Tough day. Chain Duel’s Bitcoin infrastructure got hacked.
The attacker used Boltz to drain all Lightning funds and emptied the on-chain wallet to a coinjoin.
Probably our fault for exposing Umbrel on clearnet, but it still hurts.
Learning the hard way. Don’t make the same mistake.
Login to reply
Replies (26)
Oof
Damn. I'm sorry that happened.
Lost forever
Funds were lost, lessons were learned.
nostr:nevent1qvzqqqqqqypzqhf6hpmvyp4r0tfmp98zp07rjswl873p59dv36nk66gcgumcje56qqsqyd4lx7sqhe6zxzmrn3pqa9vm2q0s4z59g874smymkvx0862g6as0kamfe
You should make a full post about this incident, more detailed.
As a lesson for others.
Maybe use SN https://stacker.news for that?
it hits hard
we might, still trying to figure out what happened ..
That's terrible. How did this happen?
stand firm
thank you we will
still trying to figure out what was the access point
sorry to hear that, sucks. you’ll recover.
thank you, it's hard to wake up a see this but hopefully we'll come back stronger
Damn.
Very understandable! I hope you can learn more and share. Hate to hear it's happened.
right after releasing the new pubpay nip05 service :(
Bummer. Thanks for being the man in the arena, the doer of deeds who dares to try! I don’t know a thing about Chain Duel yet appreciate your work.
Thank you for your support 🙏
So sorry to hear that. How was Umbrel exposed on clearnet?
I cringe when ppl ask for advise, support their key management etc.. Actually building infra for others... The pressure and pain from breaches, I cannot fathom. Hope future days are mainly brighter
I’m so sorry to read this 🥺🫂
Painful lesson 🥺 Sorry to hear, but sure "it happened for a good cause," for example, letting you secure the system for the future.
Sucks man. Sorry to hear this.
thank you man 🙏 it really does suck
Brutal. If Umbrel was on clearnet, assume full compromise: isolate the box, rotate LND macaroons and TLS, sweep any residual on chain to fresh descriptors, and rebuild clean. For the relaunch, at Masters of The Lair we favor Tor only, RPC bound to localhost, admin behind WireGuard, default deny firewall, alerts and daily caps on swap volume, and a tiny hot wallet with policy guardrails. Any IOCs or which creds were taken you can share to help others?
🫂