I had something very odd happen to me this morning and I don't know what to make of it just yet. My Lightning Address was different on some clients. To me on Snort, it still showed as pay@derekross.me, but that could have been cache. On Damus, Astral, and metadata.nostr.com it was an LNURL address that resolved to LNBits.com. I don't use LNBits.com.

This morning I used a new client, Ananostr.com by #[0] right around that time that I noticed the change. However, I used the nos2x extension as I always do.

I mostly only use Snort and Astral on my desktop, though I have used iris.to a few times.

On my phone, I use Amethyst, but I've also used Daisy with my private key. All of the other Android clients I tested were used with a burner key.

Hrm. I am very, very confused right now.

Reply to this note

Please Login to reply.

Discussion

Do any of the clients you’ve tried create a default wallet for you if you don’t set one up yourself? Anigma did that when I tried it and it used LNbits. If some client did that it could have populated to other clients? Just thinking out loud.

But then, again, if you logged in with your private key, I would think your existing wall it would’ve been there already, so maybe not

I never used Anigma with this key. I guess it's possible for a client to do this and overwrite my wallet. But it would have have to have been once of the ones I used this morning. Which would have been Snort, Ananostr, or Amethyst.

Or could something have gotten changed with forwarding when you switched your nip-05?

The address itself was changed on my nostr profile.

I’m very curious … it certainly raises questions and concerns.

That's not a good look for ananostr, I'd be very wary of using that now.

I don't know if it was that clients fault and I don't want to point any fingers. All I know is that I logged into it this morning. Then an hour later I noticed this issue because someone DMed me to say they sent me a large tip. I said oh, I didn't get it and started to investigate.

Time to break out that new POW key. Though i guess if you don't know if or how the key was comprosed might not help or could happen agian.

I am wondering if a client did something it shouldn't have done. I'll give them benefit of the doubt for now and think maybe it was an accident that they had this happen, testing something and hopefully forgot to remove it from a dev environment before going to prod.

Today I decided our friend #[0] could use some sats to go to Nostrica and I like random numbers, especially if they add up. So I sent him 324756 sats by zapping him, using the ⚡️ button on his profile. Might be he could pay a round of drinks with it, so I added that to the invoice. Then I told him about it through a message to see if he got it. Which he didn't. Now we are both unsure what actually happened, the invoice was paid but the wallet isn't his.

I figured let's just ask him for a 324765 sat invoice and consider the initial amount lost, so I paid him again. Lightning is unforgiving, and yes 'not your keys, not your coins'.

Next time I zap someone, I'm asking for an invoice first. Mystery, unsolved.

#[1]

I hope Derek gets to the bottom of this mystery.

It would be cool if he ended up with recovering it, two rounds of drinks is better than one round of drinks.

Absolutely 😀🍻

Frustrating.

I've been scraping metadata as an experiment, here's what my cache shows for you.. Is that lud06 correct or naw?

pubkey_hex: 3f770d65d3a764a9c5cb503ae123e62ec7598ad035d836e2a810f3877a745b24

name: DerekRoss

about: Bitcoin HODLer, home miner, and node runner. #Bitcoin only. Systems Administrator. NostrPlebs.com

nip05: derekross@nostrplebs.com

lud06: lnurl1dp68gurn8ghj7er9wfjkkun0wdejumt99uh8wetvdskkkmn0wahz7mrww4excup0wpshjts2xl3

lud16: pay@derekross.me

website: nostrplebs.com

display_name:

picture: https://void.cat/d/6hntYKdfbzfR13GpQcHWNH

updated_at: 2023-01-27 21:47:18.235

It points to https://derekross.me/.well-known/lnurlp/pay which is identical to your lightning address

yes, that is the correct lud06.

do you have the old event?

do you ever use the sign for 5 min option on nos2x?

Yes on your site and on snort.

have you found the event with the wrong lud06?

i would love to find it. i was looking on nostr.guru but i don't see a lot of my events there. this change would have happened most likely 6-8 hours ago?

gahh persistent db would be so useful for this...

someone must have a copy somewhere.?

if this happens to you again you should use astral sql query to grab the kind 0 event

How would I do that?

settings > dev tools, choose sql query and use this search:

SELECT n.event FROM nostr_events e

left join nostr n on e.id = n.id

where kind = 0

and pubkey = '3f770d65d3a764a9c5cb503ae123e62ec7598ad035d836e2a810f3877a745b24';

Any issues with the 5 min sign?

it will allow client to arbitrarily sign events as you for 5 min

I think some clients overwrite bio info. I am very careful to check out new clients on a completely different browser and do not enter my keys. I look first and look well before I even consider using my keys.

