pull down to refresh

Oh no, the point is not that your clients have to trust your intent, but instead trust your security posture. No matter how much you may claim "but we never get any funds" any hacker that DOES infilitrate YOUR service will be able to:

  • Falsify claims to the client that the client was paid (i.e. webhook), including potentially receiving product / service from the client because the client does not implement actually checking their actual wallet.
  • Change the exchange rate to make the client lose money when paid with Bitcoin.
  • Replace the ZPUB of your client with their own.

If the client DOES implement checking their actual wallet... they might as well just implement the rest, which is TINY compared to the work needed to validate that a payment has reached their own wallet.