Content
@
0 reply
0 recast
0 reaction
sudo rm -rf --no-preserve-root /
@pcaversaccio
A lot of positive things have been said about EIP-3074. I don't wanna be the party pooper, but let me simply add the warning that it also adds the ability to drain all your assets with just one fucking signature.
1 reply
3 recasts
13 reactions
Nico
@nicom
Well if you can sign, you can also do anything else because you have the key. But I agree that the psychological friction is better when you are asked to make a tx. I have found myself very often thinking "it's just a signature on this dapp, let's not check too much, I have all on hardware wallets anyway, can't arm..."
2 replies
0 recast
1 reaction
sudo rm -rf --no-preserve-root /
@pcaversaccio
Well, currently you can only be drained for one token in one go. Now you can get drained for all tokens in one go: send batch approvals and batch transferFrom's in one go. There is a difference here.
1 reply
0 recast
3 reactions
Nico
@nicom
You can't get drained at all with an eoa on hardware wallet until you actually sign a tx that tells you to transfer tokens. If you read carefully you know what is being done. Right?
1 reply
0 recast
0 reaction
sudo rm -rf --no-preserve-root /
@pcaversaccio
You can without signing a transfer token tx; just think about off-chain permit signatures or approvals.
0 reply
0 recast
1 reaction