{"id":25372,"date":"2022-08-08T23:24:45","date_gmt":"2022-08-08T23:24:45","guid":{"rendered":"http:\/\/egrowonline.com\/?p=25372"},"modified":"2022-08-08T23:24:45","modified_gmt":"2022-08-08T23:24:45","slug":"how-secure-is-the-ethereum-sitting-in-your-metamask-wallet","status":"publish","type":"post","link":"http:\/\/egrowonline.com\/?p=25372","title":{"rendered":"How Secure Is the Ethereum Sitting in Your MetaMask Wallet?"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div style=\"background-color:transparent;background-size:20% 100%;background-image:linear-gradient(to right, rgba(0, 0, 0, 0.04) 1px, transparent 1px);background-position:0%;overflow:visible;font-size:1.2em;line-height:1.58;text-align:left\">\n<p class=\"font-meta-serif-pro font-normal text-lg sm:text-xl sm:leading-9 tracking-px text-body\"><span style=\"font-weight:400\">It\u2019s been an unrelenting week for <span class=\"link\"><a target=\"_blank\" href=\"https:\/\/decrypt.co\/50431\/metamask-crypto-wallet-review\" class=\"sc-adb616fe-0 ePvUAp\" rel=\"noopener\">MetaMask<\/a><\/span> developers.\u00a0<\/span><\/p>\n<p class=\"font-meta-serif-pro font-normal text-lg sm:text-xl sm:leading-9 tracking-px text-body\"><span style=\"font-weight:400\">Reacting to the news that <\/span><a target=\"_blank\" href=\"https:\/\/decrypt.co\/106649\/solana-wallet-hack-what-we-know-so-far\" class=\"sc-adb616fe-0 ePvUAp\" rel=\"noopener\"><span style=\"font-weight:400\">$4.5 million worth of funds<\/span><\/a><span style=\"font-weight:400\"> had been drained from thousands of software <a target=\"_blank\" href=\"https:\/\/decrypt.co\/?post_type=post&amp;p=5702\" rel=\"noreferrer noopener\" class=\"sc-adb616fe-0 ePvUAp\"><span class=\"sc-48a5c6a5-4 eylCNa\">wallets<\/span><\/a> on <span class=\"link\"><a target=\"_blank\" href=\"https:\/\/decrypt.co\/resources\/what-is-solana-a-scalable-decentralized-network-for-dapps\" class=\"sc-adb616fe-0 ePvUAp\" rel=\"noopener\">Solana<\/a><\/span>, the team behind MetaMask\u2014far and away the most popular software wallet for <a target=\"_blank\" href=\"https:\/\/decrypt.co\/?post_type=post&amp;p=5726\" rel=\"noreferrer noopener\" class=\"sc-adb616fe-0 ePvUAp\"><span class=\"sc-48a5c6a5-4 eylCNa\">Ethereum<\/span><\/a> and Ethereum-compatible networks\u2014<\/span><span style=\"font-weight:400\">combed through the wallet&#8217;s codebase to make sure users would not be affected by a similar hack.<\/span><\/p>\n<p class=\"font-meta-serif-pro font-normal text-lg sm:text-xl sm:leading-9 tracking-px text-body\"><span style=\"font-weight:400\">That kind of fire drill has been repeated elsewhere. On reports that the <a target=\"_blank\" href=\"https:\/\/decrypt.co\/106819\/near-protocol-wallet-breach-exposed-private-keys\" rel=\"noopener\" class=\"sc-adb616fe-0 ePvUAp\">Near Walle<\/a>t might have a vulnerability similar to the hacked Solana wallets, the protocol\u2019s Twitter account said Thursday night that it\u2019s \u201c<\/span><a target=\"_blank\" href=\"https:\/\/twitter.com\/NEARProtocol\/status\/1555271136254066690\" class=\"sc-adb616fe-0 ePvUAp\" rel=\"noopener\"><span style=\"font-weight:400\">highly recommended<\/span><\/a><span style=\"font-weight:400\">\u201d users change their security settings.<\/span><\/p>\n<p class=\"font-meta-serif-pro font-normal text-lg sm:text-xl sm:leading-9 tracking-px text-body\"><span style=\"font-weight:400\">Scanning for vulnerabilities after there\u2019s been an exploit is one way that developers handle security. Ideally, they find them before they\u2019ve been exploited. MetaMask has said previously that it\u2019s working to reorganize its teams to better respond to security issues, but there are signs that it\u2019s struggling to keep up.