MetaMask / MetaMask/metamask-extension
Seed Phrase Bug Bounty
- Dominant language
- TypeScript
- Stars
- 13.2k
- Forks
- 5.6k
- Avg merge
- 2d 5h
- Merged PRs (30d)
- 451
Description
As part of our commitment to the best security we can offer, the MetaMask team is planning to continuously offer a bug bounty on our seed phrase functionality, we are starting the bounty at 1 ether, but anyone is free to add to the bounty as they like.
[As we have written about before](https://medium.com/metamask/metamask-security-advisory-and-bug-bounty-for-seed-phrase-concern-bbd95ab63210) #2577, and [have awarded a bounty for in the past](https://medium.com/metamask/seed-phrase-issue-bounty-awarded-e1986e811021), sometimes users have reported that the seed phrase they were originally given does not restore their original accounts.
We have continued to receive rare but concerning accounts of similar experiences: #2904 #3042 #4756 #4697
The bounty will be paid to anyone who can demonstrate a condition in MetaMask's code base, either through automated tests or manual reproduction, where MetaMask would show a user a seed phrase on first setup that would not work for later restoring their accounts.
Thanks for your interest and participation, we're available to answer any questions about our key management here.
Contributor guide
Research direction
Review the seed-phrase concerns in issues #2577, #2904, #3042, #4756, and #4697, then trace the related key-management paths in the MetaMask code base. Done means demonstrating through an automated test or manual reproduction that a seed phrase shown during first setup cannot restore the user's original accounts.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- typescript
- Domain
- cryptography, security
- Issue type
- Bug
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100