




Prime X+
346 posts

@_prime_eth
Founder https://t.co/4PHTFSdv1H - Building the future of Web3. Passionate AI & blockchain researcher. @xdegods member.







@XDeGods @DeGodsNFT so we bringing it back or…



👋🏼 Ron here, Head of Security @phantom. First of all, I want to reassure everyone that security is our top priority at Phantom and that there is no vulnerability that puts user funds at risk. The issue @CloakdDev is referring to involves being able to freeze a user’s Phantom app by sending it thousands of tokens. This issue has been never been exploited and is now completely remediated, but at various points this was the case for both fungible and non-fungible tokens. In the case of non-fungible tokens, it was possible to crash the collectibles tab, but not affect the rest of the app, and certainly not affect user private keys or secret recovery phrases. In the case of fungible tokens, it was possible to crash the app, and make it difficult for users to access their wallet without the help of Phantom support. Both these issues were promptly remediated and never exploited. At no point were funds at risk of being compromised. @CloakdDev had been in touch with our security team, and other members of the Phantom team, claiming that it had been possible to wipe private keys and secret recovery phrases from user devices using similar methods. Despite multiple outreaches from our team, he was not able to provide reproducible steps, and we have also not been able to reproduce this despite our best efforts. Based on this, the finding was triaged to score CVSS 3.7, rated Low, and valued at $3,000. @CloakdDev if you can provide reproducible steps to your claims, we are happy to work with you and increase the size of the bounty offered.

