Old post but still very relevant.
pull down to refresh
21 sats \ 3 replies \ @Wumbo 13h
Interesting attack vectory
reply
65 sats \ 0 replies \ @ek OP 13h
My favorite part:
When your heist is limited by your own CPU haha
reply
0 sats \ 1 reply \ @OT 12h
If the routing node charges too much the payment will likely fail due to high fees right?
reply
0 sats \ 0 replies \ @ek OP 11h
You can lower the fee until the payment suceeds, then it's free money
reply
43 sats \ 1 reply \ @Scoresby 13h
I have not tested this empirically (meaning I'm just going off the feels here) but I think most ecash wallets pass the routing fee on to the user when leaving the mint. Which wallets still exist that are custodial and that do free withdrawals? Is it WoS? I haven't used them in a good while...
reply
107 sats \ 0 replies \ @ek OP 13h
This should be a pretty well-known attack by now.
I remember that Kraken allowed free lightning withdrawals though.
Asking for a friend? haha
No, the post mentions they actually had the best security among those tested:
reply
115 sats \ 0 replies \ @DarthCoin 12h
Yes, I've tested that on Muun wallet. You are able to steal sats from Muun that later are charged from other users to cover the loses.
Using this garbage app nowadays is pure insanity and I warned about this long time ago.
Also another thing to mention about this: Muun was also bloating the block space:
https://xcancel.com/mononautical/status/1621663167582437376
https://xcancel.com/mononautical/status/1621893734156623872
reply
0 sats \ 2 replies \ @BallLightning 9h
Isn't this what is called fee siphoning attack? Also what would prevent something similar happening in the hypothetical future where merchanta use lightning? A merchant sets a node with high fee between his node and you and charges high fees from his customers?
reply
0 sats \ 1 reply \ @ek OP 9h
Yes, it's called fee siphoning and I believe wallets already do that. It's part of their business model. CashApp and ACINQ (the company behind Phoenix) are examples.
reply
0 sats \ 0 replies \ @BallLightning 9h
I kind of think this is a problem 🤔. I think I encountered this also when purchasing a channel from blocktank. Incoming payments were a lot more expensive than the default fees from robosats. It took me a while to figure out why I can't receive the sats I purchased.
reply