Some thoughts on this ported over from the bird app. Not a c...

npub1v9v56u224987250kqsfr27xy5evjz305y29dscqjyjcm388yqxcqg4jnm3
hex
35d6637c0e572e6553aeb14de7e505179eb6c343e2a1254ccb972c414aa375ffnevent
nevent1qqsrt4nr0s89wtn92whtzn08u5z3084kcdp79gf9fn9ewtzpf23htlcprpmhxue69uhhyetvv9ujuem4d36kwatvw5hx6mm9qgsxzk2dw992jnl928mqgy340rz2vkfpgh6z9zkcvqfzfvdcnnjqrvqv8eks3Kind-1 (TextNote)
↳ 回复 事件不存在
1e8746b36fbe98f4c072588cf7a8f57909e08982264ee3b7bb064069eebb9cc0...
Some thoughts on this ported over from the bird app. Not a crisis unless you are a submarine swapper. Even so, upgrade anyway
1/9 Electrum 4.8.1 contains “important security fixes”, but the maintainers have not yet disclosed the details. I reviewed the public 4.8.0→4.8.1 code changes. Here is what the evidence does—and does not—show. 🧵
2/9 First: Electrum-generated seeds are not shown to share the COLDCARD entropy flaw. Electrum’s seed-generation code did not change between 4.8.0 and 4.8.1; it uses Python’s cryptographic secrets.randbelow(), backed by the operating system’s CSPRNG.
3/9 The COLDCARD issue arose from a different mechanism: affected device-generated seeds could fall back to weak PRNG/reseed paths. Importing such a seed into Electrum cannot repair it. But an Electrum-generated seed is not weakened merely by later importing it into COLDCARD.
4/9 The critical question is where the seed was originally generated. Genuine Electrum + a normal, uncompromised OS: no analogous entropy defect found. Affected COLDCARD firmware: migrate the seed. Unknown origin: investigate, and take the conservative path if needed.
5/9 The BTCPay incident was separate: it exposed LND macaroon credentials in affected BTCPay deployments. Electrum’s built-in Lightning wallet is not LND and does not use those macaroons. This was not an Electrum seed-generation flaw.
6/9 Visible 4.8.1 hardening includes malicious-server resource limits, stricter network-response validation, CPU-DoS bounds, oversized base43 input limits, log redaction, Android screenshot protection, and Lightning/swap safety checks.
7/9 Our best inference: the undisclosed fix is the submarine-swap fund-safety cluster—funding without expected HTLCs, cancel/broadcast races, unsafe provider terms and refund-reorg timing. This is a code-based inference, not confirmation from Electrum’s maintainers.
8/9 Practical takeaway: upgrade to a verified Electrum 4.8.1 release before connected use. Do not rotate a genuinely Electrum-generated seed solely because of the COLDCARD incident. If the seed came from affected COLDCARD firmware, follow its migration guidance urgently.
9/9 It boils down to PR #10827, framed as a unit test but actually is the submarine swap flaw. If you are a lightning person (like us) take note. No issue with @ElectrumWallet doing it this way; there aren't many choices when it's all open spurce
原始 JSON
{
"kind": 1,
"id": "35d6637c0e572e6553aeb14de7e505179eb6c343e2a1254ccb972c414aa375ff",
"pubkey": "61594d714aa94fe551f604123578c4a6592145f4228ad8601224b1b89ce401b0",
"created_at": 1786586585,
"tags": [
[
"e",
"1e8746b36fbe98f4c072588cf7a8f57909e08982264ee3b7bb064069eebb9cc0",
"wss://nos.lol/",
"root",
"1027fd5bc3b5e50c9800d48bc8acfbc290d89b857c7ce15572a57048c4c0558e"
],
[
"p",
"1027fd5bc3b5e50c9800d48bc8acfbc290d89b857c7ce15572a57048c4c0558e",
"wss://nos.lol/"
],
[
"t",
"10827"
],
[
"client",
"Amethyst"
]
],
"content": "Some thoughts on this ported over from the bird app. Not a crisis unless you are a submarine swapper. Even so, upgrade anyway\n\n\n1/9 Electrum 4.8.1 contains “important security fixes”, but the maintainers have not yet disclosed the details. I reviewed the public 4.8.0→4.8.1 code changes. Here is what the evidence does—and does not—show. 🧵\n\n2/9 First: Electrum-generated seeds are not shown to share the COLDCARD entropy flaw. Electrum’s seed-generation code did not change between 4.8.0 and 4.8.1; it uses Python’s cryptographic secrets.randbelow(), backed by the operating system’s CSPRNG.\n\n3/9 The COLDCARD issue arose from a different mechanism: affected device-generated seeds could fall back to weak PRNG/reseed paths. Importing such a seed into Electrum cannot repair it. But an Electrum-generated seed is not weakened merely by later importing it into COLDCARD.\n\n4/9 The critical question is where the seed was originally generated. Genuine Electrum + a normal, uncompromised OS: no analogous entropy defect found. Affected COLDCARD firmware: migrate the seed. Unknown origin: investigate, and take the conservative path if needed.\n\n5/9 The BTCPay incident was separate: it exposed LND macaroon credentials in affected BTCPay deployments. Electrum’s built-in Lightning wallet is not LND and does not use those macaroons. This was not an Electrum seed-generation flaw.\n\n6/9 Visible 4.8.1 hardening includes malicious-server resource limits, stricter network-response validation, CPU-DoS bounds, oversized base43 input limits, log redaction, Android screenshot protection, and Lightning/swap safety checks.\n\n7/9 Our best inference: the undisclosed fix is the submarine-swap fund-safety cluster—funding without expected HTLCs, cancel/broadcast races, unsafe provider terms and refund-reorg timing. This is a code-based inference, not confirmation from Electrum’s maintainers.\n\n8/9 Practical takeaway: upgrade to a verified Electrum 4.8.1 release before connected use. Do not rotate a genuinely Electrum-generated seed solely because of the COLDCARD incident. If the seed came from affected COLDCARD firmware, follow its migration guidance urgently.\n\n9/9 It boils down to PR #10827, framed as a unit test but actually is the submarine swap flaw. If you are a lightning person (like us) take note. No issue with @ElectrumWallet doing it this way; there aren't many choices when it's all open spurce",
"sig": "0d9ead4c74adfc7dedeb1a917db93dbf9f4e0179dd21704e15d8fa29caaae83b44f5b443987e3e577943e17b39e7bd89b12f9382d7413d9cbe76d00d450a70b6"
}