# "private key" (compromised OR stolen OR leaked) — X 热门讨论 (2026-09-26 15:42 UTC)

## @ThatzXavi3rr (Xavi3r 🪼) · 09-26 14:58 · ♥78 ↻3 💬3 Minima disclosed a security incident from earlier this year,

and there’s a detail in the way they reported it that caught my attention

the Q3 update included something most projects would probably rather not talk about:

a security incident affecting the Minima Web Wallet in May

the Web Wallet is an application built on top of the Minima network

its hosting environment was compromised through a malicious backup,

and an attacker captured private key information belonging to users who logged in between March 20 and May 8

funds were subsequently withdrawn from some affected wallets

the important distinction here is that the Minima blockchain itself was not compromised

this was an attack on the wallet application’s hosting environment, not the underlying protocol

once the incident was detected, the attacker’s access was revoked.

affected users were contacted and given guidance for remediation.

the compromised server was completely decommissioned and replaced,

while the underlying wallet infrastructure was also retired in favour of a new architecture

i want to be clear about what happened

this was a real security incident that affected real users

that’s serious, and replacing the infrastructure doesn’t undo the impact on people who were affected

but there’s another part of the update worth paying attention to

Minima didn’t leave the incident out of the quarterly report

it was included publicly under a section called “Challenges and Lessons”,

with a direct explanation of what happened and what was changed afterward.

no attempt to suggest the blockchain itself had been compromised

no vague description of an industry wide incident

what was described was just:

this is what happened this is what was affected this is what we did about it this is what we’re changing

and that’s the part i found worth noting

transparency after a security incident doesn’t make the incident less serious

but documenting the failure clearly and explaining the remediation gives users and developers something concrete to evaluate

the infrastructure is now built differently from the system that was compromised

that doesn’t erase what happened

but it’s the kind of lesson that matters when you’re building infrastructure people are expected to trust https://x.com/ThatzXavi3rr/status/2103861784624963809