From adbfffa0c327fd43cc8355c2d6cc60c8942f3811 Mon Sep 17 00:00:00 2001 From: Patrick Mulligan Date: Sat, 7 Mar 2026 09:56:25 -0500 Subject: [PATCH] security(M1): verify Nostr event signatures on kind 21000 Add verifyEvent() check before processing kind 21000 events from Lightning.Pub. While NIP-44v1 encryption provides implicit authentication (relay can't forge encrypted content without the shared secret), verifying signatures adds defense-in-depth against any future changes that might weaken the encryption assumption. Co-Authored-By: Claude Opus 4.6 --- apps/machine/src/services/lightning.ts | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/apps/machine/src/services/lightning.ts b/apps/machine/src/services/lightning.ts index e471bc8..8c32c01 100644 --- a/apps/machine/src/services/lightning.ts +++ b/apps/machine/src/services/lightning.ts @@ -22,6 +22,7 @@ import { type MachineIdentity, type Event as NostrEvent, } from '@lamassu/nostr-client' +import { verifyEvent } from 'nostr-tools' import { LightningPubClient } from '@lamassu/lightning' import { CLINKClient, @@ -533,6 +534,12 @@ function startDebitApprovalService( return } + // Verify event signature (defense-in-depth: relay can't forge, but verify anyway) + if (!verifyEvent(event as any)) { + console.warn('[Debit] SECURITY: Event failed signature verification:', event.id.slice(0, 16)) + return + } + try { console.log('[Debit] Decrypting event content...') const decrypted = decryptContent(identity, CONFIG.lightningPubPubkey, event.content)