MetaMask Knows It Has a Critical Privacy Vulnerability, But Hasn’t Fixed It

Key Takeaways

  • Cryptographer Alexandru Lupascu discovered a critical vulnerability in the most popular Web3 wallet MetaMask.
  • Lupascu found that malicious entities can find MetaMask mobile users’ IP data by airdropping them NFTs.
  • MetaMask founder Daniel Finlay admitted in a Twitter post the “issue has been widely known for a long time.” It’s yet to fix the problem.

Alexandru Lupascu says that MetaMask users who access the app on mobile devices are at risk of exposing their IP address.

MetaMask Mobile App Can Expose Users’ Privacy

MetaMask users may be putting their privacy at risk, a cryptographer has warned.

Alexandru Lupascu, who co-founded the privacy node service OMNIA Protocol, says that he has found a critical vulnerability in the ConsenSys’ popular Web3 wallet that gives hackers a way to access users’ IP addresses, thus creating a privacy risk. An IP address is a unique global identifier assigned to a device connected to the web. As users can store their crypto assets on MetaMask wallets, an IP address vulnerability is a major concern.

Lupascu published a blog post explaining how the vulnerability can be exploited by minting and airdropping an NFT collectible to a MetaMask-connected Ethereum address used on a mobile phone.

NFTs are digital assets that denote the ownership of content such as digital art, music, and memes. They offer a way to tokenize content but typically do not store the actual content. Since storing image data on a blockchain like Ethereum can be expensive, NFTs contain Uniform Resource Locators that point to the data. The content for NFTs is often stored either on a decentralized storage network like IPFS or on remote centralized cloud servers.

By default, the MetaMask mobile app displays NFTs stored in an address using a URL function call to the image data. This data is hosted on remote servers. The process is done without asking for the user’s consent in order to display what NFTs are contained in their Ethereum wallet.

During this fetching process, all server gateways handling the transmission of image data receive the user’s IP information. Generally, the projects operating the servers for the image data keeps the data secure.

In his investigation, Lupascu determined that malicious entities can find MetaMask users’ IP data and exploit the information to execute targeted attacks. In his blog post, Lupascu explained:

“If a malicious actor only knows your blockchain address, he can mint an NFT with a URL pointing to his server and transfer the NFT’s ownership to your address. Thus, when your crypto wallet fetches the remote image from the server, it will compromise your privacy.”

Lupascu tested the vulnerability by minting an NFT on OpenSea based on the ERC-1155 standard. He then used a smart contract editor to change the original URL linked with the NFT to point to a new server under his control. Then, Lupascu sent the NFT to an Ethereum address. When he accessed the address through the MetaMask mobile app, his IP address appeared in the server he controlled. He said it cost about $50 to execute the attack.

Lupascu told Crypto Briefing that he notified the MetaMask team about the issue in mid-December 2021, meaning the Web3 wallet has been aware of the issue for at least a month. The MetaMask team promised to release a patch by the second quarter of 2022–a timeframe Lupascu considers “unacceptable” given the severity of the matter.

Addressing the vulnerability, MetaMask founder Daniel Finlay admitted in a tweet response to Lupascu that the “issue has been widely known for a long time.” He added:

“Alex is right to call us out for not addressing it sooner. Starting work on it now. Thanks for the kick in the pants, and sorry we needed it.”

Finlay has also proposed that the wallet could “only load IPFS-type links by default.” Furthermore, MetaMask users will have to give explicit consent to fetch NFT data stored on third-party servers.

Meanwhile, Lupascu says that he thinks Ethereum users should be vigilant if they receive airdropped NFTs, and that it’s advisable to only access them through OpenSea. “Until this issue gets fixed on the mobile application, use the OpenSea platform with any Web3 compatible wallet to explore your collectibles. A kind reminder to everyone that off-chain privacy is really important—do not neglect it,” he said.

In recent months, NFT collectors have lost millions of dollars worth of digital assets through attacks, hacks, and scams. Many of the affected users stored valuable NFTs from Bored Ape Yacht Club and other sought-after collections on MetaMask wallets and suffered from phishing attacks. As MetaMask is a hot wallet, thieves can drain funds with relative ease once they have a user’s private key. As the private keys for a hot wallet can be compromised through phishing and malware attacks, they are widely considered less secure than cold storage options such as hardware wallets, which require access to a physical device to access the funds.

