<oembed><type>rich</type><version>1.0</version><title>BTCforPlebs wrote</title><author_name>BTCforPlebs (npub1w4…4382j)</author_name><author_url>https://yabu.me/npub1w4rz7n0vunaau499xh86p84s6v5mmgys48p0nmttt7w36takc9dsf4382j</author_url><provider_name>njump</provider_name><provider_url>https://yabu.me</provider_url><html>Foot-gun = no fun.&#xA;&#xA;I ran a small Cashu mint for 1 year. Yesterday I found it empty. About 1.5M sats gone, and only around 247k had ever been put in.&#xA;&#xA;Nobody broke into my server. Nobody touched my node. I did this to myself.&#xA;&#xA;The setup file that comes with the software has a line that says, in plain words, &#34;put a random key here.&#34; It even tells you the command to make one. I did not run the command. I pasted the instruction itself in as my key and hit go.&#xA;&#xA;It started up fine. That was the problem. For months my mint&#39;s secret key was a sentence that anyone who has ever opened that setup file has seen. Eventually somebody noticed, used it to print themselves fake money from my mint, and cashed it out.&#xA;&#xA;I was stupid twice.&#xA;&#xA;Once, because I never read the one line you are supposed to read twice.&#xA;Twice, because I saw it start and took that as &#34;it&#39;s safe.&#34; &#xA;&#xA;Nutshell software does refuse to start on a couple of obviously fake keys. It just does not refuse its own example. Should it? Yes, and I have sent them a fix. &#xA;Should I have checked instead of assuming? Also yes. &#xA;&#xA;If I never looked at what the guard rail was, I do not get to blame the guard rail.&#xA;The mint is off for good.&#xA;&#xA;Open source is retards helping retards. This week I was the retard. So here is my turn helping: a fix and a warning. I still believe in this stuff.  The bug that got me was in a file I could open, read, fix, and send back the same day. That is the whole point.&#xA;&#xA;nostr:npub12rv5lskctqxxs2c8rf2zlzc7xx3qpvzs3w4etgemauy9thegr43sf485vg </html></oembed>