These security incidents highlight the problems with code review and bug bounties, although it would become a debate about confidential transactions.
/dev/fd0
floppy@joinstr.xyz
npub1v6qj...nzyr
Root Cause Analysis of the security incident done by Kimi K3:
View quoted note →

Gist
kimi_report_liquid_hack.md
GitHub Gist: instantly share code, notes, and snippets.

Trust me bro: 

Trust me bro
OHTTP Collusion | Mailbox Squatting
My next post is about OHTTP and its usage in payjoin (most overhyped privacy tool)
Spoiler:
- Relay and directory collusion breaks privacy
- Payjoin cannot be used with untrusted senders or colluding servers


HALL OF FAME PAGE FOR JOINSTR
Find all the vulnerabilities and read the scope before reporting it. I cannot pay but all the names will be added on the "hall of fame" page for joinstr.
Link:
hof
Researchers who reported vulnerabilities in the joinstr Electrum plugin


Bitkey
Security Updates


The old website has been moved to old.joinstr.xyz and a new minimalist dark-mode website is live at joinstr.xyz.
Joinstr now has a community forum at forum.joinstr.xyz that uses Nostr and Squalk. The old SimpleX chat is dead.


Electrum plugin (joinstr) v0.4.1:
- Several bug fixes
- Added more tests

GitLab
plugin/zip/v0.4.1 · main · Invincible Privacy / py-joinstr · GitLab
Python implementation for joinstr
The next wave of AI-assisted attacks won't be about discovering bugs but about subtly introducing vulnerabilities into code that pass review unnoticed.
The easiest way to contribute to finding bugs without using too many AI tokens:
- Find projects with multiple implementations or libs
- Prepare a fuzzing harness for differential fuzzing
- Run the fuzzer
- Report the findings
