Replies (2)

a1denvalu3's avatar
a1denvalu3 1 week ago
Thank you for reporting this. It is fixed with the switch to keysets v2 for which collisions are extremely unlikely.
Keyset v1 is still supported. I have used cashu.me wallet in the proof of concept that only checks for collisions across mints. This vulnerability is about collision for 2 keyset ids used by the same mint.