error – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Wed, 20 Aug 2025 10:43:40 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.8 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 error – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 Microsoft fixes Windows upgrades failing with 0x8007007F error https://earlybirdsinvest.com/microsoft-fixes-windows-upgrades-failing-with-0x8007007f-error/ https://earlybirdsinvest.com/microsoft-fixes-windows-upgrades-failing-with-0x8007007f-error/#respond Wed, 20 Aug 2025 10:43:39 +0000 https://earlybirdsinvest.com/microsoft-fixes-windows-upgrades-failing-with-0x8007007f-error/

Windows

Microsoft has resolved a known issue that caused Windows upgrades to fail with 0x8007007F errors on some Windows 11 and Windows Server systems.

Although this issue impacts both Windows client and server platforms under specific upgrade paths, it will not affect customers attempting to upgrade their devices to Windows 11 24H2 and Windows Server 2025, the latest Windows versions.

“Starting August 12, 2025, some Windows upgrades might fail with error code ‘0x8007007F’ when performed via ‘Windows Setup > Upgrade’ installation,” the company noted in a new entry on the Windows release health dashboard.

The list of upgrade paths impacted by this bug includes:

  • Upgrades from Windows 10 1809, Windows 10 21H2, and Windows 10 22H2 to Windows 11, versions 23H2 and 22H2
  • Upgrades from Windows Server 2016 to Windows Server 2019 or Windows Server 2022
  • Upgrades from Windows Server 2019 to Windows Server 2022

While the company didn’t share what was causing these upgrade problems, Redmond says the bug triggering them is now fixed.

Users who experienced issues while trying to upgrade their systems are now advised to retry the upgrade process.

“This issue was resolved as of August 15, 2025. Devices upgraded after this date should no longer encounter this error. If you do experience error ‘0x8007007F’, retrying the upgrade process will typically resolve the issue,” Redmond added.

This week, Microsoft has also released emergency out-of-band updates to address a bug that caused Windows reset and recovery to fail after installing the August 2025 security updates.

Additionally, Microsoft rolled out a Known Issue Rollback (KIR) fix last week for a bug that triggers Windows update failures when installed from a network share using the Windows Update Standalone Installer (WUSA).

​The company also resolved a separate issue triggered by the installation of the KB5063878 update, which caused the August 2025 security updates to fail with 0x80240069 errors on Windows 11 24H2 systems when delivered via Windows Server Update Services (WSUS).

Picus Blue Report 2025

46% of environments had passwords cracked, nearly doubling from 25% last year.

Get the Picus Blue Report 2025 now for a comprehensive look at more findings on prevention, detection, and data exfiltration trends.

]]>
https://earlybirdsinvest.com/microsoft-fixes-windows-upgrades-failing-with-0x8007007f-error/feed/ 0 54171
Court Error Seals $250,000 Crypto Fraud Tied to Trump Allies and MoonPay https://earlybirdsinvest.com/court-error-seals-250000-crypto-fraud-tied-to-trump-allies-and-moonpay/ https://earlybirdsinvest.com/court-error-seals-250000-crypto-fraud-tied-to-trump-allies-and-moonpay/#respond Wed, 23 Jul 2025 16:47:36 +0000 https://earlybirdsinvest.com/court-error-seals-250000-crypto-fraud-tied-to-trump-allies-and-moonpay/

A federal fraud case involving a cryptocurrency scam, and connected to figures close to US President Donald Trump and MoonPay, was briefly hidden from public view.

Interim US Attorney Jeanine Pirro said this happened because of a mistake made by court staff, not because prosecutors requested it.

Speaking to NOTUS on July 22, Pirro explained that the court “made a ministerial, clerical error” and that the entire docket was unsealed within hours after the issue was noticed.

How to Use Crypto? 5 Rewarding Strategies Explained (Animated)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

She also said court officials admitted the Department of Justice never asked for the case to be sealed in full.

The case involves a Nigerian national accused of stealing $250,000 by pretending to be Steve Witkoff, a real estate developer who served as co-chair of the Trump-Vance Inaugural Committee.

The scam began on 2024 Christmas Eve when the suspect used an email address that looked nearly identical to a legitimate one. The attacker swapped a lowercase “i” for a lowercase “l” in the domain name. The victims were tricked into sending 250,300 USDT
USDT


$1.00

/ETH
ETH


$3,602.45

on December 26, 2024.