<\/span><\/p>\n<p><span class=\"\" \/><\/p>\n<h2 style=\"margin-top:2em;text-align:left;padding-bottom:16px;margin-bottom:16px;border-bottom:1px solid #dfe2e4\" class=\"sc-e93b592e-2 dtmzta\">Unanswered messages<\/h2>\n<p class=\"font-meta-serif-pro font-normal text-lg sm:text-xl sm:leading-9 tracking-px text-body\"><span style=\"font-weight:400\">In a recent example, Aurox CEO Giorgi Khazaradze said he found MetaMask\u2019s team to be unresponsive when he tried to tip them off about a vulnerability in June.<\/span><\/p>\n<p class=\"font-meta-serif-pro font-normal text-lg sm:text-xl sm:leading-9 tracking-px text-body\"><span style=\"font-weight:400\">He told <\/span><i><span style=\"font-weight:400\">Decrypt<\/span><\/i><span style=\"font-weight:400\"> that his team was looking at MetaMask\u2019s codebase\u2014which is open source and viewable in <\/span><a target=\"_blank\" href=\"https:\/\/github.com\/MetaMask\" class=\"sc-adb616fe-0 ePvUAp\" rel=\"noopener\"><span style=\"font-weight:400\">its GitHub repository<\/span><\/a><span style=\"font-weight:400\">\u2014because they\u2019re building their own browser extension wallet.\u00a0<\/span><\/p>\n<p class=\"font-meta-serif-pro font-normal text-lg sm:text-xl sm:leading-9 tracking-px text-body\"><span style=\"font-weight:400\">The wallet has been announced, but not yet launched. When it does, it\u2019ll be competing with MetaMask. To put it plainly: That means Khazaradze stands to benefit from casting doubt on what is, far and away, the biggest competitor for his new product.<\/span><\/p>\n<p class=\"font-meta-serif-pro font-normal text-lg sm:text-xl sm:leading-9 tracking-px text-body\"><span style=\"font-weight:400\">After all, ConsenSys, the company that develops MetaMask (and, full disclosure, an investor in <i>Decrypt<\/i>), just closed a $450 million Series D round at a <\/span><a target=\"_blank\" href=\"https:\/\/decrypt.co\/95090\/consensys-funding-ethereum-metamask-series-d\" class=\"sc-adb616fe-0 ePvUAp\" rel=\"noopener\"><span style=\"font-weight:400\">$7 billion<\/span><\/a><span style=\"font-weight:400\"> valuation\u2014helped in large part by the rate at which MetaMask has been attracting new users. As of March, MetaMask had more than <\/span><a target=\"_blank\" href=\"https:\/\/decrypt.co\/95039\/metamask-consensys-30-million-users\" class=\"sc-adb616fe-0 ePvUAp\" rel=\"noopener\"><span style=\"font-weight:400\">30 million monthly active users<\/span><\/a><span style=\"font-weight:400\">, a 42% increase over the 21 million it had in <\/span><a target=\"_blank\" href=\"https:\/\/decrypt.co\/86263\/ethereum-wallet-metamask-reports-21-million-users\" class=\"sc-adb616fe-0 ePvUAp\" rel=\"noopener\"><span style=\"font-weight:400\">November 2021<\/span><\/a><span style=\"font-weight:400\">.<\/span><\/p>\n<p class=\"font-meta-serif-pro font-normal text-lg sm:text-xl sm:leading-9 tracking-px text-body\"><span style=\"font-weight:400\">Khazaradze said his team realized that it would be possible to use an HTML element called an inline frame, or iframe, to add a hidden decentralized app, or dapp, to a webpage.<\/span><\/p>\n<p class=\"font-meta-serif-pro font-normal text-lg sm:text-xl sm:leading-9 tracking-px text-body\"><span style=\"font-weight:400\">That would mean an attacker could hypothetically create a page that looks like a legit application, but connects to another that the MetaMask user never sees. So instead of swapping some <span class=\"link\"><a target=\"_blank\" href=\"https:\/\/decrypt.co\/resources\/what-is-ethereum-quickly-explained-four-minute-guide\" class=\"sc-adb616fe-0 ePvUAp\" rel=\"noopener\">Ethereum<\/a><\/span>\u00a0for coins to support a new project or buying an <span class=\"link\"><a target=\"_blank\" href=\"https:\/\/decrypt.co\/resources\/non-fungible-tokens-nfts-explained-guide-learn-blockchain\" class=\"sc-adb616fe-0 ePvUAp\" rel=\"noopener\">NFT<\/a><\/span>, the user could unwittingly be sending their crypto straight to a thief\u2019s wallet.