vrypan |--o--| pfp
vrypan |--o--|
@vrypan.eth
How tipping and marketing miniapps could be exploited by attackers for financial gain. https://blog.vrypan.net/2025/05/28/social-attacks-with-monetary-value/
2 replies
0 recast
7 reactions

Harris pfp
Harris
@harris-
The app keys attack is why I never want to add a new key from a mini app. Iirc this exact style of attack happened with tipping from an app before? Where the dev basically consumed the allowance for you via casting tips that you weren't going to use anyway or something. Maybe someone else remembers better than me
1 reply
0 recast
0 reaction

vrypan |--o--| pfp
vrypan |--o--|
@vrypan.eth
I don't think it has happened. I'm also concerned about signers. That's why I created fcp.
1 reply
0 recast
1 reaction

vrypan |--o--| pfp
vrypan |--o--|
@vrypan.eth
Oh, it once happened by mistake, where there was a cast sent out that did not belong to the user, or something like that.
0 reply
0 recast
1 reaction