pull down to refresh

I posted this on Nostr earlier today but thought it might be useful information for someone here...

I had been having problems with my zaps over the last few days and could not figure out why. I finally logged into Coinos (my NWC wallet) and found that the balance is zero. Looking at the history, everything went out of the wallet on Sept 12 (then I received a 21 zap and sent a 21 zap). The outgoing transaction does not show up in Alby or any other interface except for Coinos.

I kept enough Sats in there to use for zapping, but still a tough reminder that if you are using a custodial wallet, you are running a higher risk.

Coinos was able to reset the password and restore the sats.

Not clear if they reversed the transaction, or how they achieved that.

They said that there was a previous breech that exposed tokens, and my token had not been invalidated.

reply
32 sats \ 2 replies \ @Wumbo 17 Sep

When you click on the transaction do you have any data in the "Notes" Field?

reply

This is the only info I see - only other thing of note is that when I click on the profile, it shows 1 ₿ = R$612,886which maybe indicates the person is not in the US?

reply

R$ is brazilian real

reply

Thats a coinos user, report to Adam.

reply

I sent a message on the website

reply

Use the Telegram group. https://t.me/coinoswallet

reply

Let us know what ends up happening...

reply

How are you logging in on the wallet? I had same issues using passwords, then I made a new wallet using nostr pubkey to log in and never was robbed again.

reply

I use Alby to login, I don't think I ever created a password for Coinos

reply

Maybe a good idea to set up a password on your coinos account...

reply

Or use a nostr pkey to login

reply
11 sats \ 1 reply \ @ek 17 Sep

If you used login with nostr, I think your nsec might have been compromised in a previous breach iirc

I am considering to implement creating a Coinos account with one-click from within SN (like Damus does) but cases like this really makes me reconsider if we shouldn’t warn users about their previous breaches at least first

reply

well I am not totally sure but thought I used Alby from the get-go, which should mask the nsec, but maybe it is all compromised - can't say I never put the nsec into an app.

reply

I think you're account has been compromised and better to change the wallet.

reply
reply

If you're using a custodial wallet, use it in a custodial way.

reply

not sure what that means

reply

Bummer, still cheaper than running an albyhub in the cloud I suppose!