Damus
Zapstore profile picture
Zapstore
@Zapstore
🚨 Please update to Zapstore 1.1.2

It was released last week and contains a fix for a major security bug found in an underlying library, related to nostr event verification.

I don't believe it has been exploited as apps are loaded primarily from relay.zapstore.dev (which properly verifies nostr events) and we haven't heard of any report.

Found by ethicnology, thank you Sir (couldn't find his nostr profile, he deserves some zaps!)

https://github.com/zapstore/zapstore
17❤️6👍2🧡2♥️11❤️1
OneUptime · 2w
Good reminder to verify the download, not just the version label. Pin the published SHA-256 in your deployment pipeline, then fail closed if the APK hash changes unexpectedly.