The victims appear to include top executives at MoonPay, a crypto company connected to President Trump’s business interests, according to a NOTUS report.

The complaint included only two first names, “Ivan” and “Mouna”, from partially hidden email addresses. These match the names of MoonPay’s CEO Ivan Soto-Wright and CFO Mouna Ammari Siala. One of the wallet addresses involved is also tied to Soto-Wright.

Pirro said that prosecutors had requested to seal only the original complaint and replace it with an updated version that removed the name of one company.

Meanwhile, US authorities have officially closed their investigation into Jesse Powell, the co-founder of Kraken



$579.98M

. What did Powell say? Read the full story.

Having completed a Master’s degree in Economics, Politics, and Cultures of the East Asia region, Aaron has written scientific papers analyzing the differences between Western and Collective forms of capitalism in the post-World War II era.
With close to a decade of experience in the FinTech industry, Aaron understands all of the biggest issues and struggles that crypto enthusiasts face. He’s a passionate analyst who is concerned with data-driven and fact-based content, as well as that which speaks to both Web3 natives and industry newcomers.
Aaron is the go-to person for everything and anything related to digital currencies. With a huge passion for blockchain & Web3 education, Aaron strives to transform the space as we know it, and make it more approachable to complete beginners.
Aaron has been quoted by multiple established outlets, and is a published author himself. Even during his free time, he enjoys researching the market trends, and looking for the next supernova.


]]>
https://earlybirdsinvest.com/court-error-seals-250000-crypto-fraud-tied-to-trump-allies-and-moonpay/feed/ 0 49238
Coinbase fixes 2FA log error making people think they were hacked https://earlybirdsinvest.com/coinbase-fixes-2fa-log-error-making-people-think-they-were-hacked/ https://earlybirdsinvest.com/coinbase-fixes-2fa-log-error-making-people-think-they-were-hacked/#respond Mon, 28 Apr 2025 06:40:10 +0000 https://earlybirdsinvest.com/coinbase-fixes-2fa-log-error-making-people-think-they-were-hacked/

Coinbase

Coinbase has fixed a confusing bug in its account activity logs that caused users to think their credentials were compromised.

As BleepingComputer first reported earlier this month, Coinbase had mistakenly labeled failed login attempts with incorrect passwords as two-factor authentication failures in the Account Activity logs.

When a threat actor attempted to access someone’s account and used the wrong password, error messages stating “second_factor_failure” or “2-step verification failed” would be shown instead.

These entries imply that a valid username and password were entered, but the login was blocked by 2-factor authentication, such as entering the wrong one-time passcode from an authenticator app.

Numerous Coinbase users contacted BleepingComputer with concerns that Coinbase had been breached, as their passwords were unique to the site, there was no sign of malware, and no other accounts were affected.

Incorrect 2FA error message in Coinbase Account Activity logs
Incorrect 2FA error message in Coinbase Account Activity logs

However, Coinbase confirmed to BleepingComputer that its logging system was incorrectly attributing login attempts with incorrect passwords as “2FA failures,” even though the attackers had not successfully reached the 2FA stage.

Coinbase has now pushed an update to fix this incorrect labeling so that “Password attempt failed” logs are shown in Account Activity instead.

Bugs like this are essential to fix as they cause unnecessary panic, with users telling BleepingComputer that they had reset all their passwords and spent hours trying to determine if their devices were compromised due to this bug.

These mislabeled entries could have also been used in social engineering attacks to convince users their account credentials were compromised, potentially allowing threat actors to gain sensitive information.

Threat actors commonly target Coinbase customers in social engineering attacks to access their accounts and drain the stored cryptocurrency.

BleepingComputer was told that threat actors used these mislabeled error messages as part of such attacks, but could not independently verify if that was true.

However, ongoing campaigns use automated SMS phishing (smishing) attacks and voice calls to impersonate Coinbase and attempt to steal 2FA tokens or credentials, so all users should be wary.

Coinbase has said in the past that they will never call customers or send text messages requesting they change passwords or reset two-factor authentication, and that customers should treat all such messages as scams.

