Experts Find a Vulnerability in Older Versions of MetaMask Wallet
Security researchers at Halborn have discovered a vulnerability in most browser wallets, including MetaMask. According to them, the problem affects a small segment of users.
They have uncovered a case where, under certain conditions, the secret recovery phrase used by web wallets could be extracted from the disk of a hacked computer.
The wallet developers fixed the vulnerability in MetaMask Extension 10.11.3. However, they have warned that users who meet the following conditions may be at risk: the hard drive has not been encrypted, the recovery phrase was imported on someone else’s device or the computer was compromised, used the “Show Recovery Passphrase” checkbox to view the text on the screen.
The MetaMask team has noted the vulnerability is due to the fact that browsers do not consider attacks with physical access as a threat and store all text inputs in the device’s memory.