yes nitro signs it no an HSM cannot do the required math for cashu. even if it does, it exposes itself to the risk that it is lied to about the success/failure of payments from the outside LN node, so it must operate as a closed system. also the HSM can just be smashed an attacker can also just deny access to the mint. they could say that you can get 50% of your ecash back, but only by sending your tokens to them. the user can either do nothing (and lose it) or try (and probably get it back, but also net the attacker money). the second case is the only one that is good for the user

Replies (4)

or just ghost everyone. my solution to this in bitcoinsdeposits.net is to have public ledgers and funds controlled by someone other than the operator, so if they disappear another node just takes over couldn't figure out how to do this with blinded payments. i'm not sure it's possible