]]>
https://earlybirdsinvest.com/coinbase-fixes-2fa-log-error-making-people-think-they-were-hacked/feed/ 0 33214
7,605 Bank Customers Receive Urgent Data Breach Alerts After ‘Administrative Error’ Exposes Social Security Numbers, Names and Account Details https://earlybirdsinvest.com/7605-bank-customers-receive-urgent-data-breach-alerts-after-administrative-error-exposes-social-security-numbers-names-and-account-details/ https://earlybirdsinvest.com/7605-bank-customers-receive-urgent-data-breach-alerts-after-administrative-error-exposes-social-security-numbers-names-and-account-details/#respond Sat, 26 Apr 2025 01:39:41 +0000 https://earlybirdsinvest.com/7605-bank-customers-receive-urgent-data-breach-alerts-after-administrative-error-exposes-social-security-numbers-names-and-account-details/

A US bank is warning thousands of customers that their sensitive information may be at risk following an “administrative error.”

In a new filing with the Office of the Maine Attorney General, Bluestone Bank says an error in late February led to the unauthorized disclosure of personal data belonging to 7,605 customers.

According to the Bridgewater, Massachusetts-headquartered bank, personal and confidential information belonging to its customers was inadvertently sent to an unintended recipient on February 28th of this year.

“The personal information that may have been accessed includes the data we have on file for you, such as your name, address, social security number, and account number(s).”

Bluestone Bank says it has taken various steps to minimize the risk of potential harm to customers.

“The individual who received the information has signed a Certificate of Destruction, confirming that all information was promptly and securely destroyed and no information was retained…

We have further addressed this incident by reinforcing proper data handling procedures and mandating retraining on the appropriate management of customer data. In addition, we have evaluated and enhanced our existing protocols and controls to ensure this will not happen again.”

To prevent possible misuse of personal information following the incident, Bluestone Bank is offering its customers a complimentary membership to an identity-monitoring service for one and a half years.

Customers also have the choice of closing and reopening their bank accounts as a safety precaution.

Bluestone Bank had $1.5 billion in total assets as of November of 2024.

Follow us on X, Facebook and Telegram

Don’t Miss a Beat – Subscribe to get email alerts delivered directly to your inbox

Check Price Action

Surf The Daily Hodl Mix

&nbsp

Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any losses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any cryptocurrencies or digital assets, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing.

Generated Image: Midjourney

]]>
https://earlybirdsinvest.com/7605-bank-customers-receive-urgent-data-breach-alerts-after-administrative-error-exposes-social-security-numbers-names-and-account-details/feed/ 0 32854
Error creating RPC request: Required script-verify-flag-failed (invalid schnorr signature) https://earlybirdsinvest.com/error-creating-rpc-request-required-script-verify-flag-failed-invalid-schnorr-signature/ https://earlybirdsinvest.com/error-creating-rpc-request-required-script-verify-flag-failed-invalid-schnorr-signature/#respond Tue, 15 Apr 2025 15:21:26 +0000 https://earlybirdsinvest.com/error-creating-rpc-request-required-script-verify-flag-failed-invalid-schnorr-signature/

I have 3 Taproot addresses: one is 50 btc, one is RECEPIENT, and the other is for change

sender bcrt1p7d90fjh4k2uu7jjzw6hev8nnak2cultvcyjaj5zum696eqpwfausw79xuk
wif cULydXkHkv3h1jH7yVaGcNCvWHzbVsDiAxW76Mc8QrSqzNPU2sUG
recipient bcrt1p725t652m53g7j87n2ypm3x9pdl9f88c4c2hjyvymq78qhrc6tpsq5wp62r
change bcrt1pj5fle7sshyr04yershteu745zs2peguum7z575rydshtscmdjysq4eus02

I’m trying to send one BTC and create a raw transaction for the spend type of keypath

This is at the sender’s hands:

