There is a critical vulnerability being actively exploited on BTCPay Server, which can result in the loss of funds.
Please update your BTCPayServer to 2.4.2 by going to Admin Dashboard -> Server -> Maintenance -> Update & verify the 2.4.2 version string in the footer.
If you are unable to update right away, turn off your BTCPay Server to prevent unauthorized access until you can update.
I’ve seen some people saying coinkite might survive this.
Coinkite will not survive this.
They shipped 3 generations of products with bad entropy (unforgivable) over the course of five years.
Not to mention that the company likely doesn’t make much money and they will be slammed with lawsuits from every possible direction.
It’s over.
Publishing a Bitcoin address isn't great for privacy. It means sharing a permanent record of everything you've ever received to it, and anything you later spend.
Silent Payments are designed to fix that. Described in BIP-352, they're now finally starting to become usable. Here are my notes from using them.
I've written all this up - how to create an SP wallet in Sparrow, connect to Frigate, send and receive, and what the two keys actually do.
https://t.co/94pqHx13ib
It's still early days. Hardware wallet support is still limited, although kudos to @BitBoxSwiss for adding support for sending to sp1 addresses.
Scanning support across the popular node stacks remains thin. And @2140_dev run the only public Frigate server I know of.
I'm Bennet. For more technical explainers, I'm at https://t.co/MUevnuI4PG - independent, no ads/affiliates.
And yes I also mentioned Coldcard on the site, which I feel foolish about.
Equally, no-one should be pressured into holding their own keys. The risks are real and this week showed it. It's telling that experienced users got hit hardest.