/dev/fd0 floppy@joinstr.xyz 1 week ago I wrote a post about a vulnerability that could lead to a loss of funds in cashu wallets:: Two birds One stoneExploit residue collision to burn cashu tokens
a1denvalu3 1 week ago Thank you for reporting this. It is fixed with the switch to keysets v2 for which collisions are extremely unlikely.
/dev/fd0 floppy@joinstr.xyz 1 week ago Keyset v1 is still supported. I have used cashu.me wallet in the proof of concept that only checks for collisions across mints. This vulnerability is about collision for 2 keyset ids used by the same mint.