(
    {
        "txid": "6ee6185784989263847ebd3d2aadb83bdbe80ed0011821085975226ae994e259",
        "vout": 0,
        "address": "bcrt1p7d90fjh4k2uu7jjzw6hev8nnak2cultvcyjaj5zum696eqpwfausw79xuk",
        "label": "",
        "scriptPubKey": "5120f34af4caf5b2b9cf4a4276af961e73ed958e7d6cc125d9505cde8bac802e4f79",
        "amount": 50,
        "confirmations": 101,
        "spendable": true,
        "solvable": true,
        "desc": "rawtr(f34af4caf5b2b9cf4a4276af961e73ed958e7d6cc125d9505cde8bac802e4f79)#qrffuhzp",
        "parent_descs": (
            "addr(bcrt1p7d90fjh4k2uu7jjzw6hev8nnak2cultvcyjaj5zum696eqpwfausw79xuk)#cx2kp4mn"
        ),
        "safe": true
    }
)
  1. Create a transaction object
     (CREATE TRANSACTION START)
    -- Amount to send (sats): 100000000
    -- Fee (sats): 1000000
    -- Get UTXO id for pay: 6ee6185784989263847ebd3d2aadb83bdbe80ed0011821085975226ae994e259
    -- Reversed UTXO id: 59e294e96a22755908211801d00ee8db3bb8ad2a3dbd7e84639298845718e66e
    -- Full generated tx: {
        "version":2,
        "inputs":
            ({
                "txid":"59e294e96a22755908211801d00ee8db3bb8ad2a3dbd7e84639298845718e66e",
                "vout":0,
                "scriptSig":"",
                "sequence":4294967295
            }),
        "outputs":({
                "value":100000000,
                "scriptPubKey":"51209545ea8add228f48fe9a881dc4c50b7e549cf8ae15791184d83c705c78d2c300"
            },{
                "value":4899000000,
                "scriptPubKey":"5120a89fe7d085c837d4991c2ebcf3d5a0a0a0e51ce6fc2a7a83236175c31b6c8900"
            }),
        "locktime":0}
    (CREATE TRANSACTION END)
  1. Sign and Serialization
(SIGN AND SERIALIZE TRANSACTION START)
(INPUT 0)
-- txid (32 bytes): 59e294e96a22755908211801d00ee8db3bb8ad2a3dbd7e84639298845718e66e
-- Vout (4 bytes LE32): 00000000
-- ScriptSigLength (1 bytes Compact size): 00
-- ScriptSig (0 bytes):
-- Sequence (4 bytes LE32): ffffffff
-- (SIGHASH FOR 0 INPUT START)
---- Version (4 bytes LE32): 02000000
---- LockTime (4 bytes LE32): 00000000
---- InputIdx (4 bytes LE32): 00000000
---- SighashTypeBuf (1 bytes): 00
---- (HASH PREVOUTS (txid + LE32(vout)) START)
------ Prevout for 0 input (36 bytes): 59e294e96a22755908211801d00ee8db3bb8ad2a3dbd7e84639298845718e66e00000000
---- (HASH PREVOUTS END)
---- Finally hashPrevouts (32 bytes): 35bb28a690e32f668589a79a1b4f7ba82c00c08fe39b29672e861e90526991a9
---- (HASH AMOUNTS (LE64(amount))) START)
------ Amount for 0 input (8 bytes LE64): 3200000000000000
---- (HASH AMOUNTS END)
---- Finally hashAmounts (32 bytes): 0cbbab9d99fb661a1686f17ccaaf8a9d069aa8cb755925045a1d049c060b9e67
---- (HASH SCRIPT PUB KEYS (OP_1 + PUSH_32 + pubKeyHash) START)
------ ScriptPubKey for 0 input (34 bytes): 51209a57a657ad95ce7a5213b57cb0f39f6cac73eb66092eca82e6f45d6401727bc8
---- (HASH SCRIPT PUB KEYS END)
---- Finally hashScriptPubKeys (32 bytes): 96d403e277844293f22ba2b1914d646d8353adbe2c49a22a7f421a8c97221eaa
---- (HASH SEQUENCES (LE32(sequence)) START)
------ Sequence for 0 input (4 bytes LE32): ffffffff
---- (HASH SEQUENCES END)
