
We’re following Bitcoin’s story in motion: tracking the markets, corporate moves, regulatory environment, mining progress, protocol upgrades, Lightning Network growth, and the new tools and products driving adoption.
Bitcoin Rallies to $87,000 Before Losing Momentum
Bitcoin climbed sharply at the start of the last week, rising from around $81,100 on Sept. 21 to nearly $87,400 before closing at about $86,600. Trading volume jumped alongside the move, while U.S. spot Bitcoin ETFs recorded roughly $999 million in net inflows. More than $800 million in short positions were also liquidated, adding momentum as traders betting on lower prices were forced to close their positions.
The rally stalled near $87,000. Bitcoin held above $86,000 on Sept. 22 before briefly pushing back toward $87,300 the following day and then falling to around $84,000. The reversal came as higher U.S. Treasury yields added pressure to risk assets, while traders took profits after the week’s sharp advance.
BTC then settled into a narrower range, with the $83,000 area providing support. Bitcoin briefly dipped below that level on Sept. 24 before recovering toward $84,000, and remained largely between $83,000 and $85,000 through the weekend.
By early Sept. 28, Bitcoin fell closer to 83,800, roughly 4% below the weekly peak but still above the level where the rally began.

| Put your Bitcoin price predictions to the test and build a track record — check out Glimpse, the Bitcoin-native prediction market. |
U.S. Bitcoin ETFs Post Strongest Weekly Inflows of 2026
U.S. spot Bitcoin ETFs attracted roughly $2.39 billion in net inflows during the week ended Sept. 25, with every trading session recording positive flows, according to SoSoValue data. Monday led the surge with $999 million, the largest single-day inflow since October 2025, followed by $714.7 million on Tuesday, $347 million on Wednesday, $190.6 million on Thursday and $134.5 million on Friday.
The buying was led by BlackRock’s IBIT, which took in about $1.2 billion for the week, followed by Fidelity’s FBTC with $701.7 million and ARK 21Shares’ ARKB with $294.7 million. The seven-session streak of positive flows, which began Sept. 17, brought in roughly $3 billion, although daily inflows declined steadily after Monday’s outsized print.
Why it matters: The week marked a sharp return of demand for U.S. spot Bitcoin ETFs, but the steady decline in daily inflows after Monday leaves open whether the surge represents sustained institutional buying or a concentrated burst of demand.
Strategy Buys Bitcoin After Three Week Pause
Bitcoin treasury companies opened the week with a combined purchase of 2,305 BTC worth about $182.7 million, led by Strategy and Strive. Strategy said it bought 950 BTC for $75.7 million between Sept. 15 and Sept. 21, marking its first bitcoin purchase since August. Strive, meanwhile, added 1,355 BTC for roughly $107.7 million, according to the company’s announcement. Strategy now holds 846,000 BTC, while Strive’s holdings have reached 26,355 BTC, according to the companies’ reported figures.
Strategy’s latest purchase comes after a period in which the company focused more heavily on repurchasing its STRC perpetual preferred shares and building its cash position. It repurchased $174 million of STRC in the latest period.
Why it matters: The latest purchases show that corporate bitcoin accumulation remains active even as major treasury companies balance BTC purchases against capital-market activity and liquidity needs.
Core Lightning Urges Node Operators to Upgrade
Core Lightning developers have released version 26.06.8, a point release that includes bug fixes and patches for vulnerabilities reported by multiple sources. The release was published Sept. 22, with the project explicitly recommending that node operators upgrade.
Block Brings Bitcoin Lightning to x402 for AI payments
Block has joined the x402 Foundation, the Linux Foundation-backed initiative developing an open standard for payments between AI agents, businesses and people. The company said it will contribute its payments expertise to the foundation’s working groups while helping develop open infrastructure for agentic commerce.
Alongside joining the foundation, Block has contributed Bitcoin Lightning support to x402. The protocol uses HTTP’s 402 “Payment Required” status to allow software to request payment for APIs, data and other digital services, with the transaction taking place as part of the web interaction. Block said Lightning’s fast settlement and low-cost, high-volume capabilities make it suited to the small, frequent payments expected from agentic commerce.
Core Lightning 26.06.8 is out, and every node runner should upgrade.
This release fixes vulnerabilities responsibly reported over recent weeks. There is no embargo period: the release and fixes are available right now.
A number of tests are being held back temporarily to make…
— Core Lightning ⚡️ (@Core_LN) September 24, 2026
Unlike the previous security response, 26.06.8 has no embargo period: the fixes are available immediately. However, the developers have temporarily withheld a small number of tests to make it harder for potential attackers to reverse-engineer the vulnerabilities before operators have had time to update. The release credits the Bitcoin Red Team and several independent security researchers among those who reported issues.
Why it matters: Core Lightning is widely used to operate Bitcoin Lightning nodes, with the release coming after a series of security issues affecting Lightning infrastructure in recent months, including vulnerabilities uncovered through a wave of AI-assisted security research.
Block Brings Bitcoin Lightning to x402 for AI payments
Block has joined the x402 Foundation, the Linux Foundation-backed initiative developing an open standard for payments between AI agents, businesses and people. The company said it will contribute its payments expertise to the foundation’s working groups while helping develop open infrastructure for agentic commerce.
Alongside joining the foundation, Block has contributed Bitcoin Lightning support to x402. The protocol uses HTTP’s 402 “Payment Required” status to allow software to request payment for APIs, data and other digital services, with the transaction taking place as part of the web interaction. Block said Lightning’s fast settlement and low-cost, high-volume capabilities make it suited to the small, frequent payments expected from agentic commerce.
Block has joined the x402 Foundation, an open standard for agentic payments, to help build the rails that will let people, businesses, and agents pay and get paid.
