MetaMask and Phantom crypto wallets fix browser extension vulnerability

Quick Take

  • Security firm Halborn discovered a critical bug affecting popular web3 wallets like MetaMask and Phantom.
  • The vulnerability — which has now been fixed — made it possible for hackers to extract recovery seed phrases from computer disks.

Popular crypto wallets, including MetaMask and Phantom, suffered for months from a critical vulnerability in their browser extension software, according to a report on Wednesday from cybersecurity firm Halborn.

The vulnerability, dating back to September 2021 and now fixed, put users' funds at risk as it made it possible for hackers to extract wallet recovery seed phrases stored on computer disks. However, no exploits have yet been reported that could be tied to the vulnerability.

In the report, Halborn's researchers said the seed phrases generated by wallet providers were being saved on users' computers in plain text as part of the "Restore Session" feature. This meant malicious actors could gain entry using malware or physical access. Halborn added they worked with wallet providers to patch their wallets against the vulnerability.

MetaMask, the most popular web3 wallet on Ethereum, clarified that the critical security issue affected only a "small segment of users" and that the vast majority of users were not at high risk. The MetaMask team added that it already issued mitigations against the vulnerability in its latest update of the wallet's browser extension.

Meanwhile, Phantom, the most-used web3 wallet on the Solana blockchain, said it began issuing fixes in January, three months after the vulnerability was initially flagged by Halborn. Furthermore, Phantom plans on rolling out another exhaustive patch next week, it said.


© 2022 The Block Crypto, Inc. All Rights Reserved. This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.

About Author

Vishal Chawla is a reporter who has covered the ins and outs of the tech industry for more than half a decade. Prior to joining The Block, Vishal worked for media firms like Crypto Briefing, IDG ComputerWorld and CIO.com. Follow him on Twitter @vishal4c.