@rifvader
Thanks for making writer coins safer!
However, there's still a problem with the spoofed writer addresses and associated fake reward claims:
For example this Writer Coin was created under the paragraph writer address of @pfista :
https://basescan.org/token/0x1f0FfE37Fb6f2cEfcf1b152a4809f050ae710304
The paragraph profile for this writer address indeed shows the verified badge for his Farcaster profile.
Now what happens is, that the one who launched the writer coin, is able to claim the full 5% rewards pool - seemingly without any proof. See this transaction here:
https://basescan.org/tx/0x22b73e63fb55cafc36b81abc4f7335cc81d7c75400466d4027457bd435f8a743
(the transaction input data and emitted event look like they exploit a bug)
Finally the free reward tokens are sold, once there are buyers for the coin.
In my eyes only an "admin" should be able to call the "launch" function on the coin factory contract.