---- Finally hashSequences (32 bytes): ad95131bc0b799c0b1af477fb14fcf26a6a9f76079e48bf090acb7e8367bfd0e
---- (HASH OUTPUTS (LE64(amount), CompactSize(size), scriptPubKey) START)
------ Amount of 0 out (8 bytes LE64): 00e1f50500000000
------ ScriptPubKey of 0 out (34 bytes): 51209545ea8add228f48fe9a881dc4c50b7e549cf8ae15791184d83c705c78d2c300
------ Size of 0 out (1 bytes CompactSize): 22
------ Output of 0 out (43 bytes): 00e1f505000000002251209545ea8add228f48fe9a881dc4c50b7e549cf8ae15791184d83c705c78d2c300
------ Amount of 1 out (8 bytes LE64): c0ce002401000000
------ ScriptPubKey of 1 out (34 bytes): 5120a89fe7d085c837d4991c2ebcf3d5a0a0a0e51ce6fc2a7a83236175c31b6c8900
------ Size of 1 out (1 bytes CompactSize): 22
------ Output of 1 out (43 bytes): c0ce002401000000225120a89fe7d085c837d4991c2ebcf3d5a0a0a0e51ce6fc2a7a83236175c31b6c8900
---- (HASH OUTPUTS END)
---- Finally hashOutputs (32 bytes): c74c74b357372c390436f57e6046707b88dc74a7199e9194922818188192de44
---- Preimage (174 bytes): 02000000000000000035bb28a690e32f668589a79a1b4f7ba82c00c08fe39b29672e861e90526991a90cbbab9d99fb661a1686f17ccaaf8a9d069aa8cb755925045a1d049c060b9e6796d403e277844293f22ba2b1914d646d8353adbe2c49a22a7f421a8c97221eaaad95131bc0b799c0b1af477fb14fcf26a6a9f76079e48bf090acb7e8367bfd0ec74c74b357372c390436f57e6046707b88dc74a7199e9194922818188192de440000000000
---- TaggedHash (32 bytes): 7f73f0e9137223806b5c6c4f157f30ed439949decb84b4ab1eff249fa61692c1
-- (SIGHASH FOR 0 INPUT END)
-- Sighash (32 bytes): 7f73f0e9137223806b5c6c4f157f30ed439949decb84b4ab1eff249fa61692c1
-- SignatureObject (64 bytes): 4227542a9daebfbf518e12b016f09f5f7feaae42bdf5874039dfd1ff7ec66b63b625e27be13a04b3d58c81891aca8908cd5ca548cfc3f080fd2d0bcfc0045138
-- Pubkey (32 bytes): f34af4caf5b2b9cf4a4276af961e73ed958e7d6cc125d9505cde8bac802e4f79
-- VALID? true
-- Witness count for 0 input (1 bytes Compact Size): 01
-- Signature len for 0 input (1 bytes Compact Size): 40
-- Signature for 0 input (64 bytes): 4227542a9daebfbf518e12b016f09f5f7feaae42bdf5874039dfd1ff7ec66b63b625e27be13a04b3d58c81891aca8908cd5ca548cfc3f080fd2d0bcfc0045138
(OUTPUT 0)
-- Value (8 bytes LE64): 00e1f50500000000
-- ScriptPubKey (34 bytes): 51209545ea8add228f48fe9a881dc4c50b7e549cf8ae15791184d83c705c78d2c300
-- ScriptPubKeySize (1 bytes Compact size): 22
(OUTPUT 1)
-- Value (8 bytes LE64): c0ce002401000000
-- ScriptPubKey (34 bytes): 5120a89fe7d085c837d4991c2ebcf3d5a0a0a0e51ce6fc2a7a83236175c31b6c8900
-- ScriptPubKeySize (1 bytes Compact size): 22
Locktime (4 bytes LE32): 00000000
Marker (1 bytes): 00
Flag (1 bytes): 01
Version (4 bytes LE32): 02000000
InputsLen (1 bytes Compact Size): 01
OutputsLen (1 bytes Compact Size): 02
Finally rawTx (205 bytes): 0200000000010159e294e96a22755908211801d00ee8db3bb8ad2a3dbd7e84639298845718e66e0000000000ffffffff0200e1f505000000002251209545ea8add228f48fe9a881dc4c50b7e549cf8ae15791184d83c705c78d2c300c0ce002401000000225120a89fe7d085c837d4991c2ebcf3d5a0a0a0e51ce6fc2a7a83236175c31b6c89000140eddd2049ece47dd2fea1fb2e5f9d0c475e32431a472c64d543160097359f266f13c3a409de8366d09b105741ecaee1cfac6542ed1e084cee58310d82da28775000000000
(SIGN AND SERIALIZE TRANSACTION END)

