MetaMask / MetaMask/metamask-extension

Vault recovery issues and improvements

Open
#18,684 0 comments 0 reactions 0 assignees View on GitHub
team-accounts-framework type-enhancement
Dominant language
TypeScript
Stars
13.2k
Forks
5.6k
Avg merge
2d 5h
Merged PRs (30d)
451

Description

### Describe the bug

There are a few issues and potential improvements that we need to highlight regarding the vault recovery process. We've encountered each of these in discussions with various team members in Customer Success, data collected from users, and via direct feedback.

For clarity, current support documentation on this includes:

- [How do I access my accounts without my Secret Recovery Phrase?](https://support.metamask.io/hc/en-us/articles/13112366068251) -- a kind of triage article
- [How to recover your Secret Recovery Phrase](https://support.metamask.io/hc/en-us/articles/360018766351). This article garnered 26k views in Q1 2023.

The issues we'd like to record are:

- **We only have a working vault recovery method for Chrome-based browsers**. This, of course, means that users not on Chrome or Chrome-based browsers are excluded, and Mobile users are entirely excluded. The iOS method we currently have documented no longer works, and Android has never had one. The Firefox method is a few years out of date and, as far as we understand, doesn't work.
- **Multiple vault files appear**. Our previous understanding was that each time an SRP restored MetaMask (including immediately after install, i.e. the very first time), a new vault was created _and_ the previous one **overwritten**. However, reports from users have indicated that there are often multiple vault files, at least on Chrome.

Based on this, we would like to initiate discussion on whether or not:
- **We should develop vault recovery into a built-in feature**. Given that this method is possible in some cases, and a lot of users find themselves in this position, there's a case to be made/discussed that it should be developed into a full feature. Happy to collate some more data from CS to inform this decision.
- We could add vault recovery methods for browsers other than Chrome and for Mobile users.

### Steps to reproduce

n/a

### Error messages or log output

_No response_

### Version

n/a

### Build type

None

### Browser

Other (please elaborate in the "Additional Context" section)

### Operating system

Other (please elaborate in the "Additional Context" section)

### Hardware wallet

_No response_

### Additional context

This issue affects all operating systems and browsers.

Contributor guide

Open the contributing guide

Research direction

Start by reviewing the two linked support articles and compare the documented Chrome, iOS, Firefox, and Android recovery methods described in the issue. Clarify whether the work is a built-in recovery feature or additional platform-specific guidance, and define the supported platforms and recovery behavior before implementation; completion criteria are not yet specified.

Written by the indexing model from the issue text.

Assessment

Tech stack
android, ios
Domain
authentication, mobile, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.