In reply to @v12sec

V12

@v12sec · Twitter ·

The XSS runs in Ditto’s main frame with the Capacitor bridge attached. It calls `SecureStoragePlugin.get()` with the key `nostr:login`. That blob contains the raw `nsec`. CSP cannot help: `evaluateJavascript()` bypasses normal script-loading rules.