Damus
adam profile picture
adam
@adam
Hi folks we've been experiencing some disruptions over the past couple days as we've been working to mitigate against an attacker who found and exploited a vulnerability in our system that allowed them to get password reset codes for accounts that didn't belong to them.

Using this exploit they were able to gain access to a number of accounts that they shouldn't have had access to and withdraw funds.

We've patched the issue and believe we've revoked the attacker's access to the compromised accounts by invalidating their JWT authentication tokens and NWC secrets.

We've instituted system-wide withdrawal limits as a precautionary measure while we work to fully restore and migrate the payment records of affected accounts.

If you are seeing a blank screen when you visit the Coinos site, you may need to visit https://coinos.io/logout or clear your browser cache. If you have Coinos installed as a PWA you may need to uninstall it and re-add it to your homescreen.

About 80 accounts had their passwords reset by the attacker but only a handful were actively stolen from. If your account was compromised you may be missing some recent transactions. We do have backups and will be writing scripts to find and restore those payment records over the coming days.

If you were using Coinos via NWC your NWC connection string secret may have changed in which case you will need to re-connect Coinos to your Nostr apps.

We'll be reverting unsolicited withdrawals and covering all losses ourselves to make all our users whole. Thankfully we caught the attack relatively quickly and managed to take corrective action before the attacker had time to fully drain our wallets.

Coinos is essentially a volunteer effort and one-man show on the tech front so please be patient as it's going to take me a few days to restore everything back to normal.

This incident has not shaken my resolve, only strengthened it.

Sincerely,
Adam Soltys
6844❤️60🤙19❤️9👀5🫂5👍4
VENATOR · 56w
Parabéns. "Na guerra é que se forja o verdadeiro caráter". Avante!
TJ.III · 56w
ALL CLASS ADAM. THANK YOU FOR BEING SO VIGILANT.
Sandor Clegane · 56w
🤔 I can't remember the last time a hunk of metal was hacked...
thePR0M3TH3AN ✝️ BIP110 · 56w
Just zaped you with nostr:nprofile1qqst4qyeqenw7zm0fwjsty68h6cnys5jre2xd8ngqpjv5a2j26s78fspzemhxue69uhhyetvv9ujucm0d9hx7uewd9hj75a0pev 🙏
Kevin's Bacon · 56w
Thank you!! You're doing a tremendous service. I'm patient. I know this stuff can happen, I signed up for it with full knowledge of the tradeoffs in security vs full self custody. These things happen.
nobody · 56w
Damn it. I was one of the 80 accounts. 5k sats gone. Thank god I look at lightning as the medium of exchange and not the store of value. Sucks though.
ForrestHODL · 56w
will the transactions be automatically re-added? my history of transactions are gone
EVAN KALOUDIS · 56w
Hope you can provide a post incident report once the dust is settled. Wishing you the best.
FunkCoffee · 56w
Cheers to the transparency, and thank you for the work that you do. To those who don’t know, Coinos does have a self custody option to be able to pull down your sats on-chain which should be resistant to these kind of attack.
398ja · 56w
I cannot access my account. https://i.nostr.build/kxq85mf7lsaRwKvv.jpg
Rey · 56w
great
chrizzz · 56w
I need to send a larger amount of sats to buy a plane ticket.. wen? Pretty please 🥹
Danneskjold · 55w
I just notice that. I was affected. I tried clear the browser cache clearing solution and It didn't work.
The Bullish ₿itcoiner · 55w
Hey nostr:npub12ekpvme6m2cv37a9mgq4kzemej8tx6ttg40j582rh77ewpvkg65qj8tq0f, any update on the status of withdrawals? I just tried this GM without success.
Bohemia · 55w
nostr:nprofile1qqsrhrkznzltm0y7hr2arql9errve5g5g5xlmyk79j6k77hezadm77cpr9mhxue69uhhqatjv9mxjerp9ehx7um5wghxcctwvsq3jamnwvaz7tmnv4hxg6t59ehx7umxd3shyefwvdhk6qg5waehxw309ahx7um5wghx77r5wghxgetkp9v9j4 don't know if you saw this
Qas · 55w
Sorry to hear this, I’m a penetration tester and happy to work with you to validate that the fix you’ve implemented has worked?
Tim Bouma · 54w
Totally appreciate the transparency.
anadolufinancel · 29w
We are looking for an investor who can loan our holding company 237,000 US dollars. With this money, we will open a farm in Baku, Azerbaijan to produce animal-based food. We will also make our own animal feed, so our products will be healthier, better quality, and cheaper. Because we sell quality...