berlin, and breakthroughs in advancing Bitcoin custody

A few weeks ago, I argued that the Bitcoin ecosystem kept asking the wrong question, tending to frame everything as “trusted” or “trustless.” Instead, I urged people to ask “How many independent things have to go wrong before you lose your money?”

This is a guest post by Obi Nwosu, Co-Founder of Fedi and Fedimint. Opinions expressed are entirely their own and do not necessarily reflect those of BTC Inc.

Look at Liquid or, weeks before that, Coldcard. Matt Corallo expressed the issue in the most succinct terms: run the same software, suffer the same bugs.

That critique applied to Fedimint, too, and I’m the first to say it. We built it to remove single people and single institutions as points of failure. But there was just one implementation of the protocol — a software monoculture below federations of humans.

And so I’m happy to say that Fedimint developers have already responded.

At Ecash Hackday in Berlin, the Fedimint team got a single federation running across three independent implementations, with Cashu’s thesimplekid building one of them.

Had a great time at Ecash Hackday in Berlin, got a Fedimint running with 3 different implementations by @thesimplekid, me and the Fedimint team! Already got 3 Fedimint implementations now, who will build the 4th one? https://t.co/TnttZYOBKR pic.twitter.com/2MPdtlaJqt — elsirion (@EricSirion) September 30, 2026

Three separate codebases, one federation, holding funds together. Developers have begun to create a solution to the monoculture I called out a few weeks ago. And the team’s response was to ask who builds the fourth, which is exactly the spirit I was hoping for.

Calle took the same principle and ran with it in his own direction. At bitcoin++ he unveiled Federated Cashu, which is designed in a way that no single operator stands alone behind a user’s funds. Any four or five keep the federation going, on a new blind signature scheme.

. @callebtc unveils “Federated Cashu” at @btcplusplus “You don’t need to trust the operator with your privacy, but you do need to trust the operator with your security” “Any combination of 4/5 continues the federation” A new Blind BLS signature scheme is involved. pic.twitter.com/S8iL9Qaa9u — Matthew Vuk (@matthewvuk2) October 1, 2026

Two teams. Two approaches. One shared goal: ecosystem resilience, advanced within weeks.

Fault tolerance does not come from trustworthiness alone, however good your audits, formal verifications, and your security culture are. It comes from independent failure domains. No single bug, no single vendor, no single jurisdiction able to take everything at once.

I’ll be clear about the layers, because the distinction matters. Fedimint is the open-source protocol. Fedi is what we build on top of it. When the protocol grows a second and a third implementation, every federation gets more resilient and no member has to change a thing about how they use their wallet. Guardians can run different software while serving the same people.

I laid out five layers where independence has to hold, and I’ll hold myself to them:

  • Multiple implementations of every protocol that holds funds.
  • Multiple wallet implementations.
  • Keys generated on hardware from different vendors.
  • Multiple independent, trustworthy people, whose privacy is protected, behind every system that holds money.
  • Distribution across geographies and jurisdictions, because a jurisdiction’s rules can change overnight.

The developers who worked on this in Berlin moved those five closer to reality.

Thank you to everyone who continues to focus on building and sharing their proof-of-work. And to the rest of us, myself included: we are not done. Our ecosystem needs to start demanding independence at every layer. Software, hardware, humans, jurisdictions — all the way down.

That is how we maintain users’ confidence in Bitcoin as we enter this new age of AI-assisted threats to our ecosystem.