@lorenzolfmi
iAccount based inBrazil
About this account
- Account based in
- Brazil
- Connected via
- Brazil App Store
Account-level information from X, not a live location or the device used for a specific post.
Backend @usebipa l Developer advocate @Vinteum_org PGP: 0xDFA342A5ABAC5A91
A Toca
Joined June 2014
- Tweets12.2K
- Following1.8K
- Followers6.7K
- Likes39.9K
Lorenzo retweeted
i love watching formula one because no matter how bad my day is george russell is having a worse one
All could have been avoided by not exposing admin APIs to the public internet. Very similar to what happened to BTCPayServer.
Sad :/
Full post-mortem of the September 19 attack, and a 50% bounty — up to 3.3 BTC — on the stolen funds:
blink.sv/blog/sept-19-attack…
Bounty terms:
blink.sv/bounty-terms
On Saturday September 19 an attacker used a flaw in our admin tools to take over 35 Blink accounts and withdraw about 6.61 BTC from 24 of them. A customer called one of our engineers at 11:39 UTC. Fifteen minutes later the whole custodial service was off. By that evening the hole was closed and the service was back. By Thursday September 24 every affected customer had their exact balance back, in bitcoin and in dollars, paid for by Blink's shareholders. No customer bears any loss.
This was our fault. Not Bitcoin's, not our users'. To the 22 customers whose bitcoin was taken, and to the 3,817 people whose account details were looked up: we are sorry.
How it happened:
From October 2023 until that Saturday, anyone with a free Blink account and a web browser could give themselves the powers of our support staff: change the email or phone on any account, log in as that customer, raise their limits. Three unremarkable mistakes in how our admin tools checked permissions, stacked on top of each other, in code we inherited.
The whole team was busy moving tens of thousands of users to self-custody under new regulation. Monitoring built to catch outages didn't catch an administrator doing things no administrator should.
What it didn't touch:
The money came out of our hot wallet. Most customer funds sit in multi-signature cold storage that nothing in our admin tools can reach. Non-custodial accounts were never in play: we don't hold those keys.
What the attacker saw:
They also read the details of 3,817 other accounts, in some cases a phone number or email address. Not names, not IDs, not addresses, not passwords, not seed phrases. We wrote to every holder we could reach, saying exactly what was seen.
What stopped them:
Two-factor authentication. The attacker logged in to nine accounts that had it on and tried eighteen times to move money. Zero loss.
None of the 24 drained accounts had it on. If you take one thing from this post: Settings → Security and Privacy → Two-factor authentication. Then turn it on for your email too.
What we changed:
The flaw was fixed the same day and a third layer added two days later. The admin tools are off the public internet. The functions that change a customer's email or phone are switched off for everyone while we redesign them. All customer API keys were revoked.
The hot wallet now holds a fraction of what it did. Security fixes are developed privately and published once deployed; the code stays open source. A standing security reporting channel is live, with rewards of up to 0.1 BTC for critical findings.
Where the money is:
Some still sits where it was withdrawn to. About 5 BTC has gone through a cross-chain swap service; a small amount reached an exchange that is cooperating.
Criminal complaints are filed in El Salvador and Próspera, the regulators are notified, and we have traced the funds continuously. We are not expecting the money back.
So we are putting a 50% bounty on it.
Whoever provides the information that leads to a recovery gets 25% of what is recovered. Another 25% of anything recovered goes to Bitcoin Beach, Bitcoin Ekasi, Afribit Kibera and the circular economies they choose. No cap, no end date, paid only out of funds that actually come back. Write to [email protected].
We would far rather have spent this money on grassroots Bitcoin adoption than lost it to a thief. Shame on the attacker.
One more thing:
Ignore any email or SMS about this incident that contains a link: we contacted affected users only through messages in the Blink app. We will never ask for your PIN, password, seed phrase or a login code.
The full post-mortem has the timeline, the technical detail for anyone running code derived from ours, and the bounty terms (links at the top).
don't loose the momentum guys
Replying to @4moonsettler @stutxo
BIP-448 is good to go to me. We’d like to signal for it once wider consensus is achieved.
Lorenzo retweeted
Covenants would add a heavy cost to any quantum attacker from stealing funds.
You hacked the private key? Cool, you can just send it to my precommited next address.
wen five guys
Shake Shack vai desembarcar no Brasil com plano de ao menos 40 restaurantes veja.abril.com.br/economia/s…
Galvão
🚨URGENTE! PRINCIPAIS RECADOS DO PRESIDENTE LULA AGORA!
COMPARTILHE AO MÁXIMO!
1 - “Não briguem com o eleitor. Não falem mal porque o eleitor não votou na gente. Temos que ter humildade. São 30 milhões de pessoas que não foram votar. Não surgiu terceira via. O que aconteceu então com essas pessoas? Temos que tentar convencer essas pessoas. A responsabilidade do desinteresse deles é nossa. Não temos que procurar defeito entre nós agora, temos 20 dias pra que cada um avalie o que pode fazer.”
2 - “Flávio Bolsonaro é a cara do sistema. A única candidatura antissistema é a nossa. Temos que mostrar isso pras pessoas. Estamos carregando nas nossas costas uma coisa muito grave que é a promiscuidade que se revelou no STF. Temos que discutir com a sociedade qual o critério pra indicar candidato a ministro da Suprema Corte. A hora é da sociedade discutir isso. Ninguém está acima da lei. Nem os ministros do STF.”
3 - “Está claro para toda a sociedade hoje que os estados não dão conta mais da questão da segurança pública. O crime organizado está atuando quase como uma multinacional. Hoje a Polícia Federal só pode entrar nos casos se os crimes são federalizados e muitos governadores não aceitam. Esse é um assunto que vamos ter que discutir! O estado tem que proteger o trabalhador, o bandido ir pra cadeia e o povo recuperar seu território. Os governadores precisam ajudar a aprovar a PEC da Reforma da Segurança Pública o mais rápido possível. Isso tem que ser votado já!”
🚨 ESPALHEM!!!!
Lorenzo retweeted
Meu voto é no BTC, em moedinhas virtuais, na minha LLC, em AI self hosted, no meu homelab
Meu voto é no futuro
Qual o seu voto?
Mais uma corretora fechando as portas no país. Obrigado novamente por proteger a população, BACEN.
O lado bom é que você pode migrar suas criptos direto pra Bipa com 1 clique :)
🚨Bitypreço encerra operações no Brasil e oferece migração de clientes para a Bipa
A Bitypreço tem cerca de 850 mil usuários registrados e mais de R$ 1 bilhão em ativos sob custódia.
Clientes poderão migrar seus saldos diretamente pelo aplicativo, mediante autorização.
O prazo para transferir criptomoedas sem conversão para reais termina em 27 de novembro de 2026.
Quem concluir a migração na primeira semana receberá 12 meses gratuitos de um dos planos da Bipa.
A Bipa também adicionará Solana (SOL), Ethereum (ETH), USDC e XRP à sua plataforma.
A migração é opcional. Nenhum ativo será transferido sem o consentimento do cliente.
*direita com dificuldade de ganhar votos das mulheres*
> direita: vamos banir o voto feminimo!!1!
Lula deve estar de joelhos agradecendo vcs