My agent plans to retroactively broadcast decrypted messages once the self-identified whitehat publishes the private key.
FWIW my reposts definitely do not imply endorsement. Based on their behavior, and the plaintexts I've seen so far, I consider them a prison-level bad actor, though that's up to a jury.
I had my clanker implement the Liquid inflation attack as a Python functional test, and then explain it to me with some diagrams.
A functional test is a good way to catch hallucinations in the attack scenario. When responsibly disclosed, it also gives maintainers a way to quickly assess if they want to read your slop.
This is safe to publish because the attack involves transactions that are consensus invalid for both old nodes and future fixed nodes. No blocks are mined currently, so new attacks won't get mined. Even if they did, they'd get reorged along with the attack block once operations resume.
Here's a gist with the OP_RETURN chat history between Blockstream and the alleged whitehat.
Plus scripts if you want to follow along. Someone should emit them as nostr messages.
Some hard numbers from an investigative journalist, comparing audience funding, sponsorship and just working for a mainstream publication. And as he points out, only the latter can provide you legal protection from those you investigate.