1) By default, authentication key has only 16 bits of entropy. (I wish I was making this up…)
2) There's no good UI to make the key stronger: you can either use, say, "--code-length 16", which makes the receiving code ridiculously long, or provide your own code with "--code", in which case it's visible to other local users via ps(1).
3) Between "wormhole send" and "wormhole receive" on the other side, anyone on the Internet can attempt to intercept the transfer. Conveniently, you can list all currently valid channel ids (nameplates).
4) If the interception succeeds, the attacker can immediately run "wormhole send" with the same code, so that the intended side wouldn't notice anything is off.
5) If the interception fails, the attacker still ruined the transfer. (DoS)
All of this would be fixable, if not the maintainer's bizarre insistence on using weak crypto.