8 ms·
It appears this commit actually introduced the bug the attacker exploited by adding additional flexibility for cache key confusion via scriptPubKey. https://tw
by greyface- 10d ago
It appears this commit actually introduced the bug the attacker exploited by adding additional flexibility for cache key confusion via scriptPubKey. https://twitter.com/mononautical/status/2096928595432374706 https://twitter.com/mononautical/status/2096928595432374706
The mechanism reminds me of this classic AWS request signature forgery bug from 2008: https://news.ycombinator.com/item?id=401876 https://news.ycombinator.com/item?id=401876