tonkeeper / wallet

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

How to scam people, because of not showing jettons amount on a message on Tonkeeper

tongochi opened this issue · comments

Hi Tonkeeper team.
It appears to me, we found very easy way how to scam people because you don't show jettons amount when users sends jettons to smart contract

How users can potentially be scammed.

  1. scammer collects the data of the average amount of jUSDT, STON, Scale is being collected in users wallets. The median value is found.

  2. Let's say the scammer creates the page where user clams free minted NFT, but the smart-contracts also takes some jettons from user wallet 2023-08-28 18 12 49

People rush to the website to mint NFTs, and those who have the median token value in their wallet send the token along with the transaction. User may not even notice the loss at first.

How to fix: Show the amount jettons when users send it to smart contract

@tongochi oh wow which version of tonkeeper are you using?

Hi. Thank you! We fixed it in one of previous builds.
2023-10-09 12 34 32