MetaMask warns of security vulnerability from older versions of popular crypto wallet

Published at: June 15, 2022

On Wednesday, MetaMask said that it uncovered a critical security vulnerability in older versions of its crypto wallet with the help of security researchers at Halborn. The security firm was awarded a bounty of $50,000 for the discovery. 

For users of the MetaMask extension before version 10.11.3, three necessary conditions would have led to the potential vulnerability.: 1) an unencrypted hard drive; 2) having imported a secret recovery phrase into a MetaMask extension on a device that was compromised, stolen, or has unauthorized access; and 3) having used the "Show Secret Recovery Phrase" checkbox to view one's secret recovery phrase on-screen during the import process.

"We've only found that the Secret Recovery Phrase could be extracted under very specific circumstances, and we've been able to introduce new protections over the period that Halborn has waited to disclose."

Apparently, the exploit affects all browser versions of MetaMask wallet versions prior to the 10.11.3 update, and all operating systems if all three circumstances were met, but not mobile versions.

MetaMask is warning affected users to migrate their funds from their compromised wallets. However, keep in mind that all three conditions need to have been met for the vulnerability to be active on older versions of MetaMask.

Tags
Related Posts
The remaining steps to mainstream institutional investment
It has been said that you only get one chance to make a first impression. Perhaps the best example of this old adage is the cryptocurrency space. From exit scams and money laundering, to unaudited code and high carbon footprints, the crypto landscape has spent the better part of the past decade scrubbing itself of its infamous past. For many, the sanitizing of the decentralized ecosystem was inevitable — simply a matter of when, not if. This mindset hindered the sense of urgency that should have been on display and may have ultimately contributed to the skepticism exhibited by mainstream …
Adoption / May 29, 2021
Microsoft transformed home computing — and this project wants to transform DeFi
A decentralized autonomous organization that governs a growing number of protocols says the initial vision for DeFi “has been corrupted by greed, inefficiency and sheer incompetence” — and says a drastic new approach is needed to ensure this sector reaches its full potential. According to Jigstack, the Ethereum landscape is fragmented, with thousands of DApps that offer varying degrees of quality. Millions of dollars in user funds have been lost, hacked, stolen or fraudulently misplaced in the past year — and “everything the industry promised to deliver has yet to be brought to life in a professional manner.” Jigstack’s founders …
Decentralization / April 15, 2021
Cardano ecosystem set to expand with custom-built sidechains
Input Output Global (IOG) — the team behind the Cardano ecosystem — will release a software toolkit in late Jan. 2023 that will enable developers to deploy custom-built sidechains on Cardano aimed at improving the ecosystem. The news was announced by IOHK — a blockchain engineering company founded by Charles Hoskinson and now known as IOG — on Jan.12, which also attached the official technical documentation for the sidechain toolkit. ⛓️ The #Cardano sidechain toolkit was previewed at #IOScotFest, and we’re happy to share the first iteration is out now. Here’s the lowdown on this exciting new project! https://t.co/Ny9tQuJh5K — …
Decentralization / Jan. 13, 2023
Top 7 blockchain courses and certifications for beginners
Blockchain courses and certifications can play an important role in helping individuals gain a comprehensive understanding of blockchain technology and its applications. By completing these courses, individuals can develop technical skills, stay current with industry developments, enhance their career opportunities and increase their earning potential. Here are seven blockchain courses and certifications for beginners. INE’s Blockchain Security INE’s Blockchain Security course is an online course offered by Internetwork Expert (INE) that provides a comprehensive overview of the security aspects of blockchain technology. The course covers various topics such as consensus algorithms, cryptography, network security, smart contract security, and blockchain attacks …
Decentralization / Feb. 2, 2023
'It would be absurd' for a US court to rule private NFTs as securities: Lawyer
Blockchain Association’s chief legal officer says “it would be absurd” for a United States court to rule that digital assets on private blockchains are securities, following a federal judge's decision to allow a lawsuit against Dapper Labs's NBA Top Shots NFTs to play out. U.S. attorney Jake Chervinsky made the comment after federal judge Victor Marreo denied a motion to dismiss a 2021 lawsuit that accused Dapper Labs of selling nonfungible tokens (NFTs) as unregistered securities. Chervinsky was among a host of lawyers on Twitter to reiterate that the judge’s denial of the motion does not mean a ruling has …
Adoption / Feb. 23, 2023