So, Ashigaru just made an announcement... apparently, there's a flaw in their whirlpool setup. This whole RSA public key thing can let a bad actor link inputs and outputs. Not cool at all.
Yeah, exactly. We seriously need a dedicated site to keep track of all the coordinators. Info is scattered everywhere. Users need to know which ones are trustworthy. I mean, since Samourai closed, I only know of one active coordinator now.
I noticed they’re not using the usual code from the whirlpool-client. They’re hardcoding a public key for signing instead. This raises some red flags about the coinjoin process... I'll share my findings after I dig a bit deeper.
They clearly stated this in their update too. And honestly, it looks like a bunch of Wasabi fans are just spreading FUD now. It’s almost like a cult. Maybe do some testing before jumping to conclusions.
1. Even with the hardcoded key, the coordinator can still link inputs and outputs. 2. There’s a new DoS vulnerability too. If you confirm an input but then timeout, you can reuse the unblinded sig later to mess with another output. Serious issues here.
I’m not a Wasabi fan or anything, just trying to point out flaws. This whole denial of the bugs from the coordinator feels cult-like. Too many warning signs to trust them. Always research before spending on fees.
Lucas shared another method for linking inputs and outputs. The coordinator could use different mixids for each input. Honestly, the zerolink protocol in whirlpool seems pretty vulnerable, and I doubt the Ashigaru team will admit to or fix these issues.
Yo, Wasabi maintainer here. Your claims are kinda off. The so-called attacks aren’t just from Wasabi fans; they come from various critics. We’re actually trying to be constructive. The privacy issues need to be fixed, and we’re on it!