pull down to refresh

If there isn't much sats in the linked wallet, is it still need to do anything? 😅

reply

Bitcoin is def not for the weaks, a new hack each day...😂

reply

I guess it's the red team hardening bitcoin projects against new LLM vulnerabilities discoveries

reply

Fun fact: all those "discoveries" were made by the same LLM / AI agents.
So now humans are working double to fix what they should be done by them in the first place.

Very good efficiency in coding, right.

reply

Why don't they hack the banks or something else, there are more money outside of Bitcoin....

reply
111 sats \ 1 reply \ @DarthCoin 7 Aug

reminder: banks are full (or empty) of fake money.
Who wants to rob fake money if they can print endlessly?
Bitcoin instead is real money. And irreversible.

reply

😂😂😂 make sense.

reply
You don't need bots to produce bugs, humans can do this perfectly by themselves

- Linus

reply

Humans make mistakes and bugs.
Bots learn / read data from humans.
Its'a a circle.

reply

Yes.

reply

Humans also created bots = create more work while wanting the bots to do the work? 😂

reply
reply

and after finding these (with AI) they will ask again AI to write a patch, then they will just push the "release" button...

reply

😀😀😀

reply

so all these drams are createdby AI. 😂

reply
1 sat \ 3 replies \ @Lux 7 Aug

Fun assumption :D

reply

more to come. this is just the beginning...
but is fun.

reply

People outside the BTC space must be looking at these and laughing rn. 😂

reply
1 sat \ 0 replies \ @Lux 7 Aug
more to come

oh yes

reply

Yes — the balance in the hot wallet is not the whole exposure.

The hole is in BTCPay's own admin/API auth, not in the wallet. Someone who gets in can change where future money goes: the store's derivation scheme / payout settings. Your invoices keep being generated and paid by customers, and the funds land on an xpub that is not yours. An empty wallet today does not protect next week's sales.

Two other things leak that have nothing to do with balance: your invoice history (customer emails, addresses, order amounts) and any connected node credentials, which is why the LND macaroon rotation advice is in there.

So: update, then change the password, then re-check that your store's wallet xpub is still the one your hardware wallet shows. That last step is the one people skip and it is the one that costs you money quietly.

101 sats \ 10 replies \ @justin_shocknet OP 7 Aug -210 sats

Looking at the patch commits it seems that an attacker could glean connection details to the backing node

You wouldn't want to receive a payment with an attacker lying in wait, definitely update, and I'd recommend rotating the connection credentials to the backing node