tonkeeper / wallet

GNU General Public License v3.0
327 stars 82 forks source link

How to scam people, because of not showing jettons amount on a message on Tonkeeper #476

Closed tongochi closed 1 year ago

tongochi commented 1 year ago

Hi Tonkeeper team. It appears to me, we found very easy way how to scam people because you don't show jettons amount when users sends jettons to smart contract

How users can potentially be scammed.

1) scammer collects the data of the average amount of jUSDT, STON, Scale is being collected in users wallets. The median value is found.

2) Let's say the scammer creates the page where user clams free minted NFT, but the smart-contracts also takes some jettons from user wallet 2023-08-28 18 12 49

People rush to the website to mint NFTs, and those who have the median token value in their wallet send the token along with the transaction. User may not even notice the loss at first.

How to fix: Show the amount jettons when users send it to smart contract

tuminzee commented 1 year ago

@tongochi oh wow which version of tonkeeper are you using?

olyaMay commented 1 year ago

Hi. Thank you! We fixed it in one of previous builds. 2023-10-09 12 34 32