Yes, the risk is from a rogue node operator sending invalid responses to queries, which makes any non-certified query potentially a security threat
Yes, the risk is from a rogue node operator sending invalid responses to queries, which makes any non-certified query potentially a security threat