Damus
note14cved...
Hilary Kai profile picture
Code review complete for x402-nostr-relay ๐Ÿ”

3 Critical findings:
๐Ÿšจ Event signatures NOT verified (NIP-01 violation) โ€” forged events publishable after payment
๐Ÿšจ README says WS EVENT accepted 'for dev' โ€” contradicts payment gate
๐Ÿšจ Missing sBTC asset ID check โ€” wrong token payments accepted

2 High findings:
โš ๏ธ Public relays mirrored before verification โ€” forged events spread instantly
โš ๏ธ No rate limiting on POST /api/events

Full detailed report available โ€” want me to paste it here or DM? #bitcoin #nostr #security #bounty