MetaMask is the most popular Web3 wallet for accessing Ethereum and other EVM-compatible blockchain networks. It had more than 21 million monthly active users as of November 2021, according to a ConsenSys press release.

Disclosure: At the time of writing, the author of this piece owned ETH and other cryptocurrencies.

The information on or accessed through this website is obtained from independent sources we believe to be accurate and reliable, but Decentral Media, Inc. makes no representation or warranty as to the timeliness, completeness, or accuracy of any information on or accessed through this website. Decentral Media, Inc. is not an investment advisor. We do not give personalized investment advice or other financial advice. The information on this website is subject to change without notice. Some or all of the information on this website may become outdated, or it may be or become incomplete or inaccurate. We may, but are not obligated to, update any outdated, incomplete, or inaccurate information.

You should never make an investment decision on an ICO, IEO, or other investment based on the information on this website, and you should never interpret or otherwise rely on any of the information on this website as investment advice. We strongly recommend that you consult a licensed investment advisor or other qualified financial professional if you are seeking investment advice on an ICO, IEO, or other investment. We do not accept compensation in any form for analyzing or reporting on any ICO, IEO, cryptocurrency, currency, tokenized sales, securities, or commodities.

See full terms and conditions.

Hacker Admits to Stealing 88 ETH in NFT Scam, Then Returns It

News

A hacker has returned over $340,000 in ETH to the Creature Toadz NFT project after posting a fake mint link in Discord. Despite the return of the funds, some members…

$1.8M Lost to Fake MetaMask Token Honeypot Scam

A fake MetaMask token has conned traders out of over $1.8 million. Hackers injected code into the DEXTools application’s front end, convincing traders that the token was verified. The MetaMask…

Bored Ape NFT Collector Loses $2.2M in Phishing Scam

News

An NFT collector has lost millions of dollars’ worth of NFTs in an apparent phishing attack. NFT Collector Targeted With a Phishing Attack A New York-based art curator and NFT…

Is Time on our Side? The Case for Bitcoin’s Lengthening Cycles

One of the many unique features of BTC is its halving process, which is often accompanied by a bullish movement and preceded by bearish consolidation. Bitcoin’s halving events have been…

Note: This article have been indexed to our site. We do not claim legitimacy, ownership or copyright of any of the content above. To see the article at original source Click Here

Related Posts
Reactions against Russia continue: largest South Korean exchanges block Russian IP’s thumbnail

Reactions against Russia continue: largest South Korean exchanges block Russian IP’s

Russia› Exchanges Leading exchange platforms show differences in their response to Russian invasion of Ukraine. While Coinbase and Binance have refused to join the sanctions, five of South Korea's leading exchange platforms have banned Russian IP's. Cover art/illustration via CryptoSlateRussia invaded Ukraine 7 days ago, and the world continues to show its reaction. As Russia…
Read More
Automotive: Renault installs an "XL High Speed ​​press" in Morocco thumbnail

Automotive: Renault installs an “XL High Speed ​​press” in Morocco

Renault Group Maroc a procédé à l’inauguration de la « presse XL High Speed », presse d’emboutissage de haute performance industrielle, ce vendredi 24 décembre 2021, en présence du ministre de l’Industrie et du Commerce, Ryad Mezzour, à son usine de Tanger. L’Afrique possède désormais sa « presse XL High Speed » et le Maroc peut s’enorgueillir de l’avoir…
Read More
How to build an NFT game without selling out thumbnail

How to build an NFT game without selling out

This week, let’s talk about NFT games, as we have seen a surge in many games that utilize tokens in recent years, gaining some massive levels of interest. In fact, you can’t really talk about blockchain applications without acknowledging that games seem to be the most dominant applications being built these days, as the past…
Read More
Si la Russie envahit l'Ukraine, «il n'y aura plus» de gazoduc Nord Stream 2, dit Joe Biden thumbnail

Si la Russie envahit l’Ukraine, «il n’y aura plus» de gazoduc Nord Stream 2, dit Joe Biden

Par Le Figaro avec AFPPublié le 07/02/2022 à 23:18, Mis à jour le 08/02/2022 à 10:43 Les États-Unis font valoir que cette infrastructure dote Moscou d'un levier énergétique et stratégique trop important, alors qu'une escalade militaire en Ukraine est crainte par Washington. Le président américain Joe Biden et le chancelier allemand Olaf Scholz ont vanté leur…
Read More
Index Of News
Total
0
Share