BlockBeats News, August 20th. Self-custodial AI security agent V12 announced that the Rabby Wallet extension app has a silent signature extraction vulnerability. When a user connects to a malicious DApp and sets the auto-lock time to 10 minutes, if they stay for about 10 minutes and then unlock the wallet again, their funds may be drained.
Rabby Wallet later responded via a tweet, stating that the team had released an update to fix the vulnerability on August 11th after its discovery. Users are advised to ensure that their Rabby extension is updated to the latest version. The mobile app is not affected. Furthermore, the team mentioned that the conditions for triggering this vulnerability are highly limited (requiring a connection to a malicious website and manual setting of a 10-minute auto-lock), and currently, the team has not detected any actual exploitation cases.