And in the end I got

Error creating RPC request: Required script-verify-flag-failed (invalid schnorr signature)

However, the transaction structure is valid, it is both a signature and a witness.

{
  "version": "02000000",
  "marker": "00",
  "flag": "01",
  "inputcount": "01",
  "inputs": (
    {
      "txid": "59e294e96a22755908211801d00ee8db3bb8ad2a3dbd7e84639298845718e66e",
      "vout": "00000000",
      "scriptsigsize": "00",
      "scriptsig": "",
      "sequence": "ffffffff"
    }
  ),
  "outputcount": "02",
  "outputs": (
    {
      "amount": "00e1f50500000000",
      "scriptpubkeysize": "22",
      "scriptpubkey": "51209545ea8add228f48fe9a881dc4c50b7e549cf8ae15791184d83c705c78d2c300"
    },
    {
      "amount": "c0ce002401000000",
      "scriptpubkeysize": "22",
      "scriptpubkey": "5120a89fe7d085c837d4991c2ebcf3d5a0a0a0e51ce6fc2a7a83236175c31b6c8900"
    }
  ),
  "witness": (
    {
      "stackitems": "01",
      "0": {
        "size": "40",
        "item": "4227542a9daebfbf518e12b016f09f5f7feaae42bdf5874039dfd1ff7ec66b63b625e27be13a04b3d58c81891aca8908cd5ca548cfc3f080fd2d0bcfc0045138"
      }
    }
  ),
  "locktime": "00000000"
}

Please help. Could there be something wrong with your bytes, data, or order? thank you very much!

]]>
https://earlybirdsinvest.com/error-creating-rpc-request-required-script-verify-flag-failed-invalid-schnorr-signature/feed/ 0 30941
ChatGPT is down worldwide with something went wrong error https://earlybirdsinvest.com/chatgpt-is-down-worldwide-with-something-went-wrong-error/ https://earlybirdsinvest.com/chatgpt-is-down-worldwide-with-something-went-wrong-error/#respond Wed, 02 Apr 2025 15:29:47 +0000 https://earlybirdsinvest.com/chatgpt-is-down-worldwide-with-something-went-wrong-error/

ChatGPT

ChatGPT isn’t working for millions of users worldwide. While it’s able to respond to the first message in a conversation, it doesn’t work when you follow up or respond to ChatGPT.

You’ll run into “Something went wrong while generating the response. If this issue persists please contact us through our help center at help.openai.com.” error message when you try to chat with the AI.

GPT is down
ChatGPT is showing errors
Source: BleepingComputer

If you click the Retry button, ChatGPT will recommend you refresh the page, but the error will not go away even after reloading the page.

According to DownDetector, this outage started within the last 30 minutes.

ChatGPT is currently experiencing an outage in the U.S, Europe, India, Japan, Australia, and other parts of the world.

In an update to its support document, OpenAI confirmed it’s aware of the reports and is working on a mitigation.

“We have identified that users are experiencing elevated errors for the impacted services. We are working on implementing a mitigation,” OpenAI noted.

This is a developing story…

Red Report 2025

Based on an analysis of 14M malicious actions, discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them.

]]>
https://earlybirdsinvest.com/chatgpt-is-down-worldwide-with-something-went-wrong-error/feed/ 0 28610
BECH32 Error Detection and Correct Reference Implementation https://earlybirdsinvest.com/bech32-error-detection-and-correct-reference-implementation/ https://earlybirdsinvest.com/bech32-error-detection-and-correct-reference-implementation/#respond Thu, 27 Mar 2025 02:00:20 +0000 https://earlybirdsinvest.com/bech32-error-detection-and-correct-reference-implementation/

BECH32 detects up to 4 errors (in the sense that creating up to 4 replacement errors guarantees that the resulting string has an incorrect checksum). However, error detection is not the same as error Positioning: Just knowing that BECH32 is wrong does not mean you can’t know where the error was made.

Bech32 is also allowed Correction Up to 2 replacement errors. This means that if you know that no more than two replacement errors have been created, you can calculate what the original valid string was for a given string. The JavaScript code on the website you link to has the code to do this, but for safety reasons it will not be revealed intentionally what Errors discovered, where.

The reason is that corrections are dangerous. If the user creates two or more replacement errors, the error correction algorithm may still find two errors to “fix” in the sense that it constructs a valid address, but It is not the user’s address. Inadvertent users may make corrections suggested by the algorithm and send funds to void. Instead, the correction algorithm is still used under the hood, but only the location of the error is revealed, forcing the user to check if it is the primary resource that received the address, but perhaps forces the algorithm to focus specifically on the specific location where the location error is likely to have occurred.

