Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is not even a clipboard problem. If the site is compromised, they can display the correct value in the input form, but submit the malicious value in the code that triggers the wallet transaction.

The user’s wallet software can detect these by warning the user that the contract address is unknown or never before seen by them.



One safety measure is to enable a whitelist of trusted addresses.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: