Stick around on our web page for 10 minutes and all your funds are gone.
Just connect your wallet to the dApp and enjoy some Temple Run. Unlock your wallet again and it’s empty 😇.
A silent signature extraction in @Rabby_io, leading to a full wallet drain. 🧵
Aug 19, 2026 · 4:30 PM UTC
42
131
967
320,777
We disclosed our finding on 3 August. We're grateful for how prompt Rabby's team was to acknowledge and fix the bug in less than 24 hours. We also reviewed the patch and confirmed it was effective.
We resolved the vulnerability upon discovery and released an update on August 11. Please ensure your Rabby extension is up to date. The mobile app is unaffected.
The conditions required to trigger this vulnerability are extremely limited:
1/ The wallet must be connected to a malicious website.
2/ The user must have manually set their auto-lock timer to specifically 10 minutes (all other timer settings are completely unaffected).
No exploits have been detected in the wild.
2
50
7,927





























