We will shortly disclose a security issue that could potentially cause exchanges a loss of funds. In order to receive advance notice prior to disclosure, please add your name to the following list via pull request, or by DM’ing @trailofbits or @levelk_io:https://github.com/trailofbits/blockchain-security-contacts …
-
Show this thread
-
Replying to @levelk_io @trailofbits
Could you be a bit more specific what this affects? There are too many systems that transfer funds to users... Does this affect sending Ethereum transactions for example?
1 reply 0 retweets 2 likes -
We will disclose this to as many people and organizations we believe are affected early next week. We are only gathering contact information right now, and finishing our technical investigation of the flaw.
2 replies 1 retweet 7 likes -
Is this methodology appropriate when considering a decentralised network? Given the vagueness of the issue so far, anyone may be affected, the extent of which will be unknown except to the individual. Will your approach give big known players an unfair advantage?
1 reply 0 retweets 2 likes -
It will give people who add themselves to our notification list an advantage, which we are loudly trying to advertise in advance of a quiet, embargo'd notification period and then later public release.
1 reply 0 retweets 5 likes -
As a random individual, can I put my name on the list? If not, how do you plan to ensure that parties you are pre-disclosing to (including everyone associated with them) have the interest of their users and will not misuse their advantage?
1 reply 0 retweets 4 likes -
We are only notifying people who have an ability to patch their systems to mitigate the flaw. Everyone else will receive the details once the embargo period has expired.
3 replies 0 retweets 5 likes -
Ability to patch = ability to exploit. No? Scenario: DEX common construct has exploit allows stealing user funds. You disclose exploit to exchange first, friend of owner exploits it to steal user funds before said user has awareness or able to personally mitigate.
1 reply 0 retweets 4 likes
Thanks for your perspective, however, we see no better way to release this information than a staged process that attempts to maximize patching and minimize harm. You can choose a different process when you find the bug.
-
-
Replying to @dguido @StNakamoto and
doesn't the proposed vulnerability affect non-custodial wallets?
1 reply 0 retweets 1 like -
Replying to @shatzakis @dguido and
I meant: does*
0 replies 0 retweets 0 likes
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.