They just handed attackers the perfect playbook.
UniSat’s vault encryption was ridiculously weak (weak KDF).
Private keys and seed phrases sitting in plaintext in RAM memory.
Any website could talk directly to the extension.
unisat dot io had automatic trust without real user approval.
Permissions were leaking.
They fixed all of it… IN PUBLIC.
With ultra-detailed diffs that now double as an attack roadmap.
Meanwhile:
500,000 users are still running the OLD version.
The patched release is still stuck in pre-release.
The patch didn’t just close the holes.
It showed attackers exactly where to look…
while most users remain exposed.
It’s opening a patch gap and starting the clock.
Pure insanity.
That gives you a pretty good idea of the real level of security maturity behind an industry that claims to protect billions in user funds.
@lopp@chainalysis@udiWertheimer
They just handed attackers the perfect playbook.
UniSat’s vault encryption was ridiculously weak (weak KDF).
Private keys and seed phrases sitting in plaintext in RAM memory.
Any website could talk directly to the extension.
unisat dot io had automatic trust without real user approval.
Permissions were leaking.
They fixed all of it… IN PUBLIC.
With ultra-detailed diffs that now double as an attack roadmap.
Meanwhile:
500,000 users are still running the OLD version.
The patched release is still stuck in pre-release.
The patch didn’t just close the holes.
It showed attackers exactly where to look…
while most users remain exposed.
It’s opening a patch gap and starting the clock.
Pure insanity.
That gives you a pretty good idea of the real level of security maturity behind an industry that claims to protect billions in user funds.
@lopp@chainalysis@udiWertheimer
Si vous avez utilisé unisat d'une quelconque manière, faites les updates si vous souhaitez jouer à la roulette russe, ou migrez vos assets sur un autre wallet plus sécurisé dès que possible
Leur github a accueilli 400 commits dans toute son histoire, dont 25% ont été effectués cette semaine.
Ça sent pas la sérénité, la tisane et le massage de la nuque en supplément
They just handed attackers the perfect playbook.
UniSat’s vault encryption was ridiculously weak (weak KDF).
Private keys and seed phrases sitting in plaintext in RAM memory.
Any website could talk directly to the extension.
unisat dot io had automatic trust without real user approval.
Permissions were leaking.
They fixed all of it… IN PUBLIC.
With ultra-detailed diffs that now double as an attack roadmap.
Meanwhile:
500,000 users are still running the OLD version.
The patched release is still stuck in pre-release.
The patch didn’t just close the holes.
It showed attackers exactly where to look…
while most users remain exposed.
It’s opening a patch gap and starting the clock.
Pure insanity.
That gives you a pretty good idea of the real level of security maturity behind an industry that claims to protect billions in user funds.
@lopp@chainalysis@udiWertheimer
@grok So the vendor weaponized their security.md to avoid acknowledging researchers, only to immediately leak a 1-day exploit to attackers via uncoordinated commits. From an institutional security perspective, can a team employing these shadow tactics be trusted to secure millions in Taproot assets? What does this indicate about their internal security culture?
@ianai_lab If the industry and users still aren’t asking the right questions, this could just end up being the final nail in the coffin...
https://t.co/atrzJSDLb5
They just handed attackers the perfect playbook.
UniSat’s vault encryption was ridiculously weak (weak KDF).
Private keys and seed phrases sitting in plaintext in RAM memory.
Any website could talk directly to the extension.
unisat dot io had automatic trust without real user approval.
Permissions were leaking.
They fixed all of it… IN PUBLIC.
With ultra-detailed diffs that now double as an attack roadmap.
Meanwhile:
500,000 users are still running the OLD version.
The patched release is still stuck in pre-release.
The patch didn’t just close the holes.
It showed attackers exactly where to look…
while most users remain exposed.
It’s opening a patch gap and starting the clock.
Pure insanity.
That gives you a pretty good idea of the real level of security maturity behind an industry that claims to protect billions in user funds.
@lopp@chainalysis@udiWertheimer
@RSGOgreatAgain If the industry and users still aren’t asking the right questions, this could just end up being the final nail in the coffin...
https://t.co/atrzJSDLb5
They just handed attackers the perfect playbook.
UniSat’s vault encryption was ridiculously weak (weak KDF).
Private keys and seed phrases sitting in plaintext in RAM memory.
Any website could talk directly to the extension.
unisat dot io had automatic trust without real user approval.
Permissions were leaking.
They fixed all of it… IN PUBLIC.
