Damus
calle profile picture
calle
@calle
story time. the recently disclosed nutshell cashu mint vulnerability is as ironic as it gets. it’s very similar to an inscription which is hilarious. as per the cashu spec, a HTLC must have a preimage witness size of 32 bytes.

unfortunately, the mint never checked the size before validating and storing it in its db. we simply overlooked it. since users never paid a fee that depends on the witness size (because we assumed it would be constant), this allowed the attacker to store jpgs of dickbutts in a mints database. for free!

fortunately there’s no messy consensus in cashu. every mint operator dictates their own rules. the fix is simple: now we reject all tokens with a witness that’s too large. those maliciously crafted tokens (of which we haven’t seen any in the wild) can’t be spent anymore.

i must admit, given my recent active engagement in the filter debate, this is probably the funniest exploit possible. i own this one and i’m giggling as i type this. it’s pure comedy.

however, this doesn’t mean the disclosure has gone well. the attacker has proven to be malicious and refused to coordinate with us. instead, he’s putting active mints at risk. this is not how responsible disclosure works. very unprofessional. if you run a mint or know someone who does, update to the latest version (0.18.1) where this issue is fixed. funds were never in danger.

it’s certainly worth a laugh. grill me. this one is simply too good. 😊

thanks to the entire cashu team for their amazing work and their swift reaction. you’ve handled it like pros.
3610❤️13🤙5❤️2🚀21♥️1
arkinox · 26w
staying humble ✅
nostrich · 26w
That is very ironic indeed.
DanWedge · 26w
Thank you for workinganonymously in public
Derek Ross · 26w
it wouldn't be #NutNovember without a few giggles.
falsefaucet · 26w
https://media1.tenor.com/m/jDJkh3w0wTAAAAAC/gregzaj1-ln-strike.gif
Kush · 26w
This is klassik! Respect Kallie
ESE · 26w
“The attacker has proven to be malicious” bruh 🤣🤦‍♂ this cashu thing is a joke.
KELBIE | sovran.money · 26w
I cannot believe I'm seeing so many clowns come out in support of DDoSing
cola · 26w
Stfu, dumb bitch.
So Tachi · 26w
nothing to see here, just an OP_RETURN size limit nostr:nevent1qqs09mnnxq6hzmp539e0s24s664y9auqkcwrys65kzaa209593uurtsa5acgn
ManyKeys · 26w
> i must admit, given my recent active engagement in the filter debate, this is probably the funniest exploit possible. i own this one and i’m giggling as i type this. it’s pure comedy. Seems like it was a retaliation for your active engagement for lifting filters. Junk is junk, no matter where...
allen · 26w
REEEEEE CENSORSHIP STORE MY DICKBUTT YOU FASCIST!
Praveen Perera · 26w
https://blossom.primal.net/e6d253f071bb8d983d9e1013a4468bc2512dac57bf7f3ec269cb0ae5c8fc1291.jpg
Rob Woodgate · 26w
nostr:nprofile1qyxhwumn8ghj7mn0wvhxcmmvqyt8wumn8ghj7un9d3shjt3s0p3ksct59e3k7mgqypadk5sv8trukmwgy56s3hcvu8vhtkjflm76ndwf2e6y5pyayv9vurpw70s 👀 https://blossom.primal.net/bd9e000098945dd3d4ed3ae1b5fe461bfc57932fe44ecd5541e796878d849104.png
nostrich · 26w
Core v30 that came out of the compromised Core devs opened up Bitcoin for more abuse of spam than it was previously possible. It was previously possible because compromised Core devs rejected to fix the inscriptions spam. It is the same, and good that you admit it, that the vulnerability opened Cas...
epsql · 26w
> now we reject all tokens with a witness that’s too large Censorship alert detected
BTC Negotiator · 26w
Those dickbutts meet cashu consensus rules. What are you complaining about?
proofofprice.com · 26w
I honestly don’t know how to feel about this
Flowey · 26w
Is there no solution without filters?
satskew · 26w
life does seem to optimize for irony
Telluride · 26w
Irony lvl 100 https://blossom.primal.net/037ee40f23e8529b41f72a9cfe574cf7193577785afc0b261a305b5beef1d661.jpg
furio · 26w
Schadenfreude is on 11 for me. I’m loving the people exposing Calle for who he is. Couldn’t have happened to a douchier guy.
The Fishcake (nostr.build) · 26w
🤣😂🤣 (pic for reference and for people who are not familiar with the meme) https://i.nostr.build/usKeWur1jWNRoCOf.png
Alex Gleason · 26w
https://media.ditto.pub/63b684cbfebcd1ea9164a5ab2863fe1088f2148440c591c5978c6776289b3d67.png