We’ve also contributed Bitcoin Lightning payments, which is purpose-built for the instant, low-cost, high-volume…
— Block (@blocks) September 24, 2026
Why it matters: The move extends Block’s broader work around AI-driven commerce, including its involvement with the Universal Commerce Protocol and contributions to open-source AI agent software. It also gives x402 another payment rail beyond the stablecoins that have so far dominated the protocol’s activity.
Blockstream Provides a Security Incident Assessment of the Recent Liquid Network Exploit
Blockstream has published a technical postmortem of the Sept. 6 Liquid Network exploit, detailing how an Elements software vulnerability allowed an attacker to create roughly 4,000 LBTC without corresponding bitcoin backing. The root cause was a flaw in the rangeproof verification cache: a deliberately constructed byte sequence could match a previously validated cache entry, allowing a fabricated rangeproof to bypass verification.
The report says the vulnerability originated in code dating back to 2018 and survived a 2019 refactor. More immediately, Blockstream said it had received a report about a related cache vulnerability on Aug. 2 and deployed a fix, but the remediation itself introduced the conditions that made the second, exploitable bug possible. No internal or external review identified that byte-boundary issue before the Sept. 6 attack.
According to the company, it has since replaced the vulnerable cache-key construction with length-prefixed serialization, added additional safeguards around context-sensitive caches and plans recurring security reviews of consensus-critical code, alongside expanded fuzzing, mutation testing, symbolic execution and AI-assisted review.
Why it matters: Since Liquid is used for moving and issuing Bitcoin-related assets, including stablecoins and security tokens, the incident has implications for institutional Bitcoin infrastructure. A consensus-level exploit is materially different from a temporary service outage as it can affect assumptions about the supply and backing of assets issued on the network.
Shielded Bitcoin Proposes Zcash-Style Privacy Without Changing Bitcoin
Researchers Clara Shikhelman, Mikhail Komarov and Aleksei Moskvin of [alloc] init have published a 56-page proposal for Shielded Bitcoin, a metaprotocol designed to hide the sender, recipient and amount of Bitcoin transactions without changing Bitcoin’s consensus rules. The paper uses encrypted “notes,” zero-knowledge proofs and public nullifiers to allow users to prove that a transaction is valid and does not double-spend funds without revealing the underlying transaction details.
The key architectural choice is to leave Bitcoin largely unaware of the privacy layer. Bitcoin would publish and order the encrypted data, while separate software called indexers would verify proofs and reconstruct the shielded state. The approach therefore does not require a soft fork, a separate blockchain or a trusted custodian. Users would also be able to derive read-only viewing keys, allowing transaction information to be disclosed selectively to auditors or counterparties without giving them spending authority.
Shielded Bitcoin: Private Transfers on Bitcoin L1 pic.twitter.com/X7nZRzDiJ7
— Alloc Init (@allocinitxyz) September 24, 2026
Speaking of the trade-offs, the paper does not yet provide a mechanism for moving coins into or out of the proposed system; that is being left to a separate paper that uses PIPEs, a technique designed to lock a Bitcoin signing key until specified conditions are met. The reference implementation also uses Groth16, whose security depends on a trusted setup ceremony. Details such as transaction timing, fees, the number of inputs and outputs, and the Bitcoin transaction carrying the data remain visible. Komarov also estimated that a private transfer would require roughly 700 virtual bytes, compared with around 100–200 virtual bytes for a regular Bitcoin transaction, putting miner fees at about four times as much at an equivalent fee rate.
The anonymity-set question is another unresolved issue. A new shielded pool would initially have far less transaction history than an established privacy network such as Zcash, meaning that distinctive deposits, withdrawals and usage patterns could still provide clues to observers. Critics have also questioned the proposal’s reliance on synthetic shielded value until a functioning BTC entry/exit mechanism is demonstrated. The researchers themselves acknowledge that large deposits or unusual wallet behavior can narrow the set of plausible counterparties.
Why it matters: Shielded Bitcoin represents a serious attempt to add transaction privacy to Bitcoin without asking the network itself to change, but for now it remains a research proposal rather than a deployable system.
Lightning Gets a Post-Quantum Prototype
Researchers at East Texas A&M University have published PQLN, a post-quantum extension of the Bitcoin Lightning Network that has been implemented in a fork of rust-lightning and tested on real nodes. The design adds hybrid classical/post-quantum cryptography to Lightning’s gossip, peer-to-peer transport, invoices, payment onions and offers, using NIST-standardized ML-KEM for key exchange and ML-DSA for signatures. The researchers say this can be deployed at the Lightning layer without waiting for a Bitcoin consensus change.
With roughly 11,000 lines of code added, the researchers tested 12 combinations of post-quantum and conventional Lightning nodes. The upgraded nodes remained interoperable with legacy nodes in the tests, while a require-PQ option allows users to fail rather than fall back to classical cryptography. The main performance cost was not computation—the most expensive cryptographic operation reportedly took about 0.33 milliseconds—but network overhead. The proposal authors say a PQLN node requires roughly 10 times the download bandwidth and nine times the storage of a conventional Lightning node: about 270 MB of gossip data versus 26 MB for a standard node under the tested configuration.
Why it matters: PQLN turns post-quantum Lightning from a protocol-design discussion into a working implementation. That being said, it’s still a research implementation, not a Lightning Network upgrade adopted by node operators. Bitcoin Optech notes unresolved issues including relay-size limits, the need to assign feature bits and TLV types, and questions around protections such as pinning. More importantly, PQLN only addresses Lightning’s off-chain surfaces: it does not make Bitcoin’s on-chain keys or channel-funding transactions post-quantum safe, which would require changes at the Bitcoin protocol level.