]]>
https://earlybirdsinvest.com/bech32-error-detection-and-correct-reference-implementation/feed/ 0 27413
Lightning Labs CTO: Security Scare Is User Error, Not a Software Flaw https://earlybirdsinvest.com/lightning-labs-cto-security-scare-is-user-error-not-a-software-flaw/ https://earlybirdsinvest.com/lightning-labs-cto-security-scare-is-user-error-not-a-software-flaw/#respond Sun, 23 Feb 2025 04:49:10 +0000 https://earlybirdsinvest.com/lightning-labs-cto-security-scare-is-user-error-not-a-software-flaw/

A recent security issue in the Lightning Network has raised concerns, but Lightning Labs’ Chief Technology Officer (CTO) Olaoluwa Osuntokun has suggested the problem is not with the software itself.

Instead, according to Osuntokum’s post on X, he pointed to a compromised user device as the likely cause.

The Lightning Network, a layer-2 solution designed to make Bitcoin
BTC


$96,420.21

transactions faster and cheaper, currently holds about 5,145 BTC, valued at approximately $500 million.

What is Defi 2.0? (Explained with Animations)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

In a February 19 post on X, Satoshi Labs co-founder Pavol Rusnak issued a warning about vulnerabilities in older versions of Lightning Network Daemon (LND) and Lightning Terminal.

He urged users to update immediately, stating that attackers exploited flaws patched in newer releases. His message specifically mentioned LND versions older than 0.18.5 and Lightning Terminal versions before 0.14.1.

Osuntokun responded, stating that the issue did not appear to be a direct flaw in LND. He explained that the affected user’s machine had been compromised, which may have allowed attackers to gain access to their funds.

This warning comes after another security issue was flagged on GitHub on February 13. A report highlighted a weakness in the ECDSA (Elliptic Curve Digital Signature Algorithm) used for Bitcoin transactions. The concern was that a flaw in the elliptic library, a JavaScript package used in cryptography, could expose private keys if numbers used once or “nonces” were reused.

Meanwhile, Microsoft recently issued a warning about an updated XCSSET malware. What kind of damage could it cause? Read the full story.

Having completed a Master’s degree in Economics, Politics, and Cultures of the East Asia region, Aaron has written scientific papers analyzing the differences between Western and Collective forms of capitalism in the post-World War II era.
With close to a decade of experience in the FinTech industry, Aaron understands all of the biggest issues and struggles that crypto enthusiasts face. He’s a passionate analyst who is concerned with data-driven and fact-based content, as well as that which speaks to both Web3 natives and industry newcomers.
Aaron is the go-to person for everything and anything related to digital currencies. With a huge passion for blockchain & Web3 education, Aaron strives to transform the space as we know it, and make it more approachable to complete beginners.
Aaron has been quoted by multiple established outlets, and is a published author himself. Even during his free time, he enjoys researching the market trends, and looking for the next supernova.


]]>
https://earlybirdsinvest.com/lightning-labs-cto-security-scare-is-user-error-not-a-software-flaw/feed/ 0 21292
Mandatory script-verify-flag-failed (invalid schnorr signature) error when creating child inscriptions in Taproot transactions https://earlybirdsinvest.com/mandatory-script-verify-flag-failed-invalid-schnorr-signature-error-when-creating-child-inscriptions-in-taproot-transactions/ https://earlybirdsinvest.com/mandatory-script-verify-flag-failed-invalid-schnorr-signature-error-when-creating-child-inscriptions-in-taproot-transactions/#respond Sun, 09 Feb 2025 10:45:01 +0000 https://earlybirdsinvest.com/mandatory-script-verify-flag-failed-invalid-schnorr-signature-error-when-creating-child-inscriptions-in-taproot-transactions/

I’m trying to create a child inscription in a Taproot transaction, but I’m running into the following error:

sendrawtransaction RPC error: {"code":-26,"message":"mandatory-script-verify-flag-failed (Invalid Schnorr signature)"}

I checked all the data, including transaction structure, signatures, TapRoot scripts, and more, but the error persists.

The input refers to the parent UTXO.