<\/span><\/p>\n<p class=\"font-meta-serif-pro font-normal text-lg sm:text-xl sm:leading-9 tracking-px text-body\"><span style=\"font-weight:400\">This kind of vulnerability could take advantage of the fact that MetaMask automatically prompts users to connect to a dapp if it detects one on a webpage. It\u2019s standard behavior for the browser extension version of MetaMask. Outside the context of vulnerabilities and attackers, it\u2019s a feature that puts fewer clicks between a user and their ability to interact with dapps.\u00a0<\/span><\/p>\n<p class=\"font-meta-serif-pro font-normal text-lg sm:text-xl sm:leading-9 tracking-px text-body\"><span style=\"font-weight:400\">It\u2019s similar, but not quite the same, as a clickjacking vulnerability that MetaMask paid a <\/span><a target=\"_blank\" href=\"https:\/\/medium.com\/metamask\/metamask-awards-bug-bounty-for-clickjacking-vulnerability-9f53618e3c3a\" class=\"sc-adb616fe-0 ePvUAp\" rel=\"noopener\"><span style=\"font-weight:400\">$120,000 bounty<\/span><\/a><span style=\"font-weight:400\"> for in June. With that, an attacker hides MetaMask itself on a webpage and tricks the user into revealing private data or transferring funds.<\/span><\/p>\n<p class=\"font-meta-serif-pro font-normal text-lg sm:text-xl sm:leading-9 tracking-px text-body\"><span style=\"font-weight:400\">\u201cThat\u2019s a different vulnerability. That was within MetaMask itself. Basically, you could iframe MetaMask and then clickjack people,\u201d Khazaradze said. \u201cWhereas the one we found is iframing dapps. The wallet automatically connects to those dapps, which can allow an attacker to trick you to perform specific transactions.\u201d<\/span><\/p>\n<p class=\"font-meta-serif-pro font-normal text-lg sm:text-xl sm:leading-9 tracking-px text-body\"><span style=\"font-weight:400\">Khazaradze said he attempted to contact MetaMask about the vulnerability on June 27. First he tried the company\u2019s support chat feature and said he was told to make a post on the app\u2019s GitHub. But he didn\u2019t feel comfortable doing that.<\/span><\/p>\n<p class=\"font-meta-serif-pro font-normal text-lg sm:text-xl sm:leading-9 tracking-px text-body\"><span style=\"font-weight:400\">He said he then emailed MetaMask support directly, but got an unhelpful response: \u201cWe are experiencing extremely high volumes of inquiries. In an effort to improve our efficiencies on responding to support inquiries, direct emails to support are no longer enabled.\u201d<\/span><\/p>\n<p class=\"font-meta-serif-pro font-normal text-lg sm:text-xl sm:leading-9 tracking-px text-body\"><span style=\"font-weight:400\">At that point, Khazaradze said he gave up trying to let the team know about the vulnerability and reached out to <\/span><i><span style=\"font-weight:400\">Decrypt<\/span><\/i><span style=\"font-weight:400\">.\u00a0<\/span><\/p>\n<h2 style=\"margin-top:2em;text-align:left;padding-bottom:16px;margin-bottom:16px;border-bottom:1px solid #dfe2e4\" class=\"sc-e93b592e-2 dtmzta\">MetaMask responds<\/h2>\n<p class=\"font-meta-serif-pro font-normal text-lg sm:text-xl sm:leading-9 tracking-px text-body\"><span style=\"font-weight:400\">Herman Junge, a member of MetaMask\u2019s security team, told <\/span><i><span style=\"font-weight:400\">Decrypt<\/span><\/i><span style=\"font-weight:400\"> that the app\u2019s support team wouldn\u2019t have wanted an iframe vulnerability listed on GitHub.