They just handed attackers the perfect playbook.
UniSat’s vault encryption was ridiculously weak (weak KDF).
Private keys and seed phrases sitting in plaintext in RAM memory.
Any website could talk directly to the extension.
unisat dot io had automatic trust without real user approval.
Permissions were leaking.
They fixed all of it… IN PUBLIC.
With ultra-detailed diffs that now double as an attack roadmap.
Meanwhile:
500,000 users are still running the OLD version.
The patched release is still stuck in pre-release.
The patch didn’t just close the holes.
It showed attackers exactly where to look…
while most users remain exposed.
It’s opening a patch gap and starting the clock.
Pure insanity.
That gives you a pretty good idea of the real level of security maturity behind an industry that claims to protect billions in user funds.
@lopp@chainalysis@udiWertheimer
Why is there still no search bar in Grok conversation history on X ???
When you’ve got 150+ chats with Grok you end up scrolling like it’s 2012.
This is basic stuff. ChatGPT has it, Claude has it, even Gemini has it…
@elonmusk@benjitaylor@nikitabier@singhai@dinkin_flickaa
Can we please get a Search tab in the history ? 🙏
Who else is tired of searching manually ?
Lmao at @unisat_wallet. Yesterday they rushed a new security.md claiming that memory leaks are out of scope and won't be rewarded.
Writing legal threats to researchers while secretly using their intel to patch your code is a wild strategy. Are user funds SAFU or just your bug bounty budget?
They just handed attackers the perfect playbook.
UniSat’s vault encryption was ridiculously weak (weak KDF).
Private keys and seed phrases sitting in plaintext in RAM memory.
Any website could talk directly to the extension.
unisat dot io had automatic trust without real user approval.
Permissions were leaking.
They fixed all of it… IN PUBLIC.
With ultra-detailed diffs that now double as an attack roadmap.
Meanwhile:
500,000 users are still running the OLD version.
The patched release is still stuck in pre-release.
The patch didn’t just close the holes.
It showed attackers exactly where to look…
while most users remain exposed.
It’s opening a patch gap and starting the clock.
Pure insanity.
That gives you a pretty good idea of the real level of security maturity behind an industry that claims to protect billions in user funds.
@lopp@chainalysis@udiWertheimer
Si vous avez utilisé unisat d'une quelconque manière, faites les updates si vous souhaitez jouer à la roulette russe, ou migrez vos assets sur un autre wallet plus sécurisé dès que possible
Leur github a accueilli 400 commits dans toute son histoire, dont 25% ont été effectués cette semaine.
Ça sent pas la sérénité, la tisane et le massage de la nuque en supplément
They just handed attackers the perfect playbook.
UniSat’s vault encryption was ridiculously weak (weak KDF).
Private keys and seed phrases sitting in plaintext in RAM memory.
Any website could talk directly to the extension.
unisat dot io had automatic trust without real user approval.
Permissions were leaking.
They fixed all of it… IN PUBLIC.
With ultra-detailed diffs that now double as an attack roadmap.
Meanwhile:
500,000 users are still running the OLD version.
The patched release is still stuck in pre-release.
The patch didn’t just close the holes.
It showed attackers exactly where to look…
while most users remain exposed.
It’s opening a patch gap and starting the clock.
Pure insanity.
That gives you a pretty good idea of the real level of security maturity behind an industry that claims to protect billions in user funds.
@lopp@chainalysis@udiWertheimer
@grok So the vendor weaponized their security.md to avoid acknowledging researchers, only to immediately leak a 1-day exploit to attackers via uncoordinated commits. From an institutional security perspective, can a team employing these shadow tactics be trusted to secure millions in Taproot assets? What does this indicate about their internal security culture?
@ianai_lab If the industry and users still aren’t asking the right questions, this could just end up being the final nail in the coffin...
https://t.co/atrzJSDLb5
They just handed attackers the perfect playbook.
UniSat’s vault encryption was ridiculously weak (weak KDF).
Private keys and seed phrases sitting in plaintext in RAM memory.
Any website could talk directly to the extension.
unisat dot io had automatic trust without real user approval.
Permissions were leaking.
They fixed all of it… IN PUBLIC.
With ultra-detailed diffs that now double as an attack roadmap.
Meanwhile:
500,000 users are still running the OLD version.
The patched release is still stuck in pre-release.
The patch didn’t just close the holes.
It showed attackers exactly where to look…
while most users remain exposed.
It’s opening a patch gap and starting the clock.
Pure insanity.
That gives you a pretty good idea of the real level of security maturity behind an industry that claims to protect billions in user funds.
@lopp@chainalysis@udiWertheimer
@RSGOgreatAgain If the industry and users still aren’t asking the right questions, this could just end up being the final nail in the coffin...
https://t.co/atrzJSDLb5
They just handed attackers the perfect playbook.
UniSat’s vault encryption was ridiculously weak (weak KDF).
Private keys and seed phrases sitting in plaintext in RAM memory.
Any website could talk directly to the extension.
unisat dot io had automatic trust without real user approval.
Permissions were leaking.
They fixed all of it… IN PUBLIC.
With ultra-detailed diffs that now double as an attack roadmap.
Meanwhile:
500,000 users are still running the OLD version.
The patched release is still stuck in pre-release.
The patch didn’t just close the holes.
It showed attackers exactly where to look…
while most users remain exposed.
It’s opening a patch gap and starting the clock.
Pure insanity.
That gives you a pretty good idea of the real level of security maturity behind an industry that claims to protect billions in user funds.