With ultra-detailed diffs that now double as an attack roadmap.
Meanwhile:
500,000 users are still running the OLD version.
The patched release is still stuck in pre-release.
The patch didn’t just close the holes.
It showed attackers exactly where to look…
while most users remain exposed.
It’s opening a patch gap and starting the clock.
Pure insanity.
That gives you a pretty good idea of the real level of security maturity behind an industry that claims to protect billions in user funds.
@lopp@chainalysis@udiWertheimer
@Bracket333 If the industry and users still aren’t asking the right questions, this could just end up being the final nail in the coffin...
https://t.co/atrzJSDLb5
They just handed attackers the perfect playbook.
UniSat’s vault encryption was ridiculously weak (weak KDF).
Private keys and seed phrases sitting in plaintext in RAM memory.
Any website could talk directly to the extension.
unisat dot io had automatic trust without real user approval.
Permissions were leaking.
They fixed all of it… IN PUBLIC.
With ultra-detailed diffs that now double as an attack roadmap.
Meanwhile:
500,000 users are still running the OLD version.
The patched release is still stuck in pre-release.
The patch didn’t just close the holes.
It showed attackers exactly where to look…
while most users remain exposed.
It’s opening a patch gap and starting the clock.
Pure insanity.
That gives you a pretty good idea of the real level of security maturity behind an industry that claims to protect billions in user funds.
@lopp@chainalysis@udiWertheimer
@Relentless_btc If the industry and users still aren’t asking the right questions, this could just end up being the final nail in the coffin...
https://t.co/atrzJSDLb5
They just handed attackers the perfect playbook.
UniSat’s vault encryption was ridiculously weak (weak KDF).
Private keys and seed phrases sitting in plaintext in RAM memory.
Any website could talk directly to the extension.
unisat dot io had automatic trust without real user approval.
Permissions were leaking.
They fixed all of it… IN PUBLIC.
With ultra-detailed diffs that now double as an attack roadmap.
Meanwhile:
500,000 users are still running the OLD version.
The patched release is still stuck in pre-release.
The patch didn’t just close the holes.
It showed attackers exactly where to look…
while most users remain exposed.
It’s opening a patch gap and starting the clock.
Pure insanity.
That gives you a pretty good idea of the real level of security maturity behind an industry that claims to protect billions in user funds.
@lopp@chainalysis@udiWertheimer
@master3_0@LeonidasNFT If the industry and users still aren’t asking the right questions, this could just end up being the final nail in the coffin...
https://t.co/atrzJSDLb5
They just handed attackers the perfect playbook.
UniSat’s vault encryption was ridiculously weak (weak KDF).
Private keys and seed phrases sitting in plaintext in RAM memory.
Any website could talk directly to the extension.
unisat dot io had automatic trust without real user approval.
Permissions were leaking.
They fixed all of it… IN PUBLIC.
With ultra-detailed diffs that now double as an attack roadmap.
Meanwhile:
500,000 users are still running the OLD version.
The patched release is still stuck in pre-release.
The patch didn’t just close the holes.
It showed attackers exactly where to look…
while most users remain exposed.
It’s opening a patch gap and starting the clock.
Pure insanity.
That gives you a pretty good idea of the real level of security maturity behind an industry that claims to protect billions in user funds.
@lopp@chainalysis@udiWertheimer
@yanroto88 If the industry and users still aren’t asking the right questions, this could just end up being the final nail in the coffin...
https://t.co/atrzJSDLb5
They just handed attackers the perfect playbook.
UniSat’s vault encryption was ridiculously weak (weak KDF).
Private keys and seed phrases sitting in plaintext in RAM memory.
Any website could talk directly to the extension.
unisat dot io had automatic trust without real user approval.
Permissions were leaking.
They fixed all of it… IN PUBLIC.
With ultra-detailed diffs that now double as an attack roadmap.
Meanwhile:
500,000 users are still running the OLD version.
The patched release is still stuck in pre-release.
The patch didn’t just close the holes.
It showed attackers exactly where to look…
while most users remain exposed.
It’s opening a patch gap and starting the clock.
Pure insanity.
That gives you a pretty good idea of the real level of security maturity behind an industry that claims to protect billions in user funds.
@lopp@chainalysis@udiWertheimer
@DOG_OF_BTC@Cryptolution If the industry and users still aren’t asking the right questions, this could just end up being the final nail in the coffin...
https://t.co/atrzJSDLb5
They just handed attackers the perfect playbook.