<\/span><\/p>\n<p class=\"font-meta-serif-pro font-normal text-lg sm:text-xl sm:leading-9 tracking-px text-body\"><span style=\"font-weight:400\">\u201cAt MetaMask, we take iframe reports seriously and give them due procedure through our bug bounty program at HackerOne. If a security researcher sends their report using another instance, we invite them to go to HackerOne,\u201d he said in an email. \u201cWe don\u2019t have in our records any message where we encourage researchers to post an iframe report into GitHub.\u201d<\/span><\/p>\n<p class=\"font-meta-serif-pro font-normal text-lg sm:text-xl sm:leading-9 tracking-px text-body\"><span style=\"font-weight:400\">In an email conversation with MetaMask public relations, <\/span><i><span style=\"font-weight:400\">Decrypt<\/span><\/i><span style=\"font-weight:400\"> described the vulnerability that the Aurox team claims to have found. In his emailed statement, Junge didn\u2019t acknowledge the purported vulnerability or say that MetaMask would be investigating the issue.<\/span><\/p>\n<p class=\"font-meta-serif-pro font-normal text-lg sm:text-xl sm:leading-9 tracking-px text-body\"><span style=\"font-weight:400\">He did, however, say that publishing an active security issue before the app\u2019s team has a chance to address it can \u201cput innocent people at unnecessary risk.\u201d But so far, the language used in its support messages doesn\u2019t mention anything about HackerOne, where MetaMask launched a <\/span><a target=\"_blank\" href=\"https:\/\/hackerone.com\/metamask?type=team\" class=\"sc-adb616fe-0 ePvUAp\" rel=\"noopener\"><span style=\"font-weight:400\">bug bounty program<\/span><\/a><span style=\"font-weight:400\"> in June.<\/span><\/p>\n<h2 style=\"margin-top:2em;text-align:left;padding-bottom:16px;margin-bottom:16px;border-bottom:1px solid #dfe2e4\" class=\"sc-e93b592e-2 dtmzta\">Resorting to &#8216;spectacle&#8217;<\/h2>\n<p class=\"font-meta-serif-pro font-normal text-lg sm:text-xl sm:leading-9 tracking-px text-body\"><span style=\"font-weight:400\">In the security community, it\u2019s professional courtesy to privately notify a company about a vulnerability for the same reason it\u2019s courteous not to shout that someone\u2019s fly is down. The discretion gives them a chance to fix it before other people notice.\u00a0<\/span><\/p>\n<p class=\"font-meta-serif-pro font-normal text-lg sm:text-xl sm:leading-9 tracking-px text-body\"><span style=\"font-weight:400\">Reporting vulnerabilities discreetly keeps the information away from people who would exploit it before developers have had a chance to implement a fix. But when the reporting process is confusing or the recipient seems unresponsive, vulnerabilities go public before there\u2019s a fix, usually in an effort to force the team to act.<\/span><\/p>\n<p class=\"font-meta-serif-pro font-normal text-lg sm:text-xl sm:leading-9 tracking-px text-body\"><span style=\"font-weight:400\">Janine Romer, a privacy researcher and investigative journalist, said she\u2019s seen lots of instances of people trying discreet lines of communication first and then switching to Twitter to report vulnerabilities.<\/span><\/p>\n<p class=\"font-meta-serif-pro font-normal text-lg sm:text-xl sm:leading-9 tracking-px text-body\"><span style=\"font-weight:400\">\u201cSimilar things happen with Bitcoin wallets where the only way sometimes to get attention for stuff is to just tweet at people, which is bad. That should not be the way that things are handled,\u201d she told <\/span><i><span style=\"font-weight:400\">Decrypt<\/span><\/i><span style=\"font-weight:400\">. \u201cIt should also be possible to report things privately and not have to make a public spectacle. But then it kind of incentivizes people to make a public spectacle because nobody&#8217;s answering privately.