Ultimate magazine theme for WordPress.

Why this MetaMask vulnerability could put your funds at risk

Crypto wallet provider MetaMask has reported a vulnerability that could affect a very small portion of its users. Discovered by blockchain security firm Halborn, the vulnerability could allow an attacker to take possession of a user’s secret recovery phrase, putting their funds at risk.

Related Reading | Russia still bans crypto? A bill banning digital assets has passed its first reading

This vulnerability affects multiple web crypto wallets and allows an attacker to extract a secret recovery phrase from a PC. As already mentioned, the vulnerability does not affect all MetaMask users, but a very small part.

This is because the user must meet 3 conditions to be subject to this attack: use an unencrypted hard drive, the user should have imported the secret recovery phrase from the MetaMask web extension to a compromised device, or use the crypto wallet extension from an unsecured computer and use the “Show recovery secret phrase” check box during the import process.

Source: MetaMask via Medium

The crypto wallet provider has created a migration guide to help users move their funds to a new wallet. In this sense, the company recommended that users who meet these conditions and users who think they can meet them follow the guide. You can find this document under the following link.

Users intending to migrate to a new wallet should have enough funds to pay the necessary gas fees, the wallet provider said. These fees can “get costly” depending on the user’s funds and the smart contracts “that store or manage” those assets.

Assets under the Ethereum ETC-20, ERC-721 (NFTs) and ERC-1155 standards should be given priority. The wallet provider warned:

If your account has been compromised, it is possible that you have placed a Sweeper bot on your account. If this is the case, as soon as you transfer the tokens, they may be transferred to the attacker’s address.

Are your MetaMask funds safe?

As MetaMask clarified, the vulnerability does not affect their mobile users, only users on macOS, Linux and Windows using Google Chrome, Firefox or Chromium-based web browsers. The company has implemented a “mitigation” for this vulnerability.

With that in mind, all users have been asked to update their crypto wallets to version 10.11.3. Users were also encouraged to contact MetaMask support for further assistance or information.

The company honored Halborn with a $50,000 award. Two days ago, the provided crypto wallet launched a rewards program called HackerOne to “work with the security community to find wallet vulnerabilities and stay ahead of Web3 threats.”

The program was launched with 4 levels of security with different rewards. Low security detections are paid a total of $1,000, medium $2,000, high $15,000, and critical, such as the vulnerability described above, $50,000 for each detection.

Related Reading | Bitcoin holders remain cautious as correlation with stocks persists

At the time of writing, Ethereum (ETH) is trading at $1,180 down 3% on the 4-hour chart.

Ethereum ETH ETHUSDETH is trending down on the 4-hour chart. Source: ETHUSD Trading View

Learn Crypto Trading, Yield Farms, Income strategies and more at CrytoAnswers
https://nov.link/cryptoanswers

Comments are closed.

%d bloggers like this: