🎯 Bitcoin XSS - Targeted Bundle.data Attack

🎯 XSS Attack Vector

Path: SDK β†’ okxBtcJSBridge β†’ Hse.java β†’ Hzv.java β†’ bundle.data β†’ evaluateJavascript()

Vulnerable Methods: signPsbt, signPsbts, pushTx, pushPsbt

Target: bundle.getString("data") in Hzv.java lines 87, 121, 148

Detecting wallet…