MetaMask / MetaMask/metamask-extension

Seed Phrase Bug Bounty

Open
#3,127 216 comments 8 reactions 0 assignees View on GitHub
has bounty type-security
Dominant language
TypeScript
Stars
13.2k
Forks
5.6k
Avg merge
2d 5h
Merged PRs (30d)
451

Description

As part of our commitment to the best security we can offer, the MetaMask team is planning to continuously offer a bug bounty on our seed phrase functionality, we are starting the bounty at 1 ether, but anyone is free to add to the bounty as they like.

[As we have written about before](https://medium.com/metamask/metamask-security-advisory-and-bug-bounty-for-seed-phrase-concern-bbd95ab63210) #2577, and [have awarded a bounty for in the past](https://medium.com/metamask/seed-phrase-issue-bounty-awarded-e1986e811021), sometimes users have reported that the seed phrase they were originally given does not restore their original accounts.

We have continued to receive rare but concerning accounts of similar experiences: #2904 #3042 #4756 #4697

The bounty will be paid to anyone who can demonstrate a condition in MetaMask's code base, either through automated tests or manual reproduction, where MetaMask would show a user a seed phrase on first setup that would not work for later restoring their accounts.

Thanks for your interest and participation, we're available to answer any questions about our key management here.

Contributor guide

Open the contributing guide

Research direction

Review the seed-phrase concerns in issues #2577, #2904, #3042, #4756, and #4697, then trace the related key-management paths in the MetaMask code base. Done means demonstrating through an automated test or manual reproduction that a seed phrase shown during first setup cannot restore the user's original accounts.

Written by the indexing model from the issue text.

Assessment

Tech stack
typescript
Domain
cryptography, security
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.