-
Notifications
You must be signed in to change notification settings - Fork 72
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Additional warning for aggregate bonded announced by "third party" address #1719
Comments
Affected user: https://twitter.com/gehari3sei/status/1442883477485936651 Affected user: https://twitter.com/Yiddish816/status/1443084024872800256 |
Suggested text:
|
Related issue here: POC code
The victim will get a partial transaction below Once the victim has signed the partial transaction, The attacker announce the proof and grab victim's assets. |
@hanatyan128 showing secret lock will be done in separate issue. |
Reason:
Scammers are sending aggregate bonded requesting all funds to random addresses (transaction is initialized from a "third-party" wallet). For example:
http://explorer.symbolblockchain.io/transactions/7BE1EB498B914BDA7F17C26789711E62276280F6322A8C3F36A9E60CD878C9B6
We should add a warning (after pop up with password) - double confirmation - to ask the user if he really wants to send this transaction because it was initialized by the third-party wallet.
We should warn if account which initialized tx is not related to an account that is signing (we should not warn if another cosigner from the same multi- initialized the transaction).
There are some legit bonded initialized by "third-party" accounts like those send by All nodes or nember.art and in future we should maybe do some "whitelist" of addresses.
The text was updated successfully, but these errors were encountered: