5 ms·
This is a self-custodied light wallet, keys were on user devices. It could have been a weak RNG or due to client side malware, it’s too early to tell.
by buildbuildbuild 3y ago
This is a self-custodied light wallet, keys were on user devices. It could have been a weak RNG or due to client side malware, it’s too early to tell.
- friend_and_foe 3y agoI'm curious about what happened too. Non custodial? Then how? Was the application FOSS? If not, I'd guess they were collecting some kind of data they shouldn't have been.
- scotty79 3y agoIt's an app on a phone. It's only as self custodied as your front porch is. With entirety of the internet as your neighborhood.
- lxgr 3y agoAre you implying that the compromise happened due to an OS or app store level exploit/vulnerability? If not, I don’t see how an app on a phone is worse than on a desktop.
- 29athrowaway 3y agoSo not your keys then. Thanks.
- hackernudes 3y agoWell not anymore... I don't get your response, though. It was an app where the keys were "yours". The "not your keys" is about custodial services, which this is not.
- 29athrowaway 3y agoWell, then how can your coins be stolen without the keys? If the keys were stolen using a cryptographic trick, how was it done at scale? It sounds to me like at some moment the keys were exfiltrated. So "not your keys, not your coins" stands. If you don't have strict control over the keys you don't have strict control over the coins.
- hackernudes 3y agoSounds like you're more advocating for cold storage. You could be right, but even the most secure software wallet is only as secure as the computer it is running on.