We will shortly disclose a security issue that could potentially cause exchanges a loss of funds. In order to receive advance notice prior to disclosure, please add your name to the following list via pull request, or by DM’ing @trailofbits or @levelk_io:https://github.com/trailofbits/blockchain-security-contacts …
-
Show this thread
-
This issue also affects other systems that transfer funds to users. If you think your system may be affected, please DM
@trailofbits or@levelk_io2 replies 1 retweet 15 likesShow this thread -
Replying to @levelk_io @trailofbits
Given the vagueness of this announcement, how can someone know their system might be affected or not? Can you make a proper public post (not a tweet) that might not fully disclose the vulnerability but at least describe the nature of the issue and a provisional plan of action?
1 reply 0 retweets 0 likes
As with most logic flaws, a description of the bug is identical to writing an exploit for it. Therefore, no, there's not much we can say right now. Initial notifications are going out tomorrow, then we'll make it public a few days afterward.
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.