Avatar
EVAN KALOUDIS
2d9873b25bf2dda6141684d44d5eb76af59f167788a58e363ab1671fefee87f2
Eleutheromaniacal key puncher. Founder, ZEUS

Really excited for some of the next gen stuff we've been talking about internally this week. Even cheaper self-custodial onboarding, later this year

The nostr:npub1xnf02f60r9v0e5kty33a404dm79zr7z2eepyrk5gsq3m7pwvsz2sazlpr5 LSP had another record month in January, and by a great margin.

Lightning is taking off and Bitcoin is scaling in layers.

MEMPOOL CLEARED. 1 SAT/VBYTE GANG WE RIDE FOREVER.

Hi folks we've been experiencing some disruptions over the past couple days as we've been working to mitigate against an attacker who found and exploited a vulnerability in our system that allowed them to get password reset codes for accounts that didn't belong to them.

Using this exploit they were able to gain access to a number of accounts that they shouldn't have had access to and withdraw funds.

We've patched the issue and believe we've revoked the attacker's access to the compromised accounts by invalidating their JWT authentication tokens and NWC secrets.

We've instituted system-wide withdrawal limits as a precautionary measure while we work to fully restore and migrate the payment records of affected accounts.

If you are seeing a blank screen when you visit the Coinos site, you may need to visit https://coinos.io/logout or clear your browser cache. If you have Coinos installed as a PWA you may need to uninstall it and re-add it to your homescreen.

About 80 accounts had their passwords reset by the attacker but only a handful were actively stolen from. If your account was compromised you may be missing some recent transactions. We do have backups and will be writing scripts to find and restore those payment records over the coming days.

If you were using Coinos via NWC your NWC connection string secret may have changed in which case you will need to re-connect Coinos to your Nostr apps.

We'll be reverting unsolicited withdrawals and covering all losses ourselves to make all our users whole. Thankfully we caught the attack relatively quickly and managed to take corrective action before the attacker had time to fully drain our wallets.

Coinos is essentially a volunteer effort and one-man show on the tech front so please be patient as it's going to take me a few days to restore everything back to normal.

This incident has not shaken my resolve, only strengthened it.

Sincerely,

Adam Soltys

Hope you can provide a post incident report once the dust is settled.

Wishing you the best.

He’s gonna be a force.

Little man started dribbling today. Amazing. ⚽️

Keep doing scary things. nostr:note1v9pqar0ef0zj3rph3u4kezk0r3zzswz0kxqrmmz8rl0n8k049r8sqjp9q2

This is definitely worse UX than what we have rn.

Don’t give up now, just a little more persistence

You can just do things.

You can abolish the income tax and IRS, and then abolish the Federal Reserve.

The KYC apparatus must be destroyed. nostr:note1yepwyjvqd5gnfj9xpdkr6dc0d3ag8dfmuj8djvtezx8lwnatvdrqauevtt