By Interestana AI Editorial — AI-drafted, human-overseen. How we report
MetaMask Discloses Infrastructure Security Incident
On Thursday, cryptocurrency wallet provider MetaMask disclosed an ongoing infrastructure security incident that has affected some of its infrastructure. This incident has led to the compromise of user data for individuals who interacted with specific decentralized applications (dApps) through MetaMask's infrastructure. The company stated that the breach was discovered on June 5, 2024, and that it immediately initiated an investigation and took steps to contain the incident.
MetaMask, developed by ConsenSys, is a widely used non-custodial cryptocurrency wallet that allows users to interact with the Ethereum blockchain and other compatible networks. It serves as a gateway to decentralized finance (DeFi) applications, NFTs, and other Web3 services. The security incident specifically impacted users who utilized the 'Infura' service, which is a suite of tools and infrastructure provided by ConsenSys that helps developers build and deploy applications on Ethereum. Infura provides API access to the Ethereum network, allowing dApps to function without users needing to run their own nodes.
According to a statement released by MetaMask, the incident involved unauthorized access to a third-party data analytics tool used by the company. This tool was used to track user activity on certain dApps. The compromised data includes wallet addresses, transaction history, and potentially other personally identifiable information (PII) for a subset of users. MetaMask emphasized that the core MetaMask wallet software itself was not compromised, and users' private keys and funds remain secure. The company has begun notifying affected users directly and is advising them to be vigilant against phishing attempts and to review their transaction history for any suspicious activity.
In response to the incident, MetaMask has suspended its data analytics tool and is conducting a thorough review of its security protocols and third-party vendor relationships. The company is also working with cybersecurity experts to further investigate the breach and implement enhanced security measures. This incident highlights the ongoing security challenges within the cryptocurrency ecosystem, particularly concerning the infrastructure that supports dApp interactions. Users are encouraged to enable two-factor authentication on their accounts and to exercise caution when interacting with any new dApps or clicking on unsolicited links. The full extent of the data compromised and the specific dApps affected are still under investigation, with further updates expected from MetaMask as the situation evolves.
Original source — read the full reporting at the publisher:
Read on BleepingComputerGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.