Bybit Login CSRF PoC (F-CSRF-LOGIN regression)

Vuln: postMessage origin check e.origin.indexOf(".bybit.eu") !== -1 — substring, not strict equality. Re-confirmed live 2026-08-13 (chunk 7633-6cdba8eb34bacab5.js @ offset 174407).

This page embeds a live attacker quick_token. Clicking Run opens a Bybit login popup and posts the token; the popup authenticates into the attacker's account (session fixation ATO).

Host: — origin.indexOf('.bybit.eu') =

Ready.