Varun Srinivasan pfp
Varun Srinivasan
@v
QR Miniapp Update Earlier today, an attacker stole credentials from the QR miniapp and sent notifications from their apps. Users were sent to a different miniapp and encouraged to buy a fake token for $3. The QR team fixed this and reimbursed all users. Shoutout to the QR team for being very quick to respond. There is no other compromise of Farcaster wallets and your funds are safe. What is Farcaster doing to prevent this? Our transaction scanning prevents dangerous “send me all your money” attacks. That’s why the damage was limited to a $3 buy. We are also limiting miniapp notifications to redirect within the same domain. The attacker would have to compromise many more parts of the QR miniapp to pull off this attack again. What can I do to stay safe? If an app is asking you to do something that it normally does not, like buying a new token or claiming an airdrop, check the apps home page or the author’s page to see if it is legitimate before taking the action. If there is some doubt, ask the author over DM or in the feed before taking the action.
29 replies
52 recasts
310 reactions

Pichi pfp
Pichi
@pichi
@procoin curate Union
4 replies
2 recasts
29 reactions

Procoin pfp
Procoin
@procoin
This cast has been curated to UNION on the Feeds miniapp @v you have been issued UNION shares Feed Market Cap: $5,632.13
0 reply
0 recast
5 reactions