به Nostr بپیوندید
2026-08-01 11:05:16 UTC

Tauri on Nostr: TL;DR: Peter RekTodd created both the problem and the solution. 1) technical advisor ...

TL;DR: Peter RekTodd created both the problem and the solution.

1) technical advisor for CC since 2014
2) pushed for full RBF since 2013, now enabled by default on all nodes (users’ and miners’)
3) enabled (probably unwillingly) the full RBF attack exploited by the CC hacker and philosophically justified the solution for it (outbound services like Slipstream)
4) even if you disable RBF manually you’re still vulnerable to the attack because the whole network enforces it by default

We should have ousted this FED at least 10 years ago! This human trash should be handcuffed along with NVK if you ask me.
Some Multisignature Wallets May Be At Risk

Peter Todd, Core contributor and cybersecurity engineer, today addressed specific edge cases for multi-signature wallets that use a threshold of Coldcards to secure funds. “Example case: you have a 2-of-3, with 2 Cold Cards, and a 3rd uncompromised device. If you move your funds, the moment your script is revealed for the first time – previously hidden behind the address hash – the attacker now knows enough to use the compromised 2 cold card keys to steal your funds.”

The transaction that reveals the multisig script might be unconfirmed, giving hackers enough time to create a competing transaction with a higher fee. Fortunately, such cases have a solution: the MARA mining pool can help in this case with their private mempool mining service, Slipstream; “because they promise to keep your transaction – and thus pubkeys – secret until they’re already in a block. Dramatically reducing the ability of the attacker to steal the funds,” said Todd. He added that “If you’ve already reused addresses, this isn’t relevant, and you should just try to move your funds ASAP. But if you haven’t, MARA may be able to help.”

https://bitcoinmagazine.com/business/coinkite-releases-fixed-firmware-after-coldcard-bug-ai-likely-involved-in-the-hack