The payload poisons app-global localStorage with attacker controlled RPC URLs, hooks window.ethereum.request and rewrites the answer. Curators, arbitrators or keepers answering any live question get silently flipped to "yes" on attacker-fed data enabling forced execution of malicious module transactions.
A fresh EOA used the permissionless addProposal() on Potion DAO's abandoned Zodiac Reality Module purely as an injection vector: the module asks its question on the shared reality.eth oracle, so it lands in the global question index.
The proposal's question JSON supplies title_html directly with an
<img src=x onerror=eval(atob(...))> payload. reality.eth's DOMPurify only sanitizes the markdown path. Direct title_html is trusted verbatim and rendered via jQuery .html('.question-title'). It fires for any reality.eth visitor whose feed includes this entry.Malicious question: https://reality.gwei.site/#!/network/1/question/0x5b7dd1e86623548af054a4985f7fc8ccbb554e2c-0xdd2844cdaea74bac3f02c90bfdec152d65f03cdac1b2db585cd9e59e1c08a2d7 (do not open with a wallet)
TX: https://etherscan.io/tx/0x95932a1d8b3940847cfb26d1d42c132fce6b0ca37e144dbc3da209e25a1b8437
Attacker: https://etherscan.io/address/0xd57a4dda0ff9be630e9564e82c749e12ac4ef809
X: https://x.com/RealityEth
