Subverting Web2 authentication in Web3
Summary
OtterSec examines hidden risks in Web3 apps using Web2 auth: an OAuth logic flaw in Web3Auth, a Supabase user_metadata misconfiguration, and OAuth abuse in localhost setups.
- Published
- Collected
Skip to content