Stackframe MARKET | web3/crypto (dApp, DeFI, DAO, etc)
17.7K subscribers
7 photos
6 videos
8 links
Occasional posting on web3/crypto-related tools & vulnerabilities. If something is not listed on-market you can pay for research. Ask: Goal, Deadline, Coin.
Download Telegram
@Module & @Stackframe | Ledger Wallet 0day (In-App) — $x,xxx

Hello everyone, we're releasing a Ledger Wallet 0day that renders a full recovery flow natively inside the application. The target remains within Ledger Wallet for the duration of the session.

* Features:
— In-app execution via Ledger Wallet
— Source code included (non-obfuscated)
— Custom overlay templates available on request

* Requirements:
— Public host or tunnel for overlay delivery

NOTE: The target must accept a deeplink popup to open Ledger Live, the recovery flow then runs in-app from there. No further detail will be provided on this point.

* → Screenshots attached are for demonstration only, the overlay shown is a sample template, not the only layout available. Custom templates are available upon request.

Open to a test before purchase once a deposit is placed with a trusted MM (@scrizon/@cupid).

For more information, join @module or PM @lmaowtf17 | @moschata
Trezor Signer Spoofer (In-App / Web) | t.me/stackframe

FULL signer impersonation kit for Trezor Suite. VIC's wallet displays your identity with a green "Verified Service" badge. They confirm on device because every trust signal checks out.

* Sign arbitrary messages, transactions with your to/value/data, EIP-712 typed data for permits
* Account addresses and device model, firmware, PIN state pulled on page visit
* Panel with per-VIC-session fire buttons and brand switcher: Trezor, MetaMask, Ledger, Uniswap, Pegasus, Custom
* Delivery via trezor.io, address bar never leaves their domain
* Fresh pairing per visitor click, no manual URIs
* Each victim auto-logged: Device Name, VIC #, IP, Agent, Device, Firmware, PIN Addresses
* Cross-chain: ETH, BTC, SOL, XLM, TRX

NOTE: This DOES NOT require system access at all unlike other current Trezor Suite SE kits.

Not a signing bypass. Hardware-enforced user interaction needed still. Identity & badge are forged.

$3,000 | @moschata
Module
@Module | Trezor 1-Click Signer Takeover — $4,000 Hello all, we're releasing an in-app trezor-focused EVM signer takeover kit. Single-click delivery into the native desktop wallet flow; once the target confirms, you hold an active signing session on supported…
This older version of the newer and more efficient In-App spoofer is NOT being sold anymore. The post above (Trezor Signer Spoofer) is being sold $1,000 cheaper than before and is much more useful (to the right person)

@Cupid / @Scrizon accepted.

@moschata and @lmaowtf17 for inquiries.