PSA: Many Insecure Banano Vault Seeds Have Been Compromised
After the Banano Vault web-wallet was shut down, the Banano team was helping various users recover/transfer their funds from Vault to the TheBananoStand web-wallet which is actively maintained.
It was discovered that multiple users had used insecure seeds for Vault — e.g. using a ban address as the seed, which is completely insecure and exploitable by anyone to gain full access to the wallet. Vault did not have sufficient validation checks to prevent this (while other Banano wallets such as Kalium and TheBananoStand do).
As a result a number of users have had their wallets compromised and Banano taken.
All details here:
https://banano.cc/blog/psa-many-insecure-banano-vault-seeds-have-been-compromised
Mirrors:
https://medium.com/banano/psa-many-insecure-banano-vault-seeds-have-been-compromised-d2b8a6152f25
https://www.publish0x.com/banano/psa-many-insecure-banano-vault-seeds-have-been-compromised-xjdyjlg?a=QJ0dNjvdLO