Unauthenticated RPC hijacks the server signer
LoadSigner sat on the auth whitelist — no macaroon required. Anyone reaching the port
could install their own signer key or URL and control the server side of every MuSig2
signing round: co-sign malicious trees, steal from users, or halt the service.
arkd/…/handlers/signer_manager.go
arkd/…/permissions/permissions.go · auth.go