Hi, everyone.
I’m bummed to report that this account has been compromised.
I’ve started a new personal account at the following npub:
npub14ad23x8g6yak4mm6nad9umm7grq0ckhf4s70svq4wn5fgjywf9es9vxvet
You can also search for me at frank@primal.net.
You’ll see that my Primal Legend status has been transferred to that new account.
I’d greatly appreciate if you could share this post to help my followers find me.
I’d also like to give a major, major shout out to @The Daniel 🖖 and @miljan who’ve been helping me out tremendously in the wake of the account being compromised.
They’re both absolute legends.
To help show that the new account is real, you’ll see that they’ve both already followed me over there.
Thank you and onward 🫡
Login to reply
Replies (16)
Happens. Following on new npub 🫡
Maybe change your bio and point to new npub? Also update name with compromised or something
What if we add another kind of "block/mute/warning" for compromised keys, so npubs can flag old accounts and or "Compromised keys"..
#asknostr
View quoted note →
Unfollowed/Followed
How did it happen tho?
Would love to know the deeds so we can all learn from it.
Back in ancient times, I accidentally saved my hex private key in the nostr.json file on my web server when I was setting up my first NIP-05. Fortunately, I caught it immediately and swapped it out for my hex public key before anyone noticed.
The new Primal mobile app has a signer that you can use to login to the web version, and it even brings your wallet over.
All it takes is one sleepy moment...
Oh well, let's hope things stay alright now! :)
Oof x) Glad you caught it tho!
That’s kind of the best you can do, short of “deleting” your account, which is kind of bullshit, but it adds a "deleted": true flag to your profile that tells some clients to deny access.
posting compromised in a supposedly compromised account. how about that. is it compromised or are you a canary by any chance? et al. elaborate on this. ppl losing their private keys have forfeit their right to participate. meh. why listening to a supposed compromised posts ti begin with. i am tellin lies you shouldnt believe me (tm)
Yeah
Yeah, it’s just a way to manually sign and broadcast an event using your key. Has nothing to do with logging into apps.
How does one access the web vs?
That sucks, followed!
Clients shouldn’t allow you to do that. Unfortunately, this feature is often overlooked.