\u201d<\/span><\/p>\n<p class=\"font-meta-serif-pro font-normal text-lg sm:text-xl sm:leading-9 tracking-px text-body\"><span style=\"font-weight:400\">In January, Alex Lupascu, co-founder of Omnia Protocol, said <\/span><a target=\"_blank\" href=\"https:\/\/twitter.com\/alxlpsc\/status\/1484102749566476291\" class=\"sc-adb616fe-0 ePvUAp\" rel=\"noopener\"><span style=\"font-weight:400\">on Twitter<\/span><\/a><span style=\"font-weight:400\"> that he and his team found a \u201ccritical privacy vulnerability\u201d in MetaMask and linked to a <\/span><a target=\"_blank\" href=\"https:\/\/medium.com\/@alxlpsc\/critical-privacy-vulnerability-getting-exposed-by-metamask-693c63c2ce94\" class=\"sc-adb616fe-0 ePvUAp\" rel=\"noopener\"><span style=\"font-weight:400\">blog post<\/span><\/a><span style=\"font-weight:400\"> describing how an attacker could exploit it.<\/span><\/p>\n<p class=\"font-meta-serif-pro font-normal text-lg sm:text-xl sm:leading-9 tracking-px text-body\"><span style=\"font-weight:400\">Harry Denley, a security researcher who works with MetaMask, <\/span><a target=\"_blank\" href=\"https:\/\/twitter.com\/sniko_\/status\/1484168406861557760\" class=\"sc-adb616fe-0 ePvUAp\" rel=\"noopener\"><span style=\"font-weight:400\">replied to ask<\/span><\/a><span style=\"font-weight:400\"> if the team had been notified or said they were working on it. Lupascu said they had, but that he first made his report five months ago and the vulnerability was still exploitable.<\/span><\/p>\n<p class=\"font-meta-serif-pro font-normal text-lg sm:text-xl sm:leading-9 tracking-px text-body\"><span style=\"font-weight:400\">Eventually MetaMask co-founder Dan Finlay weighed in.<\/span><\/p>\n<p class=\"font-meta-serif-pro font-normal text-lg sm:text-xl sm:leading-9 tracking-px text-body\"><span style=\"font-weight:400\">\u201cYeah, I think this issue has been widely known for a long time, so I don\u2019t think a disclosure period applies,\u201d he wrote on Twitter. \u201cAlex is right to call us out for not addressing it sooner. Starting to work on it now. Thanks for the kick in the pants, and sorry we needed it.\u201d<\/span><\/p>\n<h2 style=\"margin-top:2em;text-align:left;padding-bottom:16px;margin-bottom:16px;border-bottom:1px solid #dfe2e4\" class=\"sc-e93b592e-2 dtmzta\">Safely using software wallets<\/h2>\n<p class=\"font-meta-serif-pro font-normal text-lg sm:text-xl sm:leading-9 tracking-px text-body\"><span style=\"font-weight:400\">A couple months later, the aforementioned bug bounty program was launched. It\u2019s not as though all MetaMask vulnerability reports go unaddressed. Web3 security firm Halborn Security reported a vulnerability that could impact MetaMask users in June and got a <\/span><a target=\"_blank\" href=\"https:\/\/twitter.com\/MetaMask\/status\/1537103629613551624\" class=\"sc-adb616fe-0 ePvUAp\" rel=\"noopener\"><span style=\"font-weight:400\">hat tip<\/span><\/a><span style=\"font-weight:400\"> from the MetaMask Twitter account for it.<\/span><\/p>\n<p class=\"font-meta-serif-pro font-normal text-lg sm:text-xl sm:leading-9 tracking-px text-body\"><span style=\"font-weight:400\">David Schwed, Halborn\u2019s chief operating officer, said he found the MetaMask team responsive. They addressed and patched the vulnerability. Even so, he said users should be cautious about keeping any substantial funds in a software wallet.