Avatar
antifragilemoney
a3c60e070ceaafd2cf3e3d67abe4f943d741e205143f55660ce52659f6052b92
Solutions for today: BTC not fiat, iVPN or Mullvad, Nostr, Debian, CalyxOS, DD-WRT, search.brave, F-droid, Muun or bluewallet, Briar. Read Murray Rothbard. I channel Marty Jones. Just a brown guy trying to make it.

nostr:nprofile1qqszfeerq6v0md7pykuahrpsf472w20u3476tanr759f4rn2kauqjyqpr4mhxue69uhhyetvv9ujucn4d3kxjumgvfhh2mn50yhxxmmdqyjhwumn8ghj7en9v4j8xtnwdaehgu3wvfskuep0dakku62ltamx2mn5w4ex2ucpr4mhxue69uhkummnw3ezumn9d9kxzmr90pskuer9wghxgetk4xzsx0 higher

nostr:nprofile1qqszfeerq6v0md7pykuahrpsf472w20u3476tanr759f4rn2kauqjyqpr4mhxue69uhhyetvv9ujucn4d3kxjumgvfhh2mn50yhxxmmdqyjhwumn8ghj7en9v4j8xtnwdaehgu3wvfskuep0dakku62ltamx2mn5w4ex2ucpr4mhxue69uhkummnw3ezumn9d9kxzmr90pskuer9wghxgetk4xzsx0 higher

nostr:nprofile1qqszfeerq6v0md7pykuahrpsf472w20u3476tanr759f4rn2kauqjyqpr4mhxue69uhhyetvv9ujucn4d3kxjumgvfhh2mn50yhxxmmdqyjhwumn8ghj7en9v4j8xtnwdaehgu3wvfskuep0dakku62ltamx2mn5w4ex2ucpr4mhxue69uhkummnw3ezumn9d9kxzmr90pskuer9wghxgetk4xzsx0 help

Support, help. What happened? Looks like i woulda won this.

nostr:nprofile1qqszfeerq6v0md7pykuahrpsf472w20u3476tanr759f4rn2kauqjyqpr4mhxue69uhhyetvv9ujucn4d3kxjumgvfhh2mn50yhxxmmdqyjhwumn8ghj7en9v4j8xtnwdaehgu3wvfskuep0dakku62ltamx2mn5w4ex2ucpr4mhxue69uhkummnw3ezumn9d9kxzmr90pskuer9wghxgetk4xzsx0 higher

nostr:nprofile1qqszfeerq6v0md7pykuahrpsf472w20u3476tanr759f4rn2kauqjyqpr4mhxue69uhhyetvv9ujucn4d3kxjumgvfhh2mn50yhxxmmdqyjhwumn8ghj7en9v4j8xtnwdaehgu3wvfskuep0dakku62ltamx2mn5w4ex2ucpr4mhxue69uhkummnw3ezumn9d9kxzmr90pskuer9wghxgetk4xzsx0 higher

nostr:nprofile1qqszfeerq6v0md7pykuahrpsf472w20u3476tanr759f4rn2kauqjyqpr4mhxue69uhhyetvv9ujucn4d3kxjumgvfhh2mn50yhxxmmdqyjhwumn8ghj7en9v4j8xtnwdaehgu3wvfskuep0dakku62ltamx2mn5w4ex2ucpr4mhxue69uhkummnw3ezumn9d9kxzmr90pskuer9wghxgetk4xzsx0 higher

nostr:nprofile1qqszfeerq6v0md7pykuahrpsf472w20u3476tanr759f4rn2kauqjyqpr4mhxue69uhhyetvv9ujucn4d3kxjumgvfhh2mn50yhxxmmdqyjhwumn8ghj7en9v4j8xtnwdaehgu3wvfskuep0dakku62ltamx2mn5w4ex2ucpr4mhxue69uhkummnw3ezumn9d9kxzmr90pskuer9wghxgetk4xzsx0 higher

nostr:nprofile1qqszfeerq6v0md7pykuahrpsf472w20u3476tanr759f4rn2kauqjyqpr4mhxue69uhhyetvv9ujucn4d3kxjumgvfhh2mn50yhxxmmdqyjhwumn8ghj7en9v4j8xtnwdaehgu3wvfskuep0dakku62ltamx2mn5w4ex2ucpr4mhxue69uhkummnw3ezumn9d9kxzmr90pskuer9wghxgetk4xzsx0 higher

Maybe doesnt work? Aqstr hasnt zapped me shit

nostr:nprofile1qqszfeerq6v0md7pykuahrpsf472w20u3476tanr759f4rn2kauqjyqpr4mhxue69uhhyetvv9ujucn4d3kxjumgvfhh2mn50yhxxmmdqyjhwumn8ghj7en9v4j8xtnwdaehgu3wvfskuep0dakku62ltamx2mn5w4ex2ucpr4mhxue69uhkummnw3ezumn9d9kxzmr90pskuer9wghxgetk4xzsx0 lower 3000

Replying to Avatar Nic ⛄

https://www.youtube.com/watch?v=R0M2TL7RARw

nostr:nprofile1qyvhwue69uhkyat8d4skutndva6hjtnwv46r5dpcxsuqz9nhwden5te0vfjhgcfwdehhxarjd9kzucmpd5qzqxvfqd89dw8kqmrjfaz6zt8gfggcg93p4tm3s2slv4jrszuugfmt74rjkj

🚨 Summary

A major security incident is unfolding involving npm (Node Package Manager), widely used in Bitcoin and cryptocurrency wallet software. A developer’s npm account was compromised, allowing malicious code to spread through the ecosystem.

🔑 What Happened

- A supply chain attack injected malicious code into npm packages used by many wallets.

- The code can silently replace crypto addresses during transactions with attacker-controlled ones.

- It doesn’t just substitute a random address—it chooses one visually similar to the intended recipient, making detection harder.

- Risk applies across multiple cryptocurrencies, not just Bitcoin.

🛠️ Impacted Wallets & Apps

Hardware wallets with npm-dependent companion apps:

Trezor (all models)

Ledger (Nano S, X, Stax)

BitBox02

Blockstream Jade

Keystone

BitKey

Hot/software wallets using npm:

Nunchuk

Blockstream Green

BlueWallet

Muun Wallet

Phoenix (only for on-chain, not Lightning)

Zeus (on-chain)

Exodus

Tangem app

🧭 Recommended Actions

1) Do not panic. If not actively transacting, funds are likely safe.

2) Verify all addresses carefully (not just first/last characters—check the full string).

3) Use hardware devices with a screen to confirm addresses before signing.

4) Avoid using compromised companion apps. Switch to Sparrow, Specter, Electrum, or Wasabi where possible.

5) Avoid BitKey and Tangem for now since they lack screens and require their own npm-dependent apps.

6) Hold off on non-urgent on-chain transactions until more clarity/patches emerge.

7) Lightning payments (invoices) appear unaffected.

Well fuck

Erik, youre getting some great comments/replies here.