{"type":"rich","version":"1.0","title":"BTCforPlebs wrote","author_name":"BTCforPlebs (npub1w4…4382j)","author_url":"https://yabu.me/npub1w4rz7n0vunaau499xh86p84s6v5mmgys48p0nmttt7w36takc9dsf4382j","provider_name":"njump","provider_url":"https://yabu.me","html":"Foot-gun = no fun.\n\nI ran a small Cashu mint for 1 year. Yesterday I found it empty. About 1.5M sats gone, and only around 247k had ever been put in.\n\nNobody broke into my server. Nobody touched my node. I did this to myself.\n\nThe setup file that comes with the software has a line that says, in plain words, \"put a random key here.\" It even tells you the command to make one. I did not run the command. I pasted the instruction itself in as my key and hit go.\n\nIt started up fine. That was the problem. For months my mint's secret key was a sentence that anyone who has ever opened that setup file has seen. Eventually somebody noticed, used it to print themselves fake money from my mint, and cashed it out.\n\nI was stupid twice.\n\nOnce, because I never read the one line you are supposed to read twice.\nTwice, because I saw it start and took that as \"it's safe.\" \n\nNutshell software does refuse to start on a couple of obviously fake keys. It just does not refuse its own example. Should it? Yes, and I have sent them a fix. \nShould I have checked instead of assuming? Also yes. \n\nIf I never looked at what the guard rail was, I do not get to blame the guard rail.\nThe mint is off for good.\n\nOpen source is retards helping retards. This week I was the retard. So here is my turn helping: a fix and a warning. I still believe in this stuff.  The bug that got me was in a file I could open, read, fix, and send back the same day. That is the whole point.\n\nnostr:npub12rv5lskctqxxs2c8rf2zlzc7xx3qpvzs3w4etgemauy9thegr43sf485vg "}
