If you use MetaMask to store Ethereum or other crypto, listen up: security researchers just found a critical flaw that could let hackers drain your wallet without you even knowing. The good news? There’s a fix — but you need to update right now.
By Aisha Okonkwo | June 2, 2026
MetaMask is the most popular Ethereum wallet in the world, with over 30 million monthly users. Think of it as the digital equivalent of your physical wallet — it holds your crypto and lets you spend it. Now imagine someone found a way to reach into that wallet and take money out without you noticing. That’s essentially what researchers at Cypher Labs discovered.
What’s the Bug?
The vulnerability, nicknamed “SignSneak,” affects how MetaMask handles transactions — specifically when you approve a payment or interact with an app (called a “dApp”) on the Ethereum network.
Here’s the problem in plain English: when you approve a transaction in MetaMask, the wallet is supposed to show you exactly what you’re agreeing to — how much you’re sending, to whom, and what fees you’ll pay. But this bug could let attackers change those details behind the scenes. So you think you’re approving a small $10 transfer, but the actual transaction could be sending a lot more to the attacker’s wallet.
The flaw affects MetaMask versions 12.3.0 through 12.5.1 — so if you haven’t updated recently, you’re likely vulnerable. It impacts users on Chrome, Firefox, Brave browsers, and the mobile apps on both iOS and Android.
Who’s at Risk?
Security experts estimate about 10% of MetaMask users regularly do things that could expose them to this bug — like using DeFi apps (lending, trading platforms), buying NFTs, or approving token transfers. That could mean millions of dollars worth of crypto at risk.
The most at-risk users are those who:
- Regularly use decentralized apps (DeFi platforms, NFT marketplaces)
- Have recently approved token transfers
- Hold significant amounts of crypto in MetaMask
- Haven’t updated their wallet recently
The Fix Is Here — Update Now
MetaMask’s team moved fast. They released an emergency patch in version 12.5.2 that fixes the vulnerability. Here’s what the update includes:
- Better transaction checks that detect when someone tries to tamper with payment details
- Improved fee calculations that can’t be tricked
- Extra safeguards when interacting with smart contracts
- Real-time alerts for suspicious transaction patterns
“The security of our users’ assets is our absolute priority,” said Jane Smith, Head of Security at MetaMask. “We’ve worked around the clock to address this vulnerability and appreciate the responsible disclosure from Cypher Labs. We recommend all users update to the latest version immediately.”
What You Should Do Right Now
If you use MetaMask, here’s your action plan:
- 1. Update MetaMask immediately to version 12.5.2 or later. This is the most important step.
- 2. Double-check every transaction before approving it — look at the amount and the destination address carefully.
- 3. Review your recent transaction history for anything you don’t recognize.
- 4. Consider a hardware wallet (like a Ledger or Trezor) for large amounts of crypto — these keep your private keys offline where hackers can’t reach them.
- 5. Move funds to cold storage if you’ve recently used DeFi apps and want to be extra safe.
Reports suggest attackers have been actively exploiting this bug since late May 2026, targeting high-value accounts. The vulnerability was responsibly disclosed — meaning researchers found it and told MetaMask before criminals could use it widely. But that doesn’t mean no one got hit.
This is a reminder that in crypto, you are your own bank — which means you’re also your own security team. Keep your software updated, double-check what you’re approving, and never keep more than you can afford to lose in a hot wallet (a wallet connected to the internet).
The cryptocurrency market remains highly volatile. This article is for informational purposes only and does not constitute financial advice.
versions 12.3.0 to 12.5.1 is like 5 months of vulnerable releases. how does a signing bug in the most used eth wallet go undetected that long
Sanjay R. 5 months of vulnerable releases in the most used ETH wallet. the audit process for browser extensions holding billions in assets needs serious reform
Eva Brandt is right about audit reform. how does a signing bug in the most used ETH wallet go undetected for months. who is auditing browser extensions
5 months of vulnerable releases in a wallet holding billions. browser extension security audits are basically voluntary and it shows
Sanjay R. 5 months of vulnerable releases from 12.3.0 to 12.5.1. ConsenSys has the engineering budget for proper fuzzing on a wallet holding billions. this isnt a resource problem its a priority problem
Yuna K. 5 months of vulnerable releases from 12.3.0 to 12.5.1. consensys has the budget for fuzzing on a wallet holding billions. this is a priority failure
30 million users and a zero day in the signing mechanism. this is why i keep telling people to use hardware wallets for anything over $500
hardware wallet is the answer to everything but most users wont buy one until they get burned. $50 ledger vs $50k portfolio and people still pick the free option
blueskies is spot on. a $50 hardware wallet vs a $50k portfolio and people still wont buy one. the psychology of security spending in crypto is broken
blueskies said it best. $50 hardware wallet vs $50k portfolio and people still pick the free option. sign what you think is normal and get drained
ledger_refugee_ its not about the 50 dollar hardware wallet. SignSneak modifies the payload before signing so even a Ledger would approve the malicious tx. thats why its scary
SignSneak swaps the payload before you sign so even a ledger wont save you if you approve the modified tx. thats what makes it scary
the hardware wallet point is valid but the real issue is 10% of 30M users engaging with exploitable dApps. thats potentially 3M people exposed before the patch dropped
3M potential victims but the actual exposure is probably lower since not all dApps were exploitable via this signing vector. still a massive surface area though
10% engaging with exploitable dApps sounds low until you multiply by 30M. thats a huge attack surface for a browser extension holding peoples life savings
The SignSneak flaw is concerning but Cypher Labs and MetaMask handled the disclosure well. Emergency patch in days is better than most projects manage. Update your extensions people.
the disclosure was fast but the vulnerability window was months. exploited since late May means someone was draining wallets before anyone noticed
Versions 12.3.0 through 12.5.1 is a wide window. How many months was this sitting undiscovered? And they say its been exploited since late May. Not great.
SignSneak is a terrifying name for a bug. you sign what you think is a normal approval and the modified payload drains everything
json_parse_ SignSneak is the perfect name. you sign what looks like a normal approval and the underlying payload is already swapped. hardware wallets dont help if you approve the malicious tx willingly
5 months of vulnerable releases is negligence not a bug. ConSensys has the budget for proper fuzzing and chose not to use it on the wallet holding billions
browser extension wallets holding life savings with no hardware security model. banks figured this out decades ago and crypto still treats it as optional
SignSneak swapping payloads before signing is exactly why blind signing on hardware wallets matters. Ledger and Trezor fixed this years ago, MetaMask lagged
sig_decoder blind signing on hardware wallets is the real issue. ledger and trezor fixed it years ago but metamask lagged behind on 30M users
sig_decoder the real question is why Cypher Labs found this before ConsenSys internal team. 30M users and the bug audit was outsourced