Other

"Critical privacy vulnerability — getting exposed by MetaMask"

2022-01-20 [vendor] MetaMask vulnerability
Primary Source ↗

Incident Details

Security researchers publicly disclosed a critical privacy vulnerability with the popular cryptocurrency wallet Metamask, where a malicious attacker can easily create an NFT and airdrop it to a victim to obtain their IP address (and thus potentially their location). Metamask founder Dan Finlay acknowledged that “this issue has been widely known for a long time”, and that the researchers were “right to call us out for not addressing it sooner. Starting work on it now. Thanks for the kick in the pants, and sorry we needed it.”

Technical Details

Initial Attack Vector
Software bug / unintentional loss
Vendor / Product
MetaMask vulnerability

Timeline

  1. 2022-01-20 Breach occurred
  2. 2022-01-20 Publicly disclosed