Spyke
bitcoin·Bitcoinbydeafboy

Bisq decentralized exchange money drainig bug

Trading was halted by the Bisq team, by raising the minimal required trading protocol version.

Only active trade offers could've been affected. The local wallet is safe

How did the exploit happen?

In short, the exploit was caused by a missing validation that should have rejected negative input values provided by the taker.

The maker and taker must use the same miner fee. That fee value is provided by the taker.

The attacker supplied a negative miner fee.

When the maker calculated the multisig output amount — which includes the miner fee for the payout transaction — the negative value reduced the multisig amount to 0.001 BTC, while the remaining funds were redirected to the taker’s change output.

Bisq decentralized exchange money drainig bughttps://bisq.community/t/update-on-the-exploit-of-may-1st/13691Open linkView original on lemmy.world
bitcoin·Bitcoinby0x0F

Bitcoin Core v31.0 released

cross-posted from: https://lemmy.blahaj.zone/post/41550753

Notable changes:

other changes in the linked release notes

Bitcoin Core v31.0 releasedhttps://github.com/bitcoin/bitcoin/blob/master/doc/release-notes/release-notes-31.0.mdOpen linkView original on lemmy.blahaj.zone

Darkhorse Podcast Interview about BTC

"Who Hijacked Bitcoin? Steve Patterson and Aaron Day on DarkHorse"

As a fan of BTC I found this episode very interesting. I wish I had know this stuff earlier as it would have changed my perspective on BTC, such as the ideological differences between BTC and BTC Cash.

https://pscrb.fm/rss/p/www.buzzsprout.com/424075/episodes/18812392-who-hijacked-bitcoin-steve-patterson-and-aaron-day-on-darkhorse.mp3Open linkView original on lemmy.today