top of page
Writer's pictureCreative Season

Metamask Not Secure? Vulnerability Notice: Extension Disk Encryption Issue

Updated: Jun 20, 2022



Cryptocurrency is secure; in fact, very secure. However, it is important to note that a small vulnerability in a single area can cause a "domino effect", that is a collapse in the whole system. Imagine discovering a vulnerability in a single Bitcoin ledger or the encryption algorithm. Anyways, for now let us look at the Cryptocurrency 'Browser Wallets' Vulnerability.


Cryptocurrency 'Browser Wallets" Vulnerability


Thanks to Halborn, a Blockchain cybersecurity firm, all cryptocurrency wallets are safe. Who knows what hackers would have done with this information. You now understand why we need "White hats".



The Vulnerability


Possibility to extract the secret recovery phrase that web wallets use, for example, MetaMask, Brave, Phantom and xdefi. The vulnerability violates the password lock feature of the browsers.


Potential Risks to the Vulnerability Attack

  1. You have an unencrypted hard drive.

  2. You used "Show Secret Recovery Phrase" checkbox to view your secret recovery phrase on screen.

  3. You imported your secret phrase into your MetaMask Extension.

  4. Your computer is compromised or you're using your wallet extension on a friend's computer.

Systems affected

  1. Desktop Operating Systems and Browsers

  • Windows

  • MacOs

  • Linux

  • Google Chrome

  • Chromium

  • Firefox

Note: You are not affected if,

  1. You are using MetaMask Mobile.

  2. You manage your funds using a hardware wallet.

Solutions

  1. Immediately migrate funds to a safe account.

  2. Follow this guide.

Note: Do not use any third party migration tools.

  1. Enable full disk encryption of your system.

Who can Exploit the Vulnerability?

  1. A malware

  2. Anyone with physical access to your computer

Closing Thoughts


MetaMask has awarded Halborn $50,000 US Dollars for the discovery. I am a MetaMask user, and it's such a relief to hear good "hacking" news, especially during the bear markets. The markets are not even 'bear markets', they are "recession markets". Closing up, do you still have dreams to be a hacker, you still have time. Remember, don't buy the dips for now, stake your coins.



Recent Posts

See All

Comentarios

Obtuvo 0 de 5 estrellas.
Aún no hay calificaciones

Agrega una calificación

Explore The Store

All Products

bottom of page