JAKE pfp
JAKE
@jake
QR MINI APP USERS - PLEASE READ THIS IMPORTANT UPDATE ON TODAY'S INCIDENT. SUMMARY: QR MINI APP NOTIFICATIONS WERE COMPROMISED. THEY ARE NOW SECURED. THERE ARE NO FURTHER RISKS OR ACTIONS REQUIRED. ALL LOSSES HAVE BEEN REIMBURSED IN FULL. Earlier today, our QR mini app notifications system was compromised. The system has since been secured. There will be no further damages, there are no further risks for users whether they engaged with the notifications or not, and there are no further actions required by you or any of our users. As a result of our notifications system being compromised, some users were tricked into participating in a fake airdrop where they were asked to send 0.0006 ETH in order to receive worthless tokens. There were 302 such transactions in total, all of which have now been reimbursed in full. Here is the basescan confirmation for the reimbursement: https://basescan.org/tx/0xe86129aa25785aed91b15b3549cd93ad4d86361961d5b6097f6069001c3d205b I take full responsibility for this incident and appreciate everyone's patience while we figured out what happened and how best to resolve it as quickly as possible. I want to thank the Farcaster and Neynar teams for their immediate and effective assistance in helping us to do that. Thank you also to everyone who reached out and offered their assistance. Moving forward, you should feel safe interacting with our regular once-daily notifications, and if you get any other notification that looks unusual, please check my profile or message me before interacting. As always, thank you all for your support.
33 replies
33 recasts
164 reactions

phil pfp
phil
@phil
nice work
1 reply
1 recast
8 reactions

Nick T pfp
Nick T
@nt
Great work. What exactly happened on a technical level? How did the notifications get compromised? What can other miniapp devs do to avoid this?
1 reply
0 recast
2 reactions

Ben Broad | bbroad.eth 🎩 pfp
Ben Broad | bbroad.eth 🎩
@bbroad
Great job handling the situation!
0 reply
0 recast
0 reaction

Jacque(she|her) 009/100🎥 pfp
Jacque(she|her) 009/100🎥
@jacque
First of all, thank you and that is above and beyond. I feel so sad that I fell for this kind of thing. It really truly appreciate the fact that you are taking ownership and it really shows hope. I understand for so many people this isn’t a lot of money, but for somebody who has been having to watch their finances their entire life and can’t even afford rent it means the world to have somebody like you help fix the situation that was created so again thank you. From me and all of us who may not have the voice to say.
0 reply
1 recast
9 reactions

Juny pfp
Juny
@junyboy.eth
LEGEND!!
0 reply
0 recast
1 reaction

Grif pfp
Grif
@grif
Someone vibe coded a little too close to the sun
0 reply
0 recast
0 reaction

Carl Gustaf 👨🏼‍💻 pfp
Carl Gustaf 👨🏼‍💻
@acgk.eth
Swift and great communication through out this. Will be interesting once you’ve learned how it all happened. But as I said class A communication.
0 reply
0 recast
0 reaction

eatzebugs pfp
eatzebugs
@eatzebugs
Who did the deed? @proxystudio
0 reply
0 recast
0 reaction

Kieran Daniels pfp
Kieran Daniels
@kdaniels.eth
1. Def don’t feel safe 2. Are you doing an actual post mortem? 3. How do other teams prevent this? @dylsteck.eth This was a lucky situation that the app wasn’t actually a financial app and didn’t rekt full trading balances Is this a systemic mini app vulnerability?
1 reply
0 recast
0 reaction

MetaEnd🎩 pfp
MetaEnd🎩
@metaend.eth
But how?
0 reply
0 recast
0 reaction

Megabased.base.eth pfp
Megabased.base.eth
@maro95
Luckily, Farcaster is safe it could have gone differently. Even the $3 are nothing compared to what could have happened
0 reply
0 recast
0 reaction

Odyssey Of The Heart 🎩💎 pfp
Odyssey Of The Heart 🎩💎
@odysseyheart
Gurl
0 reply
0 recast
0 reaction

Jason pfp
Jason
@jachian
Class act
0 reply
0 recast
0 reaction

hamta.base.eth pfp
hamta.base.eth
@hamta.eth
Good job 👍
0 reply
0 recast
0 reaction

KingBlack pfp
KingBlack
@kingblack
Hopefully we'll get a proper explanation of how the compromise happened.
0 reply
0 recast
0 reaction

SQX pfp
SQX
@sqx
Some 1111 $tipn toward reimbursement
0 reply
0 recast
0 reaction

Hind 📸 pfp
Hind 📸
@hind
Thank you 🙏🏽
0 reply
0 recast
0 reaction

WG pfp
WG
@wgmeets
Really appreciate it and even tho I should’ve known better to click claim on a mini app not by you guys, you refunded us. Gracias 🙏🏽 2000 $tipn
0 reply
0 recast
0 reaction

noice pfp
noice
@noicebot
https://app.noice.so/?castHash=0x5527111a597d0251a62443b2a9175c9d5bbf26e2&timestamp=1753833615449
0 reply
0 recast
0 reaction