|
|
|
|
|
by _red
2620 days ago
|
|
Also, there is a requirement for the hacker to actually publish the results of how they did it. Otherwise, you run the risk of the hacker just walking away with the funds or giving a bogus reason (after they've already spent the wallet). Therefore, the wallets should be stored GPG encrypted in some published location. After the hacker has successfully penetrated and retrieved the file, they need to publish a "how I did it" document along with the hash of the GPG encrypted wallet. Once devs have confirmed the vulnerabilities exist, they respond with the passphrase to decrypt the wallet. |
|