{
  "txid": "02cde20c6db772c9ddced410c52cb2bdcbf476016fa398cfa1ac5207f1ff462f",
  "vout": 0,
  "value": 546,
  "scriptPk": "5120932a0391d2ec13cb8f303ded9297ece089f739b3ced40bc98eebdd277fdb9c9d",
  "address": "tb1pjv4q8ywjasfuhres8hke99lvuzylwwdnem2qhjvwa0wjwl7mnjwsdqu3e0"
}

The output sends 546 Satoshis to the recipient address. The Taproot script for the child’s inscription includes:

Parent inscription data (InscriptionID). Child inscription metadata.

const childOrdinalStacks = (
  publicKey,
  bitcoin.opcodes.OP_CHECKSIG,
  bitcoin.opcodes.OP_FALSE,
  bitcoin.opcodes.OP_IF,
  Buffer.from("ord", "utf8"),
  1, 1,
  Buffer.from("text/plain;charset=utf-8", "utf8"),
  1, 2,
  pointerBuffer1,
  1, 3,
  Buffer.from(parentInscriptionId, "hex"),
  1, 5,
  cbor.encode(childMetadata),
  1, 7,
  Buffer.from("parcel.bitmap", "utf8"),
  bitcoin.opcodes.OP_0,
);

RAW TX Hash

020000000001022f46fff10752aca1cf98a36f0176f4cbbdb22cc510d4ceddc972b76d0ce2cd020000000000ffffffffc14499f6058bc6c6d5eed11c699c80007199690c12bee4a54fd46d5a9f5193e00100000000ffffffff022202000000000000225120932a0391d2ec13cb8f303ded9297ece089f739b3ced40bc98eebdd277fdb9c9d2202000000000000225120932a0391d2ec13cb8f303ded9297ece089f739b3ced40bc98eebdd277fdb9c9d01406fcbc5b6b63cb67c2289a5b4df1f3e1971b26ad4310b644da9a5a8488247f6ae44b50d7be59eecd8c58a268ce74eeb490b31bfda28cfeee6c101a914b54d613e03400058e04b9c6438f33f9a3541fe8d2a5c229794a00eb6c005aaedeb1b4622ca9c0c902d714b550e0b352578c761ac3853a5766078d7cded283f15070ef53b6c1ee8206705021108c86f6f7249e85d233414afa8eeaadaea2bad863b2ccce504126879ac0063036f7264010118746578742f706c61696e3b636861727365743d7574662d3801020222020103202f46fff10752aca1cf98a36f0176f4cbbdb22cc510d4ceddc972b76d0ce2cd02010528a264747970656b54657374204e46542023316b6465736372697074696f6e6954657374205465737401070d70617263656c2e6269746d6170003f68747470733a2f2f617277656176652e6e65742f4933326c517668673341514c583444632d334e48557773434e366e75382d6c78477352634e7765336372346821c06705021108c86f6f7249e85d233414afa8eeaadaea2bad863b2ccce50412687900000000

I’m using Tweaksigner to sign the input.

const signer = tweakSigner(wallet);
psbt.signInput(0, signer);
psbt.signInput(1, wallet.keyPair);


export function tweakSigner(wallet: Wallet, opts: any = {}) {
  let privateKey: any = wallet.keyPair.privateKey;
  if (!privateKey) {
    throw new Error('Private key is required for tweaking signer!');
  }
  if (wallet.keyPair.publicKey(0) === 3) {
    privateKey = ecc.privateNegate(privateKey);
  }
  const tweakedPrivateKey = ecc.privateAdd(privateKey, tapTweakHash(wallet.internalPubkey, opts.tweakHash));
  if (!tweakedPrivateKey) {
    throw new Error('Invalid tweaked private key!');
  }
  return ECPair.fromPrivateKey(Buffer.from(tweakedPrivateKey), {
    network: wallet.network,
  });
}


function tapTweakHash(pubKey: Buffer, h: Buffer | undefined): Buffer {
  return bitcoin.crypto.taggedHash(
    "TapTweak",
    Buffer.concat(h ? (pubKey, h) : (pubKey))
  );
}

]]>
https://earlybirdsinvest.com/mandatory-script-verify-flag-failed-invalid-schnorr-signature-error-when-creating-child-inscriptions-in-taproot-transactions/feed/ 0 18392