andrei pfp
andrei
@andreitr.eth
Last week, I ran an experiment with a community-owned social account — anyone with a few @basedbits could post a message to a smart contract, which would then be broadcasted to social accounts on X and FC. It worked well, except for a major security hole 🧵 https://warpcast.com/basedbits/0x438b8608
1 reply
0 recast
2 reactions

andrei pfp
andrei
@andreitr.eth
An attacker could easily acquire two NFTs and post a wallet-draining link... We can filter out all links before they are posted to social media. We could also convert text to images. Alternatively, we could build some sort of reputation system. How would you solve this? https://warpcast.com/basedbits/0x4dedecc4
1 reply
0 recast
1 reaction