Some thoughts on this ported over from the bird app. Not a c...

LightningRoulette

npub1v9v56u224987250kqsfr27xy5evjz305y29dscqjyjcm388yqxcqg4jnm3

hex

35d6637c0e572e6553aeb14de7e505179eb6c343e2a1254ccb972c414aa375ff

nevent

nevent1qqsrt4nr0s89wtn92whtzn08u5z3084kcdp79gf9fn9ewtzpf23htlcprpmhxue69uhhyetvv9ujuem4d36kwatvw5hx6mm9qgsxzk2dw992jnl928mqgy340rz2vkfpgh6z9zkcvqfzfvdcnnjqrvqv8eks3

Kind-1 (TextNote)

2026-08-13T02:03:05Z

↳ 回复 事件不存在

1e8746b36fbe98f4c072588cf7a8f57909e08982264ee3b7bb064069eebb9cc0...

Some thoughts on this ported over from the bird app. Not a crisis unless you are a submarine swapper. Even so, upgrade anyway

1/9 Electrum 4.8.1 contains “important security fixes”, but the maintainers have not yet disclosed the details. I reviewed the public 4.8.0→4.8.1 code changes. Here is what the evidence does—and does not—show. 🧵

2/9 First: Electrum-generated seeds are not shown to share the COLDCARD entropy flaw. Electrum’s seed-generation code did not change between 4.8.0 and 4.8.1; it uses Python’s cryptographic secrets.randbelow(), backed by the operating system’s CSPRNG.

3/9 The COLDCARD issue arose from a different mechanism: affected device-generated seeds could fall back to weak PRNG/reseed paths. Importing such a seed into Electrum cannot repair it. But an Electrum-generated seed is not weakened merely by later importing it into COLDCARD.

4/9 The critical question is where the seed was originally generated. Genuine Electrum + a normal, uncompromised OS: no analogous entropy defect found. Affected COLDCARD firmware: migrate the seed. Unknown origin: investigate, and take the conservative path if needed.

5/9 The BTCPay incident was separate: it exposed LND macaroon credentials in affected BTCPay deployments. Electrum’s built-in Lightning wallet is not LND and does not use those macaroons. This was not an Electrum seed-generation flaw.

6/9 Visible 4.8.1 hardening includes malicious-server resource limits, stricter network-response validation, CPU-DoS bounds, oversized base43 input limits, log redaction, Android screenshot protection, and Lightning/swap safety checks.

7/9 Our best inference: the undisclosed fix is the submarine-swap fund-safety cluster—funding without expected HTLCs, cancel/broadcast races, unsafe provider terms and refund-reorg timing. This is a code-based inference, not confirmation from Electrum’s maintainers.

8/9 Practical takeaway: upgrade to a verified Electrum 4.8.1 release before connected use. Do not rotate a genuinely Electrum-generated seed solely because of the COLDCARD incident. If the seed came from affected COLDCARD firmware, follow its migration guidance urgently.

9/9 It boils down to PR #10827, framed as a unit test but actually is the submarine swap flaw. If you are a lightning person (like us) take note. No issue with @ElectrumWallet doing it this way; there aren't many choices when it's all open spurce

原始 JSON

{
  "kind": 1,
  "id": "35d6637c0e572e6553aeb14de7e505179eb6c343e2a1254ccb972c414aa375ff",
  "pubkey": "61594d714aa94fe551f604123578c4a6592145f4228ad8601224b1b89ce401b0",
  "created_at": 1786586585,
  "tags": [
    [
      "e",
      "1e8746b36fbe98f4c072588cf7a8f57909e08982264ee3b7bb064069eebb9cc0",
      "wss://nos.lol/",
      "root",
      "1027fd5bc3b5e50c9800d48bc8acfbc290d89b857c7ce15572a57048c4c0558e"
    ],
    [
      "p",
      "1027fd5bc3b5e50c9800d48bc8acfbc290d89b857c7ce15572a57048c4c0558e",
      "wss://nos.lol/"
    ],
    [
      "t",
      "10827"
    ],
    [
      "client",
      "Amethyst"
    ]
  ],
  "content": "Some thoughts on this ported over from the bird app. Not a crisis unless you are a submarine swapper. Even so, upgrade anyway\n\n\n1/9 Electrum 4.8.1 contains “important security fixes”, but the maintainers have not yet disclosed the details. I reviewed the public 4.8.0→4.8.1 code changes. Here is what the evidence does—and does not—show. 🧵\n\n2/9 First: Electrum-generated seeds are not shown to share the COLDCARD entropy flaw. Electrum’s seed-generation code did not change between 4.8.0 and 4.8.1; it uses Python’s cryptographic secrets.randbelow(), backed by the operating system’s CSPRNG.\n\n3/9 The COLDCARD issue arose from a different mechanism: affected device-generated seeds could fall back to weak PRNG/reseed paths. Importing such a seed into Electrum cannot repair it. But an Electrum-generated seed is not weakened merely by later importing it into COLDCARD.\n\n4/9 The critical question is where the seed was originally generated. Genuine Electrum + a normal, uncompromised OS: no analogous entropy defect found. Affected COLDCARD firmware: migrate the seed. Unknown origin: investigate, and take the conservative path if needed.\n\n5/9 The BTCPay incident was separate: it exposed LND macaroon credentials in affected BTCPay deployments. Electrum’s built-in Lightning wallet is not LND and does not use those macaroons. This was not an Electrum seed-generation flaw.\n\n6/9 Visible 4.8.1 hardening includes malicious-server resource limits, stricter network-response validation, CPU-DoS bounds, oversized base43 input limits, log redaction, Android screenshot protection, and Lightning/swap safety checks.\n\n7/9 Our best inference: the undisclosed fix is the submarine-swap fund-safety cluster—funding without expected HTLCs, cancel/broadcast races, unsafe provider terms and refund-reorg timing. This is a code-based inference, not confirmation from Electrum’s maintainers.\n\n8/9 Practical takeaway: upgrade to a verified Electrum 4.8.1 release before connected use. Do not rotate a genuinely Electrum-generated seed solely because of the COLDCARD incident. If the seed came from affected COLDCARD firmware, follow its migration guidance urgently.\n\n9/9 It boils down to PR #10827, framed as a unit test but actually is the submarine swap flaw. If you are a lightning person (like us) take note. No issue with @ElectrumWallet doing it this way; there aren't many choices when it's all open spurce",
  "sig": "0d9ead4c74adfc7dedeb1a917db93dbf9f4e0179dd21704e15d8fa29caaae83b44f5b443987e3e577943e17b39e7bd89b12f9382d7413d9cbe76d00d450a70b6"
}