<\/span><\/p>\n<p class=\"font-meta-serif-pro font-normal text-lg sm:text-xl sm:leading-9 tracking-px text-body\"><span style=\"font-weight:400\">\u201cI wouldn\u2019t necessarily take a shot at MetaMask. MetaMask serves a certain purpose right now. Now if I was an organization, I wouldn\u2019t store hundreds of millions of dollars on MetaMask, but I probably wouldn\u2019t store it on any particular wallet,\u201d he said. \u201cI would diversify my holdings and self-custody and use other security practices to manage my risk.\u201d<\/span><\/p>\n<p class=\"font-meta-serif-pro font-normal text-lg sm:text-xl sm:leading-9 tracking-px text-body\"><span style=\"font-weight:400\">For him, the safest and most responsible way to use software wallets is to keep private keys on a hardware security module, or HSM. Two of the most popular hardware wallets, as they\u2019re also known in crypto, include the Ledger and Trezor.<\/span><\/p>\n<p class=\"font-meta-serif-pro font-normal text-lg sm:text-xl sm:leading-9 tracking-px text-body\"><span style=\"font-weight:400\">\u201cAt the end of the day, that\u2019s what\u2019s actually storing my private keys and that\u2019s where the signing of the transactions is actually happening,\u201d Schwed said. \u201cAnd your [browser] wallet is really just a mechanism to broadcast out to the chain and construct the transaction.\u201d<\/span><\/p>\n<h2 style=\"margin-top:2em;text-align:left;padding-bottom:16px;margin-bottom:16px;border-bottom:1px solid #dfe2e4\" class=\"sc-e93b592e-2 dtmzta\">Closing the gap<\/h2>\n<p class=\"font-meta-serif-pro font-normal text-lg sm:text-xl sm:leading-9 tracking-px text-body\"><span style=\"font-weight:400\">The problem is that not everybody uses browser extension wallets that way. But there have been efforts to address it, both by giving developers better guidance on how to build security into their apps and teaching users how to keep their funds safe.\u00a0<\/span><\/p>\n<p class=\"font-meta-serif-pro font-normal text-lg sm:text-xl sm:leading-9 tracking-px text-body\"><span style=\"font-weight:400\">That\u2019s where the CryptoCurrency Certification Consortium, or C4, comes in. It\u2019s the same organization that created the Bitcoin and Ethereum professional certifications. Fun fact: Ethereum creator Vitalik Buterin helped write the Certified Bitcoin Professional exam before he invented Ethereum.\u00a0<\/span><\/p>\n<p class=\"font-meta-serif-pro font-normal text-lg sm:text-xl sm:leading-9 tracking-px text-body\"><span style=\"font-weight:400\">Jessica Levesque, executive director at C4, said there\u2019s still a big knowledge gap for new crypto adopters.<\/span><\/p>\n<p class=\"font-meta-serif-pro font-normal text-lg sm:text-xl sm:leading-9 tracking-px text-body\"><span style=\"font-weight:400\">\u201cWhat\u2019s kind of scary about this is that people who have been around crypto for a long time probably are like, it\u2019s pretty clear you shouldn\u2019t keep a lot of money on MetaMask or any hot wallet. Move it off,\u201d she told <\/span><i><span style=\"font-weight:400\">Decrypt<\/span><\/i><span style=\"font-weight:400\">. \u201cBut most of us, when we first started, we didn\u2019t know that.\u201d<\/span><\/p>\n<p class=\"font-meta-serif-pro font-normal text-lg sm:text-xl sm:leading-9 tracking-px text-body\"><span style=\"font-weight:400\">On the other end of things, there\u2019s been a prevailing assumption that open-source projects are more secure because their code is available for review by independent researchers.\u00a0<\/span><\/p>\n<p class=\"font-meta-serif-pro font-normal text-lg sm:text-xl sm:leading-9 tracking-px text-body\"><span style=\"font-weight:400\">In fact, on Wednesday, in light of the Solana wallet hack, a developer who goes by fubuloubu on Twitter, garnered a lot of attention for saying it\u2019s \u201c<\/span><a target=\"_blank\" href=\"https:\/\/twitter.com\/fubuloubu\/status\/1554828581418815488?ref_src=twsrc%5Etfw\" class=\"sc-adb616fe-0 ePvUAp\" rel=\"noopener\"><span style=\"font-weight:400\">irresponsible not to have open source code in crypto<\/span><\/a><span style=\"font-weight:400\">.