Join Nostr
2025-09-08 23:56:20 UTC

Luke Dashjr on Nostr: Now for the purely hypothetical: this is only one step away from also displaying the ...

Now for the purely hypothetical: this is only one step away from also displaying the transaction to the recipient, tricking him into thinking he received it.

The only thing standing in the way of this on the receiver end is if he is using his own full node!

What happens on a Bitcoin standard, if 80% of the merchants aren't using full nodes and are tricked into accepting fake payments like this?
PSA: There is a supply chain attack on Bitcoin wallets going on.
HARDWARE WALLETS AND SIGNAL MAY BE AFFECTED. READ FURTHER.

I have not studied the full scope of this attack yet, but from what I hear, it can impact websites/webapps (including "local" webapps like Signal Desktop) and cause them to display a thief's address instead of the intended one.

This means hardware wallets will correctly display the actual send-to address, but you the human may compare the address to one that has already been replaced!

Regardless of what wallet you use, verify the address you are sending to without trusting a computer. Call your recipient and verify verbally.