pull down to refresh
5 sats \ 3 replies \ @ek 6h \ parent \ on: How to Verify the Impact of the Recent NPM Attack on My Wallets? bitcoin
the malware swaps the address. so when you sign without double-checking the address, you're actually signing a tx to the attacker. you're then broadcasting that tx like you would normally. that's how anything signed leaves the browser or wallet.
reply