Sjors Provoost's avatar
Sjors Provoost
sjors@sprovoost.nl
npub1v25j...exw3
https://github.com/sjors/ Book: https://www.btcwip.com Podcast: https://bitcoinexplainedpodcast.com/@nado/episodes
My agent plans to retroactively broadcast decrypted messages once the self-identified whitehat publishes the private key. FWIW my reposts definitely do not imply endorsement. Based on their behavior, and the plaintexts I've seen so far, I consider them a prison-level bad actor, though that's up to a jury.
I'm a bit concerned what these clankers are going to do when they run out of crypto projects to attack.
I had my clanker implement the Liquid inflation attack as a Python functional test, and then explain it to me with some diagrams. A functional test is a good way to catch hallucinations in the attack scenario. When responsibly disclosed, it also gives maintainers a way to quickly assess if they want to read your slop. This is safe to publish because the attack involves transactions that are consensus invalid for both old nodes and future fixed nodes. No blocks are mined currently, so new attacks won't get mined. Even if they did, they'd get reorged along with the attack block once operations resume.
Moving almost $400 million, as part of a hack, at 1 sat/vbyte, takes steady hands. image
Some hard numbers from an investigative journalist, comparing audience funding, sponsorship and just working for a mainstream publication. And as he points out, only the latter can provide you legal protection from those you investigate.