mountWallet zeroed the vault root after mounting, but the WizardConnect adapter kept a reference to that same buffer and read it again for every new pairing's relay key. Every pairing made after mount therefore got a Nostr identity derived from 32 zero bytes and the pairing URI alone, so anyone who saw the URI (the QR, a script on the dapp page) could read the relay traffic, xpubs included, and speak as the wallet. The adapter now gets, and keeps, its own copy. The signing overlay and the PIN request named the dapp by its own userPrompt, so a dapp paired once could present itself as any site. The pairing origin the host verified is now recorded per URI and shown instead; the dapp's text is a quoted row with invisible and bidi characters removed. One sign request per connection may be on screen at a time, and revoking a site in Aegis ends its pairings too. |
||
|---|---|---|
| .. | ||
| aegis | ||
| blocker | ||
| consent | ||
| docx-editor | ||
| notepad | ||
| pdf-editor | ||
| pithos | ||
| screenshot | ||
| translate | ||
| vpn | ||