Replies (26)
Depends on how they disclose to the project. Do we have confirmation either way?
The grift continues
just another virtue signalling grift
Someone posted a graphic that was like 390 out of 391 projects were flagged as vulnerable.
Once again, good opsec and responsible disclosure is to go thru back channels to give devs a chance to remediate THEN you spill the beans.
Agreed
Because they need to use the crisis to get back some of the lost social capital. In reality they are doing nothing useful. Stupid people will cheer it anyway.

🚨 NEW SWEEP THREAT 🚨
We need eyes on this; plz repost. 🤙
exist270
#ColdCard funds are getting swept WHILE THE #BITCOIN / #BTC TRANSACTIONS ARE STILL IN THE MEMPOOL.
The attacker is clearly watching broadcasts, so unless users are signing transactions straight from a miner, this shit is gonna keep getting worse until ALL at-risk funds have been drained. 🫠
Absolute fucking shambles. 🤙
https://x.com/i/status/2085325832285757680
View quoted note →
View quoted note →
🚨 NEW SWEEP THREAT 🚨
We need eyes on this; plz repost. 🤙
exist270
#ColdCard funds are getting swept WHILE THE #BITCOIN / #BTC TRANSACTIONS ARE STILL IN THE MEMPOOL.
The attacker is clearly watching broadcasts, so unless users are signing transactions straight from a miner, this shit is gonna keep getting worse until ALL at-risk funds have been drained. 🫠
Absolute fucking shambles. 🤙
https://x.com/i/status/2085325832285757680
View quoted note →
View quoted note →
Jews have always been the ultimate gypsys/chameleon’s.
100% yeah… that is a major opsec issue if back channels were not tried before disclosure.
No words…
PsyOps are effective. Simple.
They just got rid of NVKlown five minutes ago and theyre simping for Rob Hamilton and doing PR stunts
They have to be tried AND given sufficient time to issue fixes across the board.
Typical panic
What it it was the plan all the way. Imagine it they actually plant more exploits then patch
Because we are entering a paradigm shift when it comes down to software development. We either bundel together as a community or all get wrecked individually. But that’s just my opinion.
This definitely does feel like an attempt to shift the blame or to justify the fuck up.
There are ways to accomplish this mission without yapping about it online every day and making yourself a target to would be hackers and infiltrators
We are in a jungle and instead of quietly grabbing spears and making defensive formations our peers are shouting and virtue signaling to deflect blame
Devs can do the same effort without broadcasting. OpenSats can give the money quietly and just wait a month after patches are there to start virtue signaling. Instead they choose to broadcast to the world the existence of the vulnerabilities. OpenSats is the last group that should be talking right now.
What are these ways ? Cause in my mind if you have a piece of software either running or shipped having a small group where you can go to that poke holes into your system is exactly what we could use. Boltz getting disabled is a sign of those times 🤷♂️ and those are experienced dev blokes. What chance do the little guys stand 😂 ?
You understand that you can send emails to maintainers and just do the work without giving hourly updates?
It is blatant self promotion from the in group. The same one that cheerlead and enabled NVKlown
Tokens aren't free.
Rest assured the bad actors have already known. Good guys catching up.
Ugh email 😆 I agree with some but I guess the last thing the self custodians need is another leak like this one so everyone on edge, but in the end a funded red team is a good thing in my book. The exploit sat dormant for quite some time before it got used this broad so running an initial sweep will raise allot of bugs. Best thing is if we don’t hear about them anymore cause everything’s fine and dandy 😄
It now, even putting out the numbers of vulnerabilities out there is a target… sounds like they contacting teams before hand per Calle.
Still the sloppiness doesn’t go away with the same team that brought the problem in the first place.
Is the Wolf is in the hen house now?