akasakaid / blumtod

Auto claim
359 stars 144 forks source link

Blum session #66

Open LostEmpires opened 3 hours ago

LostEmpires commented 3 hours ago

Hi

This issue isn’t about this project, but it’s related, and I would appreciate it if you could answer, as I don’t know where to ask the question.

How do I revoke access to my Blum account?

I started the Telegram bot, and now the developer has access to the Blum, Hamster, TapSwap, cex.io (PowerTap), and Pixelverse accounts.

It seems the access link is as follows, and it allows access to the accounts through the browser(Session or ...):

https://telegram.blum.codes/?tgWebAppStartParam=ref_A☆☆☆h#tgWebAppData=user%3D☆☆☆first_name☆☆☆last_name☆☆☆username☆☆☆language_code%2522%253A%2522en%2522%252C%2522is_premium%2522%253Atrue%252C%2522allows_write_to_pm%2522%253Atrue%257D%26chat_instance%3D-4☆☆☆1%26chat_type%3Dprivate%26start_param%3Dref_A☆☆☆h%26auth_date%3D1☆☆☆07%26hash%3D4d9☆☆☆26a&tgWebAppVersion=7.0&tgWebAppPlatform=ios

I have censored part of the link for the security of the Blum account with the symbol ☆

akasakaid commented 2 hours ago

I don't think you can delete your access to bot blum, because the query_id/user= data from bot blum does not expire, even I have a banned account from telegram but I can still access bot blum using the query_id/user= data.