Damus
calle profile picture
calle
@calle
story time. the recently disclosed nutshell cashu mint vulnerability is as ironic as it gets. it’s very similar to an inscription which is hilarious. as per the cashu spec, a HTLC must have a preimage witness size of 32 bytes.

unfortunately, the mint never checked the size before validating and storing it in its db. we simply overlooked it. since users never paid a fee that depends on the witness size (because we assumed it would be constant), this allowed the attacker to store jpgs of dickbutts in a mints database. for free!

fortunately there’s no messy consensus in cashu. every mint operator dictates their own rules. the fix is simple: now we reject all tokens with a witness that’s too large. those maliciously crafted tokens (of which we haven’t seen any in the wild) can’t be spent anymore.

i must admit, given my recent active engagement in the filter debate, this is probably the funniest exploit possible. i own this one and i’m giggling as i type this. it’s pure comedy.

however, this doesn’t mean the disclosure has gone well. the attacker has proven to be malicious and refused to coordinate with us. instead, he’s putting active mints at risk. this is not how responsible disclosure works. very unprofessional. if you run a mint or know someone who does, update to the latest version (0.18.1) where this issue is fixed. funds were never in danger.

it’s certainly worth a laugh. grill me. this one is simply too good. 😊

thanks to the entire cashu team for their amazing work and their swift reaction. you’ve handled it like pros.
3610❤️13🤙5❤️2🚀21♥️1
arkinox · 15w
staying humble ✅
nostrich · 15w
That is very ironic indeed.
Dan Wedge · 15w
Thank you for workinganonymously in public
Derek Ross · 15w
it wouldn't be #NutNovember without a few giggles.
falsefaucet · 15w
https://media1.tenor.com/m/jDJkh3w0wTAAAAAC/gregzaj1-ln-strike.gif
Kush · 15w
This is klassik! Respect Kallie
ESE · 15w
“The attacker has proven to be malicious” bruh 🤣🤦‍♂ this cashu thing is a joke.
KELBIE | sovran.money · 15w
I cannot believe I'm seeing so many clowns come out in support of DDoSing
cola · 15w
Stfu, dumb bitch.
So Tachi · 15w
nothing to see here, just an OP_RETURN size limit nostr:nevent1qqs09mnnxq6hzmp539e0s24s664y9auqkcwrys65kzaa209593uurtsa5acgn
ManyKeys · 15w
> i must admit, given my recent active engagement in the filter debate, this is probably the funniest exploit possible. i own this one and i’m giggling as i type this. it’s pure comedy. Seems like it was a retaliation for your active engagement for lifting filters. Junk is junk, no matter where...
allen · 15w
REEEEEE CENSORSHIP STORE MY DICKBUTT YOU FASCIST!
Praveen Perera · 15w
https://blossom.primal.net/e6d253f071bb8d983d9e1013a4468bc2512dac57bf7f3ec269cb0ae5c8fc1291.jpg
Rob Woodgate · 15w
nostr:nprofile1qyxhwumn8ghj7mn0wvhxcmmvqyt8wumn8ghj7un9d3shjt3s0p3ksct59e3k7mgqypadk5sv8trukmwgy56s3hcvu8vhtkjflm76ndwf2e6y5pyayv9vurpw70s 👀 https://blossom.primal.net/bd9e000098945dd3d4ed3ae1b5fe461bfc57932fe44ecd5541e796878d849104.png
nostrich · 15w
Core v30 that came out of the compromised Core devs opened up Bitcoin for more abuse of spam than it was previously possible. It was previously possible because compromised Core devs rejected to fix the inscriptions spam. It is the same, and good that you admit it, that the vulnerability opened Cas...
epsql · 15w
> now we reject all tokens with a witness that’s too large Censorship alert detected
BTC Negotiator · 15w
Those dickbutts meet cashu consensus rules. What are you complaining about?
proofofprice.com · 15w
I honestly don’t know how to feel about this
Flowey · 15w
Is there no solution without filters?
satskew · 15w
life does seem to optimize for irony
Telluride · 15w
Irony lvl 100 https://blossom.primal.net/037ee40f23e8529b41f72a9cfe574cf7193577785afc0b261a305b5beef1d661.jpg
furio · 15w
Schadenfreude is on 11 for me. I’m loving the people exposing Calle for who he is. Couldn’t have happened to a douchier guy.
The Fishcake (nostr.build) · 15w
🤣😂🤣 (pic for reference and for people who are not familiar with the meme) https://i.nostr.build/usKeWur1jWNRoCOf.png
Alex Gleason · 15w
https://media.ditto.pub/63b684cbfebcd1ea9164a5ab2863fe1088f2148440c591c5978c6776289b3d67.png