Stick around on our web page for 10 minutes and all your funds are gone. Just connect your wallet to the dApp and enjoy some Temple Run. Unlock your wallet again and it’s empty 😇. A silent signature extraction in @Rabby_io, leading to a full wallet drain. 🧵

Aug 19, 2026 · 4:30 PM UTC

42
131
967
320,777
We disclosed our finding on 3 August. We're grateful for how prompt Rabby's team was to acknowledge and fix the bug in less than 24 hours. We also reviewed the patch and confirmed it was effective.
Replying to @v12sec
We resolved the vulnerability upon discovery and released an update on August 11. Please ensure your Rabby extension is up to date. The mobile app is unaffected. The conditions required to trigger this vulnerability are extremely limited: 1/ The wallet must be connected to a malicious website. 2/ The user must have manually set their auto-lock timer to specifically 10 minutes (all other timer settings are completely unaffected). No exploits have been detected in the wild.
2
50
7,927
Sort replies: Relevant Recent Liked
Replying to @v12sec
We resolved the vulnerability upon discovery and released an update on August 11. Please ensure your Rabby extension is up to date. The mobile app is unaffected. The conditions required to trigger this vulnerability are extremely limited: 1/ The wallet must be connected to a malicious website. 2/ The user must have manually set their auto-lock timer to specifically 10 minutes (all other timer settings are completely unaffected). No exploits have been detected in the wild.
28
94
560
312,976
Replying to @v12sec @Rabby_io
nightmare fuel. gud wrk
23
3,108
Replying to @v12sec @Rabby_io
Use a hardware wallet
4
10
5,298
Replying to @v12sec @Rabby_io
insane find
3
2,628
Replying to @v12sec @Rabby_io
based finding 🔥
2
2,118
Replying to @v12sec @Rabby_io
i have been mentioning this to everyone today and it blows everyone’s mind that this was possible
3
907
Replying to @v12sec @Rabby_io
Silent signature extraction is exactly the kind of vulnerability users have almost no chance of spotting themselves.
1
1,218
Replying to @v12sec @Rabby_io
bruh
1
817
Replying to @Rabby_io
Hey @v12sec we as a community launched a token inspired by your work The generated fees are routed to you (RenwaX23) and can optionally be used to support ongoing development I saw that you got rewarded with $3k which is a joke for what you've done Contract: 0xce40db76b14e60405f93e6a6745bb0f337b55ba3
1
230
Replying to @v12sec @Rabby_io
Update plz @Rabby_io
1
1
866
Replying to @v12sec @Rabby_io
Absolutely fantastic work guys thank you for putting in the time on this
1
1,466
Replying to @v12sec @Rabby_io
Similar exploit found in ledger
🚨Every Ledger running the Ethereum app is vulnerable to signature substitution A malicious dApp with WebHID access could race an APDU during your transaction review and swap the tx being signed while the device still shows the original Here's what you need to know:
1
385
Replying to @v12sec @Rabby_io
Would this work on a hardware wallet??
1
1,907
Replying to @v12sec @Rabby_io
Has this been tested against other wallets? Also do you have a public PoC?
669
Replying to @v12sec @Rabby_io
Holy shit
1,123
Replying to @v12sec @Rabby_io
Interestingg!! And scary at same time 😬
1
656
Replying to @v12sec @Rabby_io
insane find wth v12 master race
567
Replying to @v12sec @Rabby_io
amazing find
427
Replying to @v12sec @Rabby_io
Damn impressive findings
3
3,133
Replying to @v12sec @Rabby_io
Bruh how did you even come up with this
2
1,065
Replying to @v12sec @Rabby_io
Did Rabby patch this yet? I guess I'm thankful for a hardware wallet with Rabby here...
2
897
Replying to @v12sec @Rabby_io
Thats scary
1
1,430
Replying to @v12sec @Rabby_io
Even before the Rabby fix, this wouldn't affect a hardware wallet connected to Rabby extension correct?
2
2,076
Replying to @v12sec @Rabby_io
would not having an auto lock would mitigate this? then its at least possible someone would notice the pending scam tx?
1
1,045
Replying to @v12sec @Rabby_io
Militereum would tell you this, even if the wallet does not tell you anything. There is no escaping Militereum.
1
1
214
Replying to @v12sec @Rabby_io
You guys should consider launching a subnet on bittensor:native or better yet, partner with @_redteam_
276
Replying to @v12sec @Rabby_io
ma fav wallet is ecxactly rabby
318