![Zoide Profile](https://pbs.twimg.com/profile_images/1682453128862367744/EGXiqaEZ_x96.jpg)
Zoide
@ZoideNFT
Followers
1K
Following
4K
Statuses
10K
The Digital Spermatozoon Bitcoin project. Ordinal marketplace and non custodial wallet. π treechat https://t.co/pmxV8zAPIH
EspaΓ±a
Joined January 2022
1/8 𧡠Exciting Updates: Royalties & Referrals Are Live! Royalties for creators and the referral program are here. Together, they make the secondary NFT market more dynamic and profitable, powered by BSV micropayments. Letβs break it down π #BitcoinSV #NFTs
3
15
33
@treechatai is for bsvers now, which means degen people are using it to post regular things. We must enjoy this before regular people enter to post degen things. π #NFTCommunity #NFTdrop #NFTartist #NFTcollectible #bitcoin
1
3
12
RT @RealCoinGeek: In this episode, Bitcoin developer David Case explains how to create real-world apps that can grow and talks about how BSβ¦
0
3
0
@MilkmanOdb @nauete @BSVGeir @pxl_u_272 Egger = VIP Only 100 eggs Only 5 EXOTICS Exotic egger = EXOTIC VIP #few
1
0
3
@AndyGInvest @InvestWithDiego It's so easy. So many people buy cyptos like BTC based on a speculative schema. But others like bsvers USE bitcoin based on a utility schema. Anyway, the bubble will explode soon or later π€·ββοΈ
0
2
38
The Dark Side of HTML in NFTs: Security Risks in Non-Custodial Wallets π¨π NFTs integrate HTML to become interactive, but this can introduce security vulnerabilities, especially in non-custodial wallets where users manage their private keys. πNon-Custodial Wallets ---------- These are wallets where you control your private keys, giving you full asset control but also making you solely responsible for security. β οΈSecurity Risks Inventory ---------- XSS (Cross-Site Scripting) Attacks π: ---------- -Definition: Malicious scripts run in your browser via HTML in NFTs. -Risks: Theft of private keys, unauthorized transactions, data breaches. Advanced Phishing π£: ---------- -Definition: Fake interfaces trick users into giving away sensitive info. -NFT Context: An NFT might look like a legitimate wallet page, leading to credential theft. Script Injection π§βπ»: ---------- -How it works: Unauthorized code alters NFT or wallet functionality. -Dangers: Modifies NFT content or introduces wallet vulnerabilities. Denial of Service (DoS) Attacks π: ---------- -Explanation: Overwhelms system resources, making the wallet unusable. -Impact: Prevents access to your assets when needed. Privacy Violations π΅οΈ: ---------- -Concern: HTML can track your interaction with NFTs. -Risk: Compromises your privacy by collecting interaction data. Mitigations and Best Practices π‘οΈ ---------- -HTML Sanitization: Clean HTML to remove harmful scripts before showing. -Sandbox Environments: Isolate HTML to prevent system access. -Integrity Checks: Ensure HTML integrity post-minting. -Display Policies: Regulate HTML in NFTs to enhance security. Conclusion π ----------- HTML in NFTs adds value but requires robust security to protect users, especially those using non-custodial wallets. Balancing innovation with security is key. Additional Resources π ---------- DOMPurify - OWASP HTML5 Security Cheat Sheet - π #NFTCommunity #NFTdrop #NFTartist #NFTcollectible #bitcoin β―β― #NFTSecurity #Web3Safety #BlockchainRisks #HTMLinNFTs
0
2
5
π Congratulations @1soysauce you win!! ππππ π«Check your wallet and take care of your new egg π π #NFTCommunity #NFTdrop #NFTartist #NFTcollectible #bitcoin
3
1
25
GFM π airdrop finished, it's egg o'clock today, who's gonna be the lucky ass? centimeitor milkyorion bsvgodfather brooz indeguy777 amargada soysauce 4dtoken pxl nftproject nauete pacart 1babi kandenchi π #NFTCommunity #NFTdrop #NFTartist #NFTcollectible #bitcoin
1
0
7