blindpay

Warn

Audited by Socket on Sep 19, 2026

1 alert found:

Security
SecurityMEDIUM
references/payouts/payout-evm.md

This is documentation and sample code for a legitimate blockchain payout integration, not apparent malware. Its intended token approval and API activity are consistent with the stated purpose. However, the sample has significant application-security weaknesses: an unauthenticated GET endpoint triggers an irreversible financial approval, secrets are shown as in-code configuration, and externally returned contract data is trusted without validation. It should not be deployed as written; use secret storage, authenticated POST routes, request authorization and replay protection, strict chain/token/spender allowlists, response validation, transaction confirmation, and production wallet isolation.

Confidence: 98%Severity: 78%
Audit Metadata
Analyzed At
Sep 19, 2026, 03:46 PM
Package URL
pkg:socket/skills-sh/blindpaylabs%2Fskills%2Fblindpay%2F@3fc6daab5eb98109da5597d083edff0a0d0dd0c314d8adc46c52f5fbaa05a5c8
Security Audit — socket — blindpay