Party A explains how to send bitcoin to them but used a well known wallet address in their documentation/guide (Satoshi's).
Party B didn't use Party A's address and committed a bad case of copy-pasta.
Party A explains how to send bitcoin to them but used a well known wallet address in their documentation/guide (Satoshi's).
Party B didn't use Party A's address and committed a bad case of copy-pasta.
A very similar thing used to happen with people accidentally using a QR code linking to a popular blog post or something explaining QR codes ("PLEASE INSERT QR CODE HERE --ed.").
Somewhat hilariously, even Google's (discontinued) Titan security key had this type of blunder in its Bluetooth software: It was using the example key from the Bluetooth specifications for all keys, making them vulnerable to man-in-the-middle attacks [1].
[1] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-2102
[1] https://www.schneier.com/blog/archives/2007/11/the_strange_s...
Shared security parameters work just fine for some applications; we use them all the time in ECC, for example. Obviously avoiding them is preferable, but isn't always possible. But importantly, using shared parameters is required by some protocols.
On the other hand, using somebody else's URL, email address etc. or symmetric encryption key by mistake and assuming it'll work for you as well is just that: A mistake.
May even just be a low-information buyer.