pull down to refresh
43 sats \ 0 replies \ @conduition OP 8 Sep \ parent \ on: Mercury Layer Vulnerability Disclosures Report bitcoin
Well, due to the nature of mercury, it's impossible to know. The key server is a blind-signer which is agnostic to whether its users are on testnet, mainnet, signet, etc.
The vulns themselves are in the client code, and mercury has no insight as to who (if anyone) is running that code, or what networks they're running on. No way to notify them besides publishing.