Top

Rabby patches browser extension flaw that could expose signatures

August 20, 2026, 3:45 AM
Rabby said via its official X account that it discovered a vulnerability in its browser extension that could allow unauthorized extraction of signatures under certain conditions, and completed a patch on Aug. 11. The issue was found to potentially expose funds if a user connected a wallet to a malicious dApp, set the auto-lock timer to 10 minutes, remained on that dApp for 10 minutes, and then unlocked the wallet again. Rabby added that its mobile app was not affected, no cases of actual fund theft have been confirmed as the flaw occurred only under limited conditions, and users should update the extension immediately.

Leave the first comment

You need to log in to leave a comment.
Log In
Loading