MetaMask warns of security vulnerability from older versions of popular crypto wallet

Share This Post

“Ultimately, we’ve learned that our password encryption feature’s security was partially undermined by browser behavior,” said the team at MetaMask.

On Wednesday, MetaMask said that it uncovered a critical security vulnerability in older versions of its crypto wallet with the help of security researchers at Halborn. The security firm was awarded a bounty of $50,000 for the discovery. 

For users of the MetaMask extension before version 10.11.3, three necessary conditions would have led to the potential vulnerability. They are: 1) an unencrypted hard drive, 2) having imported a secret recovery phrase into a MetaMask extension on a device that was compromised, stolen, or has unauthorized access, and 3) having used the “Show Secret Recovery Phrase” checkbox to view one’s secret recovery phrase on-screen during the import process.

“We’ve only found that the Secret Recovery Phrase could be extracted under very specific circumstances, and we’ve been able to introduce new protections over the period that Halborn has waited to disclose.”

Apparently, the exploit affects all browser versions of MetaMask wallet versions prior to the 10.11.3 update, and all operating systems if all three circumstances were met, but not mobile versions.

MetaMask is warning affected users to migrate their funds from their compromised wallets. However, keep in mind that all three conditions need to have been met for the vulnerability to be active on older versions of MetaMask.

Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

LBank x 7 Meme Projects: Don’t Miss the Halloween Campaign with $7,000 in Prizes

PRESS RELEASE LBank, leading global cryptocurrency exchange, has officially launched its “Spooky Season” Halloween Campaign, running from October 22 to November 3, 2024 With a total

XRP News: Ripple Partners with Garanti BBVA and IBM to Boost Crypto Security in Türkiye

The post XRP News: Ripple Partners with Garanti BBVA and IBM to Boost Crypto Security in Türkiye appeared first on Coinpedia Fintech News In an exciting move for the Turkish crypto market, Garanti

India About to Ban Bitcoin, Eth As Government Favors CBDC Expansion

The post India About to Ban Bitcoin, Eth As Government Favors CBDC Expansion appeared first on Coinpedia Fintech News India is moving closer to a major decision on cryptocurrencies like Bitcoin and

SPX6900 Price Prediction: Sell The Broken Parabola Or Buy Dip For Next Meme Coin Supercycle

The post SPX6900 Price Prediction: Sell The Broken Parabola Or Buy Dip For Next Meme Coin Supercycle appeared first on Coinpedia Fintech News SPX6900 recently witnessed one of the biggest rallies in

Ripple Price Analysis: Will XRP Price Reclaim $0.63 or Fall to $0.48? 

The post Ripple Price Analysis: Will XRP Price Reclaim $063 or Fall to $048  appeared first on Coinpedia Fintech News Following the SEC appeal, the XRP coin price had experienced a major price

ECB’s Attack on Bitcoin Backfires! Here’s Why Experts Are Furious

The post ECB’s Attack on Bitcoin Backfires! Here’s Why Experts Are Furious appeared first on Coinpedia Fintech News A group of researchers, Dr Murray A Rudd, Dennis Porter, Allen Farrington, and