I’ve had to many overwrites of my following to be willy nilly about it.

Yes, it took me almost a day to figure out something overwrote everything to be blank

Looks like you have the right metadata on your profile

```

{"id":"14b02dce8aa5257fd519d156b220c90ebe6b795e3e41d09ec72144c8a5bb45b4","kind":0,"pubkey":"3f770d65d3a764a9c5cb503ae123e62ec7598ad035d836e2a810f3877a745b24","created_at":1674860601,"content":"{\"name\":\"DerekRoss\",\"about\":\"Bitcoin HODLer, home miner, and node runner. #Bitcoin only. Systems Administrator. NostrPlebs.com\",\"nip05\":\"derekross@nostrplebs.com\",\"lud06\":\"lnurl1dp68gurn8ghj7er9wfjkkun0wdejumt99uh8wetvdskkkmn0wahz7mrww4excup0wpshjts2xl3\",\"display_name\":\"Derek Ross\",\"picture\":\"https://void.cat/d/6hntYKdfbzfR13GpQcHWNH\",\"banner\":\"https://void.cat/d/SSQfvee6s8wqfKPfcRLKqu\",\"website\":\"nostrplebs.com\",\"lud16\":\"pay@derekross.me\"}","tags":[],"sig":"764a941d372bee4398a28c470d4ba8e72f893bc806e9fd0a9393c969538e413254e4543262c31580e9c93b694844385fb7c56425ca27c64cadc710a54e91900a","first_seen":1674861881,"last_updated":1674861881,"seen_on":["wss://nostr-pub.semisol.dev","wss://relay.nostr.info","wss://nostr.zebedee.cloud"]}

```

The LNURL is `lnurl1dp68gurn8ghj7er9wfjkkun0wdejumt99uh8wetvdskkkmn0wahz7mrww4excup0wpshjts2xl3` which [decodes](https://lightningdecoder.com/lnurl1dp68gurn8ghj7er9wfjkkun0wdejumt99uh8wetvdskkkmn0wahz7mrww4excup0wpshjts2xl3) to `pay@pay.derekross.me`

I do now, but I'd like to know when this changed this morning and why.

All of what you said here is like a foreign language to me. What I got out of it is…someone who is very knowledgeable has noticed something strange about their accounts. This very knowledgeable person is unsure how this strange thing has happened.

That's sad, but your key has probably been stolen. I see 34 published event where your LN address was changed to lnbits. The last one was this:

relay 'wss://relay.nostr.ch' event '["EVENT","1",{"id":"1a4d5ffe81826555a5540024aeefc2b37c90745791177654c28a81bbaf084ebd","pubkey":"3f770d65d3a764a9c5cb503ae123e62ec7598ad035d836e2a810f3877a745b24","created_at":1674828562,"kind":0,"tags":[],"content":"{\"npub\":\"npub18ams6ewn5aj2n3wt2qawzglx9mr4nzksxhvrdc4gzrecw7n5tvjqctp424\",\"name\":\"DerekRoss\",\"about\":\"Bitcoin HODLer, home miner, and node runner. #Bitcoin only. Systems Administrator. NostrPlebs.com\",\"picture\":\"https://void.cat/d/ED5XcQYebiqrgqQFtDM3Xd\",\"nip05\":\"derekross@nostrplebs.com\",\"lud06\":\"LNURL1DP68GURN8GHJ7MR9VAJKUEPWD3HXY6T5WVHXXMMD9AKXUATJD3CZ76ZZGA65VDSHC6WKV\",\"lud16\":\"pay@derekross.me\",\"display_name\":\"Derek Ross\",\"website\":\"NostrPlebs.com\",\"banner\":\"https://void.cat/d/J9c2jiSocXbhTnZ6b2bCy9\"}","sig":"6ea16014c3e5b503fd9ded1a3c3304cb313bfce1fc125888e703012d8194f0847a3439d73225deb015170ff39d29bf61c5d71e32cff05ec398103e31ccd768ac"}]'

Added edit history for profiles, here is yours: https://nostr.band/npub18ams6ewn5aj2n3wt2qawzglx9mr4nzksxhvrdc4gzrecw7n5tvjqctp424?edits

To get there, find your profile in search, open your profile, click on dropdown menu button near your name, click 'View edit history'