What just happened? A single appnebula.co email click and $50 gone
It started like any other "fun astrology moment". I saw a beautifully designed promo leading me to a quiz about my cosmic identity. You know the type - "Find your starseed origin!" I clicked, took the test, landed on appnebula.co/starseed/prelanding, and was offered access to something "personalized" after payment
The page looked polished. Familiar branding. No red flags. The price wasn’t small, but I figured - okay, let’s go for it. I paid through their checkout page, but the content didn’t show up in the Nebula app. That was odd, but not alarming. Yet. I went to contact support. There was a support email address on the page. I tapped it. That’s all. No form, no second payment screen, not even a warning. Just tapped
A few minutes later, I got a PayPal notification. $50. Gone. For… clicking an email link? I didn’t even send the message. No confirmation. No "Are you sure?"
That one tap somehow triggered a real charge. I don’t know what kind of system this is, but I’m stunned this is happening under something connected to an App Store-listed app. Apple, if you see this: please investigate. Because users are being pulled into an external payment trap that feels anything but secure
iPad (10th generation)