Tim Bouma on Nostr: My bet this attack was weeks in the making. Once the attackers assembled enough ...
My bet this attack was weeks in the making. Once the attackers assembled enough private keys for high value utxos they executed.
My biggest disappointment is relying on a hardware vendor that has 'Don't Trust. Verify.' plastered all over their product marketing and the primary motivation that led to the bug was a 'get out of open source' licensing issue.
Let this be a lesson for all in the industry.
'Not your keys, not your coins' rings a bit hollow now.
It's more like: 'God plays dice for those who self-custody.'
Published at
2026-07-31 16:02:03 UTCEvent JSON
{
"id": "35ad182350dff12ca32ae163877b118a664262399955e9ff7351c190de47e3d1",
"pubkey": "06b7819d7f1c7f5472118266ed7bca8785dceae09e36ea3a4af665c6d1d8327c",
"created_at": 1785513723,
"kind": 1,
"tags": [
[
"alt",
"A short note: My bet this attack was weeks in the making. Once t..."
],
[
"client",
"Amethyst"
]
],
"content": "My bet this attack was weeks in the making. Once the attackers assembled enough private keys for high value utxos they executed.\n\nMy biggest disappointment is relying on a hardware vendor that has 'Don't Trust. Verify.' plastered all over their product marketing and the primary motivation that led to the bug was a 'get out of open source' licensing issue.\n\nLet this be a lesson for all in the industry.\n\n'Not your keys, not your coins' rings a bit hollow now.\n\nIt's more like: 'God plays dice for those who self-custody.'",
"sig": "9fddc11513d5ac24c19cdc766c500e52b28710db86686ee64f687c0570f601b4c65dbbbeea836ceb6b95f70338dc96a73f85ff6fcf6772b0c416f58ef5d437de"
}