Vuln: postMessage origin check e.origin.indexOf(".bybit.eu") !== -1 — substring, not strict equality. Re-confirmed live 2026-08-13 (chunk 7633-6cdba8eb34bacab5.js @ offset 174407).
This page embeds a live attacker quick_token. Clicking Run opens a Bybit login popup and posts the token; the popup authenticates into the attacker's account (session fixation ATO).
Host: — origin.indexOf('.bybit.eu') =
Ready.