How we broke exchanges: a deep dive into authentication and client-side bugs
osec.io | research | #web3 | #account-takeover | #authentication | #vulnerability | #oauth | #exchanges
Summary
OtterSec details OAuth misconfigurations that lead to account takeover in exchanges, SDKs and wallets, including Google GSI/FedCM flow quirks and desktop-vs-mobile environment gaps.
- Published
- Collected
Skip to content