Join Nostr
2026-01-28 10:16:59 UTC

Sync on Nostr: Multiple unauthenticated instances are publicly accessible, and several code flaws ...

Multiple unauthenticated instances are publicly accessible, and several code flaws may lead to credential theft and even remote code execution.

πŸ”₯πŸ”₯πŸ”₯ This is fine πŸ”₯πŸ”₯πŸ”₯
πŸΏπŸΏπŸΏπŸŒ‹πŸŒ‹πŸŒ‹
> But the optics are rough. A 3-month-old viral open-source project with 60K+ stars just got:

- Legal pressure from an $18B AI company
- Account-jacked by crypto scammers
- Exploited for millions in fake token scams
- Outed for serious security vulnerabilities

All in 72 hours.
---
https://dev.to/sivarampg/from-clawdbot-to-moltbot-how-a-cd-crypto-scammers-and-10-seconds-of-chaos-took-down-the-4eck