Lightweight Bitcoin Wallet | No support over Twitter. npub1zqnl6k7rkhjsexqq6j9u3t8mc2gd3xu9037wz4tj54cy33xq2k8qpqv2pm

Not your keys, not your coins. Not your lightning channels, not your coins. Not your federated sidechain, not your coins. Verify the software you use. Use software that verifies instead of trusting.
17
67
437
16,751
Electrum retweeted
We've paused Blink services while we investigate a security incident. An attacker accessed a limited number of custodial accounts and withdrew funds. The large majority of funds are secure. Non-custodial wallets are not affected.
54
200
549
152,683
Electrum retweeted
The recommendations column in fedimint observer is useless. I just spammed thousands of nostr events and changed this federation's rating from 4.7 to 1.3. Cc: @fedimint @EricSirion
7
7
68
8,222
New release: Electrum 4.8.2. This is another security update, so please upgrade. Thanks to all contributors and researchers who reported issues to us. electrum.org/#download
8
64
346
32,063
Not your federation, not your coins. This post is from 6 month ago. It became real today. primal.net/e/nevent1qqsqfvxk…
8
31
269
11,120
The old world is dying, and the new world struggles to be born: now is the time of monsters.
18
69
594
18,308
Talking about how AI is reshaping the security landscape
1
2
43
2,085
Electrum retweeted
Liquid hack explained. Liquid has confidential transactions that hide the amounts for improved privacy. A bug in how these transactions are validated caused inflation of Liquid BTC (L-BTC) and allowed hackers to empty the entire side chain. Liquid nodes don't see the amounts of a confidential transaction, so to make sure that the transaction is still valid and doesn't cause inflation nodes check something called a balance proof and a range proof. The balance proof establish that sum of the input amounts equal the output amounts, i.e., that "x L-BTC going in and x L-BTC going out". But there's a catch. Only relying on a balance proof isn't enough. You also need the range proof. The range proof establishes that a hidden output amount falls within a positive range. That means a valid output must be at least 1 L-sat and at most 2^64 − 1 L-sats. Range proofs make sure that you can't mint "negative L-BTC". Why is this even necessary? Remember, the amounts are hidden and a hidden negative amount would allow extra positive outputs to balance against it. Without a range proof, a transaction could say "I've put 1 L-BTC in, and I'm taking two outputs out: one with 4000 L-BTC and one with -3999 L-BTC)." This is going to cause a disaster in a little bit. Once the balance proof, the range proof, and other validations pass, a transaction is regarded as valid and can pass consensus. However, because especially the range proof is computationally expensive, Liquid nodes cache the result of a successful range proof in memory. Essentially, the node remembers "I saw this range proof before and it was valid, all good!". In order to recognize the same range proof later on, you need to assign a label to it. This is called a cache key. This cache key is the actual cause of the bug. The way this cache key was constructed allowed two different transactions to collide on their cache key. Essentially, one valid transaction (1 L-BTC in, 1 L-BTC out) had the same cache key as an invalid transaction (1 L-BTC in, 4000 L-BTC out). Here's the hack: the attackers submitted the valid transaction (1 L-BTC in, 1 L-BTC out) first. Liquid nodes verified this transaction successfully, created a cache key called REKT and stored it in their cache. Then the attackers carefully crafted a second invalid transaction with (1 L-BTC in, 4000 L-BTC out) that created the same cache key REKT. Instead of validating the second transaction and realizing that it printed money out of thin air, Liquid nodes found it in their cache and said "hey I saw this transaction before, everything is fine" and that caused the inflation. The attackers then took their 4000 L-BTC and withdrew 4000 BTC onto the Bitcoin base chain. Note: I might have gotten some details wrong, and I'm aware that I simplified quite a bit. I wrote this post to help people understand what happened. Please feel free to correct me in the comments or add more details below.
83
253
1,468
151,700
If you are wondering why Electrum does not create BIP39 seeds
21
24
209
69,285
The current period in the history of Bitcoin will be remembered as the Great Hardening
29
73
638
35,134
... actually, in the history of software.
1
50
2,621
Electrum retweeted
Replying to @MrHodl
What everyone is calling “passphrase” @ElectrumWallet is calling “Seed Extension” There will forever be confusion between “Password” used for encrypting your wallet and “Passphrase” used for extending your Seed.
2
3
30
5,637
To clarify: The security fixes we made do not concern seed/random number generation, so there is no need to move your coins to a new seed. The fixes are mostly related to submarine swaps, as hinted at in the other replies.
2
1
42
2,410
Not sure if the BIP110 chain will ever reach difficulty retarget
24
5
163
12,438