pull down to refresh

The problem was storing secret keys in a wide open database (host 0.0.0.0) with no auth. Surprized this did not happen earlier. Secret keys are only needed once to generate NWC connection strings. After that, only public keys need to be stored on the server side. Sister wallet https://coinos.pro did not suffer this attack, but nevertheless wiped all the keys and patched this vulnerability.