Rabby Wallet Fixes Silent Signature Extraction Vulnerability, Users Need to Update Plugin Promptly
As disclosed by security researcher V12 (@v12sec), the Rabby Wallet browser extension contains a silent signature extraction vulnerability that allows attackers to extract wallet signatures via malicious websites without user awareness, thereby draining wallet assets. The conditions required to trigger this vulnerability are extremely limited: users must simultaneously meet two conditions—connecting to a malicious website and manually setting the auto-lock timer to 10 minutes. Other timer settings are unaffected, and the mobile app is also unaffected. Rabby Wallet officially stated that a fix update was released on August 11 following the vulnerability's discovery. No actual exploitation cases have been detected so far. Users are advised to confirm as soon as possible that the extension has been updated to the latest version.