\u201d<\/span><\/p>\n<p class=\"font-meta-serif-pro font-normal text-lg sm:text-xl sm:leading-9 tracking-px text-body\"><span style=\"font-weight:400\">Noah Buxton, who leads Armanino\u2019s blockchain and digital asset practice and sits on C4\u2019s CryptoCurrency Security Standard Committee, said the low visibility of smaller projects or offers to pay bug bounties in native tokens can act as a disincentive for researchers to spend their time looking at them.<\/span><\/p>\n<p class=\"font-meta-serif-pro font-normal text-lg sm:text-xl sm:leading-9 tracking-px text-body\"><span style=\"font-weight:400\">\u201cIn open source, the attention of developers is driven largely by either notoriety or some monetization,\u201d he said. \u201cWhy spend time looking for bugs on a new decentralized exchange when there\u2019s very little liquidity, the governance token isn\u2019t worth anything and the team wants to pay you in the governance token for a bounty. I would rather spend time on Ethereum on another layer 1.\u201d<\/span><\/p>\n<div class=\"my-4 border-b border-decryptGridline\">\n<p><span class=\"border-t-4 border-l-4 w-4 h-4 sm:border-t-[6px] sm:border-l-[6px] sm:w-6 sm:h-6 border-decryptPurple dark:border-decryptNeon absolute top-4 left-4 sm:top-6 sm:left-6\" \/><span class=\"border-t-4 border-l-4 w-4 h-4 sm:border-t-[6px] sm:border-l-[6px] sm:w-6 sm:h-6 border-decryptPurple dark:border-decryptNeon absolute rotate-180 bottom-4 right-4 sm:bottom-6 sm:right-6\" \/><\/p>\n<h3 class=\"font-ak-bold text-xl sm:text-3xl mb-6 md:text-center\">Stay on top of crypto news, get daily updates in your inbox.<\/h3>\n<\/p>\n<\/div>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/decrypt.co\/106848\/how-secure-ethereum-metamask-wallet\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>It\u2019s been an unrelenting week for MetaMask developers.\u00a0 Reacting to the news that $4.5 million worth of funds had been drained from thousands of software wallets on Solana, the team behind MetaMask\u2014far and away the most popular software wallet for Ethereum and Ethereum-compatible networks\u2014combed through the wallet&#8217;s codebase to make sure users would not be [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":25373,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","enabled":false}}},"categories":[41],"tags":[158,440,1651,10324,1130],"class_list":["post-25372","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ethereum","tag-ethereum","tag-metamask","tag-secure","tag-sitting","tag-wallet"],"jetpack_publicize_connections":[],"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"http:\/\/egrowonline.com\/wp-content\/uploads\/2022\/08\/metamask-ethereum-wallet-gID_6.jpeg","_links":{"self":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts\/25372","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=25372"}],"version-history":[{"count":1,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts\/25372\/revisions"}],"predecessor-version":[{"id":25374,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts\/25372\/revisions\/25374"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/media\/25373"}],"wp:attachment":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=25372"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=25372"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=25372"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}