@lopp@chainalysis@udiWertheimer
@Bracket333 If the industry and users still aren’t asking the right questions, this could just end up being the final nail in the coffin...
https://t.co/atrzJSDLb5
They just handed attackers the perfect playbook.
UniSat’s vault encryption was ridiculously weak (weak KDF).
Private keys and seed phrases sitting in plaintext in RAM memory.
Any website could talk directly to the extension.
unisat dot io had automatic trust without real user approval.
Permissions were leaking.
They fixed all of it… IN PUBLIC.
With ultra-detailed diffs that now double as an attack roadmap.
Meanwhile:
500,000 users are still running the OLD version.
The patched release is still stuck in pre-release.
The patch didn’t just close the holes.
It showed attackers exactly where to look…
while most users remain exposed.
It’s opening a patch gap and starting the clock.
Pure insanity.
That gives you a pretty good idea of the real level of security maturity behind an industry that claims to protect billions in user funds.
@lopp@chainalysis@udiWertheimer
@Relentless_btc If the industry and users still aren’t asking the right questions, this could just end up being the final nail in the coffin...
https://t.co/atrzJSDLb5
They just handed attackers the perfect playbook.
UniSat’s vault encryption was ridiculously weak (weak KDF).
Private keys and seed phrases sitting in plaintext in RAM memory.
Any website could talk directly to the extension.
unisat dot io had automatic trust without real user approval.
Permissions were leaking.
They fixed all of it… IN PUBLIC.
With ultra-detailed diffs that now double as an attack roadmap.
Meanwhile:
500,000 users are still running the OLD version.
The patched release is still stuck in pre-release.
The patch didn’t just close the holes.
It showed attackers exactly where to look…
while most users remain exposed.
It’s opening a patch gap and starting the clock.
Pure insanity.
That gives you a pretty good idea of the real level of security maturity behind an industry that claims to protect billions in user funds.
@lopp@chainalysis@udiWertheimer
@master3_0@LeonidasNFT If the industry and users still aren’t asking the right questions, this could just end up being the final nail in the coffin...
https://t.co/atrzJSDLb5
They just handed attackers the perfect playbook.
UniSat’s vault encryption was ridiculously weak (weak KDF).
Private keys and seed phrases sitting in plaintext in RAM memory.
Any website could talk directly to the extension.
unisat dot io had automatic trust without real user approval.
Permissions were leaking.
They fixed all of it… IN PUBLIC.
With ultra-detailed diffs that now double as an attack roadmap.
Meanwhile:
500,000 users are still running the OLD version.
The patched release is still stuck in pre-release.
The patch didn’t just close the holes.
It showed attackers exactly where to look…
while most users remain exposed.
It’s opening a patch gap and starting the clock.
Pure insanity.
That gives you a pretty good idea of the real level of security maturity behind an industry that claims to protect billions in user funds.
@lopp@chainalysis@udiWertheimer
@yanroto88 If the industry and users still aren’t asking the right questions, this could just end up being the final nail in the coffin...
https://t.co/atrzJSDLb5
They just handed attackers the perfect playbook.
UniSat’s vault encryption was ridiculously weak (weak KDF).
Private keys and seed phrases sitting in plaintext in RAM memory.
Any website could talk directly to the extension.
unisat dot io had automatic trust without real user approval.
Permissions were leaking.
They fixed all of it… IN PUBLIC.
With ultra-detailed diffs that now double as an attack roadmap.
Meanwhile:
500,000 users are still running the OLD version.
The patched release is still stuck in pre-release.
The patch didn’t just close the holes.
It showed attackers exactly where to look…
while most users remain exposed.
It’s opening a patch gap and starting the clock.
Pure insanity.
That gives you a pretty good idea of the real level of security maturity behind an industry that claims to protect billions in user funds.
@lopp@chainalysis@udiWertheimer
@DOG_OF_BTC@Cryptolution If the industry and users still aren’t asking the right questions, this could just end up being the final nail in the coffin...
https://t.co/atrzJSDLb5
They just handed attackers the perfect playbook.
UniSat’s vault encryption was ridiculously weak (weak KDF).
Private keys and seed phrases sitting in plaintext in RAM memory.
Any website could talk directly to the extension.
unisat dot io had automatic trust without real user approval.
Permissions were leaking.
They fixed all of it… IN PUBLIC.
With ultra-detailed diffs that now double as an attack roadmap.
Meanwhile:
500,000 users are still running the OLD version.
The patched release is still stuck in pre-release.
The patch didn’t just close the holes.
It showed attackers exactly where to look…
while most users remain exposed.
It’s opening a patch gap and starting the clock.
Pure insanity.
That gives you a pretty good idea of the real level of security maturity behind an industry that claims to protect billions in user funds.
@lopp@chainalysis@udiWertheimer
@30Npres If the industry and users still aren’t asking the right questions, this could just end up being the final nail in the coffin...
https://t.co/atrzJSDLb5
They just handed attackers the perfect playbook.
UniSat’s vault encryption was ridiculously weak (weak KDF).
Private keys and seed phrases sitting in plaintext in RAM memory.
Any website could talk directly to the extension.
unisat dot io had automatic trust without real user approval.
Permissions were leaking.
They fixed all of it… IN PUBLIC.
With ultra-detailed diffs that now double as an attack roadmap.
Meanwhile:
500,000 users are still running the OLD version.
The patched release is still stuck in pre-release.
The patch didn’t just close the holes.
It showed attackers exactly where to look…
while most users remain exposed.
It’s opening a patch gap and starting the clock.
Pure insanity.
That gives you a pretty good idea of the real level of security maturity behind an industry that claims to protect billions in user funds.
@lopp@chainalysis@udiWertheimer