Post by Dangerous Mammal
We're still investigating what happened here. It seems a handful of accounts may have been compromised and had their autowithdrawal settings tampered with, including our own "coinos@coinos.io" account. We ran a script to search for accounts that had the attacker's "speed.app" withdrawal address in place and found about 9 that seem to have been affected. There could be more though, we will update as we have more information. I worry that this may be the same attacker who exploited a password reset vulnerability back in January which allowed them to gain access to a number of accounts. It's possible that since that time they have been sitting on the account data and working to brute force the encrypted nostr private keys that we had on file for some accounts that had imported their nostr key into Coinos. Those keys were encrypted at rest in our database but it's possible they may have been cracked. We no longer store nostr private keys for accounts and have since added support for external signing apps and browser extension login, but there was a time when we were storing encrypted nsec private keys. Having a users nsec would allow an attacker to authenticate into Coinos by signing a nostr event and change the user settings. It also means your entire nostr profile and identity may be compromised. This is only a hypothesis at this point and we need to investigate further but we may end up recommending that affected users rotate their nostr keys.
PSA: An autowithdraw exploit for coinos1231 has been confirmed. Check your settings if you’re using this wallet. Felt bad for not giving them more time to respond privately, but hopefully this saves some of your sats.
⚡ 50Simply Nostr“🚨New ep. Just dropped🚨simply Nostr 💟”
⚡ 2₿oniz23⚡️🏴‍☠️🇮🇹“Great post 👍”
Np I’ll just rotate my keys…. Wait a minute
like, inside out or?
I’m just bouncing off the elliptic curve here I’m still inside
Just use your next bip85 index...oh wait...
Think he means create new Nostr keys entirely ? 🤔
We have disabled all auto-withdrawals for the time being until we get a better handle on the situation.
Unable to zap.... No lightening wallet found.
There is no such thing as rotating Nostr keys
That is a business professional way of saying, ‘you’re fucked’
💯 Once your key is compromised it's over. New game plus 😬😅
New game plus lmaoooo I cant not zap that
I didn't want to know this,😔
TKay tried flipping, it was not effective!
Wow. I hope I never did something stupid with my nsec. But we really need to find a way to stop this single point of failure.
I hope everybody learns a valuable lesson about third parties
node heads up, not sure if you're still using coinos but nsec may be compromised
Thanks Cuban. Saw that. Never used the forwarding feature. But I emptied the wallet and switched to primal NWC just in case.
Might be worth checking for this address too.
Good luck with the investigation. Here’s to coming out stronger from this. 👊
😳😳😳👀🤦‍♂️