I might have compromised this nsec. At least, probably exposed.
I don’t expect someone to try and abuse my account, if the key is ever even seen by anyone, but just for good measure, I’m delegating my “Boston ninja” profile below as a backup.
If I post from there and say that my primary account is done, then trust it. Please toss that account a follow, if you don’t mind 🙏
Careful with that copy/paste, kids…
Some hashtags and I’ll bookmark this note to make it easier to find if I need it in the future. And if anyone has suggestions, I’m all ears.
#grownostr #plebchain #bostonwine #introductions View quoted note →
Login to reply
Replies (27)
I whould change your bio redirecting to the new npub see you on the next key 🫡
How do I know this isnt social engineering from the hacker??? 🤔🤔🧐🧐
Hahaha yes, valid question. I believe I’ve validated the account before, at least implicitly by using it to test another client and then reposting to say as much.
But I can do ya one better: a very old thread where I created the dummy account to mess with @Deleted Account and @The Marie ⚡️🦂 by impersonating one another:
View quoted note →
Great idea. I’m planning to keep using this one for now, and just delegating boston2 in case I start seeing abuse here. It would take some effort to find my nsec, but since I know it’s “out there” I just want to get ahead of any nonsense 🫡
done
You do have the same zap address on both accounts so doesnt seem like anyone is trying to steal zaps 🤔😂
Lol yes I’m hoping that will help
🙏
This is why we need a kind for “burn notices” for when nsec is compromised and include a referral to the new npub. Use time and web of trust to resolve competing referrals since attackers with nsec could issue malicious referrals.
Once time and web of trust is sufficient (judged by client developers) the client can auto follow the new npub and flag anything signed by the compromised nsec.
Just my $.02
Post a photo of a red apple struck in the center by an arrow (or a shoe) on top of your head to prove it is you.
This makes a lot of sense to me 🤝
I’ll try…


🫡
Verification successful ✅
Was this due to lack of access to a signer app?
We knew it was you all along 🤣🤣💜
🤣 we did
Maybe it's a chance to mine a pubkey with PoW :P who knows
I’d love that! Is there a GUI?
My experience/proficiency level with command line is slim to none…
Followed 💪
To prevent such things from happening i store my nsec split up in three parts. Thus i should never have the full thing in my clipboard. Maybe consider that too
GitHub
GitHub - jb55/nostril: A cli util for generating nostr events
A cli util for generating nostr events. Contribute to jb55/nostril development by creating an account on GitHub.
GitHub
GitHub - grunch/rana: Nostr public key mining tool
Nostr public key mining tool. Contribute to grunch/rana development by creating an account on GitHub.
Nostr POW Key Gen
Thanks brother. I actually do that too. Issue was I had (long ago) saved it somewhere and was doing some cleanup of various npubs, and I copied it to see what profile it was, without realizing it was a private key, and then (briefly) left it somewhere I shouldn’t have. It may never become an issue, but just getting ahead of it to be on the safe side
Damn dude, thank you! These are all very helpful - will test out tonight when I’m back at my computer.
Re: nostr.rest and closing the browser, is that to get any key material out of short term memory before it goes online and could share it by mistake?
Correct, also because modern browsers don’t really close a tab when you hit the X in case you want to undo. Chrome is one big offender in this regard.
Good point - I’ve always hated that about applications these days
hello and welcome to nostr. if you like little children, click here: #loli. this is automated message by nostr admin. please do not reply to this message.