UniSat’s vault encryption was ridiculously weak (weak KDF).
Private keys and seed phrases sitting in plaintext in RAM memory.
Any website could talk directly to the extension.
unisat dot io had automatic trust without real user approval.
Permissions were leaking.
They fixed all of it… IN PUBLIC.
With ultra-detailed diffs that now double as an attack roadmap.
Meanwhile:
500,000 users are still running the OLD version.
The patched release is still stuck in pre-release.
The patch didn’t just close the holes.
It showed attackers exactly where to look…
while most users remain exposed.
It’s opening a patch gap and starting the clock.
Pure insanity.
That gives you a pretty good idea of the real level of security maturity behind an industry that claims to protect billions in user funds.
@lopp@chainalysis@udiWertheimer
@30Npres If the industry and users still aren’t asking the right questions, this could just end up being the final nail in the coffin...
https://t.co/atrzJSDLb5
They just handed attackers the perfect playbook.
UniSat’s vault encryption was ridiculously weak (weak KDF).
Private keys and seed phrases sitting in plaintext in RAM memory.
Any website could talk directly to the extension.
unisat dot io had automatic trust without real user approval.
Permissions were leaking.
They fixed all of it… IN PUBLIC.
With ultra-detailed diffs that now double as an attack roadmap.
Meanwhile:
500,000 users are still running the OLD version.
The patched release is still stuck in pre-release.
The patch didn’t just close the holes.
It showed attackers exactly where to look…
while most users remain exposed.
It’s opening a patch gap and starting the clock.
Pure insanity.
That gives you a pretty good idea of the real level of security maturity behind an industry that claims to protect billions in user funds.
@lopp@chainalysis@udiWertheimer
@ontop_sats If the industry and users still aren’t asking the right questions, this could just end up being the final nail in the coffin...
https://t.co/atrzJSDLb5
They just handed attackers the perfect playbook.
UniSat’s vault encryption was ridiculously weak (weak KDF).
Private keys and seed phrases sitting in plaintext in RAM memory.
Any website could talk directly to the extension.
unisat dot io had automatic trust without real user approval.
Permissions were leaking.
They fixed all of it… IN PUBLIC.
With ultra-detailed diffs that now double as an attack roadmap.
Meanwhile:
500,000 users are still running the OLD version.
The patched release is still stuck in pre-release.
The patch didn’t just close the holes.
It showed attackers exactly where to look…
while most users remain exposed.
It’s opening a patch gap and starting the clock.
Pure insanity.
That gives you a pretty good idea of the real level of security maturity behind an industry that claims to protect billions in user funds.
@lopp@chainalysis@udiWertheimer
@steko170981 If the industry and users still aren’t asking the right questions, this could just end up being the final nail in the coffin...
https://t.co/atrzJSDLb5
They just handed attackers the perfect playbook.
UniSat’s vault encryption was ridiculously weak (weak KDF).
Private keys and seed phrases sitting in plaintext in RAM memory.
Any website could talk directly to the extension.
unisat dot io had automatic trust without real user approval.
Permissions were leaking.
They fixed all of it… IN PUBLIC.
With ultra-detailed diffs that now double as an attack roadmap.
Meanwhile:
500,000 users are still running the OLD version.
The patched release is still stuck in pre-release.
The patch didn’t just close the holes.
It showed attackers exactly where to look…
while most users remain exposed.
It’s opening a patch gap and starting the clock.
Pure insanity.
That gives you a pretty good idea of the real level of security maturity behind an industry that claims to protect billions in user funds.
@lopp@chainalysis@udiWertheimer
@nisu152 If the industry and users still aren’t asking the right questions, this could just end up being the final nail in the coffin...
https://t.co/atrzJSDLb5
They just handed attackers the perfect playbook.
UniSat’s vault encryption was ridiculously weak (weak KDF).
Private keys and seed phrases sitting in plaintext in RAM memory.
Any website could talk directly to the extension.
unisat dot io had automatic trust without real user approval.
Permissions were leaking.
They fixed all of it… IN PUBLIC.
With ultra-detailed diffs that now double as an attack roadmap.
Meanwhile:
500,000 users are still running the OLD version.
The patched release is still stuck in pre-release.
The patch didn’t just close the holes.
It showed attackers exactly where to look…
while most users remain exposed.
It’s opening a patch gap and starting the clock.
Pure insanity.
That gives you a pretty good idea of the real level of security maturity behind an industry that claims to protect billions in user funds.
@lopp@chainalysis@udiWertheimer