Oddbean new post about | logout
 This new Yakhionne 2.0 is looking good! 😊 #GrowNostr 
 
 How did they implemented their non custodial wallet, without the user getting any seed phrase or a channel opening? 
 Great question. Idk. 

But I kept trying to respond to you (on Primal) and this popped up several times 👀 

https://m.primal.net/LnSG.png  
 Right after you clicket on reply button? 
 Yeah, Primal for web on safari. So weird. New feature being tested? (All those wallets are horrendous though) @miljan it’s so weird 🤷‍♀️ 
 something weird is going on, same here primal on safari but I dont like getting suddent prompted to connect a wallet out of nowhere 
 Especially non-Bitcoin wallets 
 Not good. 
 What if primal is under a shitcoin attack? 
 🤨 
 A great list of wallets one should never have 
 This looks like an XSS attack 
 👀 
 My friend sent me the same image yesterday asking the same thing. what is this exactly? 
 This is like a phishing thing, right? Where the attacker just hopes you will clicky click on the scam wallets? @hodlbod 
 AAH! could be.  
 Yep, exactly. Definitely don't use it. 
 fwiw, I did a malware scan now and found nothing. so all good 😊  
 That looks like you have a full of shitcoin apps installed and your device is asking which one to use.
When you play with shit, you smell like shit. 
 Nope. I do not. Same thing was happening to others as well who were using Primal desktop. Follow the entire thread to see what the devs have to say. TLDR, it’s an XSS attack 🙄 

The one annoying thing on nostr is when people jump to conclusions and or gossip 🙄 
 I am on Primal desktop. But my browser is always clean. never play with crap.
Even if it is a XSS attack, that shit must come from something you did. 
 Nope 👎 it did not. 
 what you are seeing is Wallet Connect

a web3 solution to connect wallet to the app

it's a shitcoin thing, just a bit of code on the website that allows for a QR-based handshake

https://walletconnect.network/ 
 Can I block it? 
 In browser, inspect element, remove JS?

maybe using an extension like NoScript?

... I would tell the devs/open a github issue, sure you are not the only users not interested in this new feature they added...

or change nostr client, data portability rocks
 
 Why is this suddenly being promoted on primal for no reason? 
 I don’t know that I’d called it promoted, but it is suddenly there and wasn’t earlier today 
 I meant prompted, but I understand, very weird 
 not a primal dev or user

my guess they added the code in but misconfigured the flags for when it should appear (not on reply function definately)

It's a free thing, they add it, now web3 domain holders can 'connect with wallet' and use their publickey as their identity (I am guessing)

not necessarily going full shitcoin, but welcoming users who want to connect via a web3 wallet... like a Google or Facebook OAuth 
 Something is hijacking all button clicks. I don't know what post it is, but I was able to replicate it. 
 Seems ok on my phone app. Just happening on my Primal for web with safari on MacBook 
 Also started for me earlier trying to reply to @619297f6c93475d89ca8122b9e75cc6383486941aecbcd3eed... 
 Replicated it, it's an XSS 
 Holy shit! https://github.com/airbnb/lottie-web/issues/3127 
 So now we can blame Airbnb? 
 You're much faster than I am 
 Amazing. I was just inspecting that too, but seemed like an innocuous library. 
 Nostr devs on top of things 🫡 
 Insane, primal just removed the lottie-player https://github.com/PrimalHQ/primal-web-app/commit/299a26daa1ec6ebc642e117827c9b21c0b3117ec 
 Yep, just discovered myself that this is the source of the issue: https://github.com/airbnb/lottie-web/issues/3127 
 Last time there was an xss vulnerability on nostr (anigma) lots of people leaked their nsecs 
 Nostr devs on top of things 🫡 
 So now we can blame Airbnb?