In a nutshell, from the victim LN address, we can easily find its Spark on-chain address throught LNURL "well-known" URL, for example:
https://walletofsatoshi.com/.well-known/lnurlp/warmestfuture710
From here, we can browse all the address details on a blockchain explorer like:
https://www.sparkscan.io/address/spark1pgss9gqjlk5emnuwg9dvxdh76r70ny2nmumhnzlth6q4zr0hych72gerqux6vp?network=mainnet
Conclusion: Everything is public... 🤬
cc @BTC Sessions @Louferlou
Login to reply
Replies (3)
Wild! Thanks for sharing this.


Not only public -- but Lightspark has the IP address and user-agent of this user, which they can granularly associate with each transaction. Crazy.
Is it safe to say that all Spark-enabled wallets have this issue? What are the others?