I’m not an official UniSat developer.
I was the external contributor who wrote and detailed those specific security fixes (the PBKDF2 upgrade, sandbox tightening, externally_connectable removal, etc.) and submitted them as PRs in good faith.
In an open-source wallet the commits become public once merged.
that’s how the model works. The detailed messages exist for auditability and maintainability, not as an “attack playbook.” The coordinated part happened earlier (private contribution + review with the team).
The remaining gap you’re pointing at is the time between merge and the patched version reaching all users. that’s a release/distribution issue, not the existence of clear commit history.
Security 101 also includes transparent, reviewable hardening. Happy to clarify further if useful.
Its an OS wallet. So the code is there for everyone. That the goal of being Open source.
Meanwhile non of the attacks bro mentioned can be done as easily as claimable. Not to mention that its so exaggerating as the only way for now anyone could lose their unisat wallet funds is if their device is compromised which isnt a wallet problem.
@laz1m0v@BitcoinArchive we do what we do bro. there is no point in trying to change them. let the change come from us and it will flourish.
Bitcoin started with few honest people working together.
@laz1m0v@BitcoinArchive dude whats wrong, you're mad at anycase wether i come on your side or against it. proving each time.
im sharing knowledge the same way you are
@Ryversss@laz1m0v@lorenzonical make sure to learn and understand how to use multisigs , it can also be problematic if misimplemented. feel free to reach out anytime if you need any help or would like to talk it out.
@Ryversss@laz1m0v@lorenzonical i wouldn't honestly recommend a certain specific hardware wallet and say this is the best/secure as its relative. i have been using @Tangem though and it has been great never had an issue with it.
@Ryversss@laz1m0v@lorenzonical the only way to know is to be able to check the wallet code and ensure there is no mistakes/vulnerabilities to that effect. the actual vulnerability is a misimplementation. which led to bad entropy
@Ryversss@laz1m0v@lorenzonical logically compromise = fund stolen unless the attacker didnt get to it.
and yes there is technically no issue, idk why you think there is one ? maybe because of the main post ? which is the reason i debated ?