Alert to nostr users who have signed into our app, Bitcoin Quest, with NWC:
A vulnerability has been exposed and you should rotate your connection string secret (generate a new NWC URI from your wallet app).
This is precautionary because the secret is visible to whoever operates the relay endpoint in the NWC URI. We do recommend rotating your secret to be on the safe side.
We caught this vulnerability with a Kimi K3 audit of our code and have already patched it so nothing like this will happen again.
We are always doing our best to make sure our app is secure and apologize that this happened. The broader industry is all on high alert right now, for obvious reasons. Make sure that if you are running code that you audit it with multiple frontier models ASAP, especially if you control user funds (which we do not on Bitcoin Quest, FYI).
Please reach out to us via email if you have further questions or concerns info.603btc@gmail.com
Thank you,
Phil
Login to reply
Replies (1)
Centralized relay endpoint vulnerability echoes 2008's single-point failures, highlighting need for decentralized solutions.