— no diffs detected in snapshot history yet —
No reports yet — be the first to share your triage timing for MetaMask.
// peer-sourced response times. platforms won’t publish this — hunters can. anonymized in aggregate.
{
"allows_bounty_splitting": true,
"average_time_to_bounty_awarded": 231,
"average_time_to_first_program_response": 17,
"average_time_to_report_resolved": 4770,
"handle": "metamask",
"id": 0,
"managed_program": true,
"name": "MetaMask",
"offers_bounties": true,
"offers_swag": true,
"response_efficiency_percentage": 67,
"submission_state": "open",
"url": "https://hackerone.com/metamask",
"website": "https://metamask.io/",
"targets": {
"in_scope": [
{
"asset_identifier": "MetaMask Browser Extension",
"asset_type": "OTHER",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "[MetaMask](https://metamask.io/download) is everything you need to manage your identity, digital assets and to explore web3. Available as an extension on chromium-based and firefox browsers. ",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "MetaMask SDK",
"asset_type": "OTHER",
"availability_requirement": "low",
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "The MetaMask SDK allows for third party developers to remotely connect with their user's MetaMask wallets after performing an authorization flow. ",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "Snaps",
"asset_type": "OTHER",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Snaps is a feature that allows third party developers to add new functionality to MetaMask. A snap is a JavaScript program that runs in an isolated environment and customizes the wallet experience. Snaps have access to a limited set of capabilities, determined by the [permissions](https://docs.metamask.io/snaps/how-to/request-permissions/) the user granted them during installation.\n\nVisit our [quickstart guide](https://docs.metamask.io/snaps/get-started/quickstart/) to learn how to build your own snap, or visit [snaps.metamask.io](http://snaps.metamask.io) to see the possibilities that snaps now offer.\n\nPlease note that for the duration of the open beta, custom made snaps can only be installed on experimental [MetaMask Flask](https://metamask.io/flask/). While that asset is out of scope, vulnerabilities concerning the snaps feature are eligible for submission if they affect the main extension as well. \n\n**Supporting Documentation:**\n\n- https://github.com/MetaMask/snaps/tree/main\n- https://docs.metamask.io/snaps/\n\n**Architecture Documentation**\n\n- https://github.com/MetaMask/snaps/tree/main/docs/internals\n\n**Packages included in this scope:**\n\n- [rpc-methods](https://github.com/MetaMask/snaps/tree/main/packages/rpc-methods)\n- [snaps-controllers](https://github.com/MetaMask/snaps/tree/main/packages/snaps-controllers)\n- [snaps-execution-environments](https://github.com/MetaMask/snaps/tree/main/packages/snaps-execution-environments)\n- [snaps-utils](https://github.com/MetaMask/snaps/tree/main/packages/snaps-utils)\n- [snaps-ui](https://github.com/MetaMask/snaps/tree/main/packages/snaps-ui)\n\nAs snaps is a first party feature integrated into MetaMask, vulnerabilities will be scored relative to the impact demonstrated against the MetaMask Extension without a change in scope.",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "Third Party Snaps",
"asset_type": "OTHER",
"availability_requirement": "none",
"confidentiality_requirement": "none",
"eligible_for_bounty": false,
"eligible_for_submission": true,
"instruction": "Vulnerabilities found in third party snaps should always reported to the developer responsible for the snap. However, in cases where a developer is unable to be reached, please report the vulnerability here so that we may assist with getting in contact. These kinds of reports will be closed as informative, and will not be eligible for a bounty.",
"integrity_requirement": "none",
"max_severity": "none"
},
{
"asset_identifier": "api-wallet.web3auth.io",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "API used by Web3Auth Wallet Services",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "https://metamask.github.io/phishing-warning/<vX.Y.Z>",
"asset_type": "OTHER",
"availability_requirement": "medium",
"confidentiality_requirement": "low",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "The phishing warning page is a security control that warns users when they attempt to visit a webpage found on one of our known phishing blocklists. Only vulnerabilities found on the latest version are eligible for a bounty. \n\nSupporting Documentation:\n* https://github.com/MetaMask/phishing-warning/releases\n* [Code usage in MetaMask extension](https://github.com/MetaMask/metamask-extension/blob/d96c2b8530ff0fe66ad8977641bc70cc0b58cc03/app/scripts/contentscript.js#L611-L624)\n",
"integrity_requirement": "medium",
"max_severity": "critical"
},
{
"asset_identifier": "io.metamask",
"asset_type": "GOOGLE_PLAY_APP_ID",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "[MetaMask](https://metamask.io/download) is everything you need to manage your identity, digital assets and to explore web3. Available as a mobile application on iOS and Android.",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "io.metamask.Metamask",
"asset_type": "APPLE_STORE_APP_ID",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "[MetaMask](https://metamask.io/download) is everything you need to manage your identity, digital assets and to explore web3. Available as a mobile application on iOS and Android.",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "mUSD Stablecoin",
"asset_type": "OTHER",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "**This asset is owned and maintained by the m0 team. All reports should be directed to security@m0.xyz and are subject to the m0 team’s assessment when determining if a report may be eligible for a bounty.**\n\nIf you do not receive a response within 1 week, please submit a report to us as well and we will assist you with getting in contact with m0.\n\n**Introduction**\n\nThe mUSD token is built upon the M0 framework, which leverages real-world assets (RWA) to mint a rebasing M token on-chain, with subsequent yield from RWAs distributed through M token rebasing mechanisms.\nThe M0 framework wraps the rebasing M token into non-rebasing MExtension tokens that feature customizable configurations for yield distribution. The mUSD token represents one such implementation, utilizing the MYieldToOne extension to direct yield to a designated recipient. The broader M0 framework and MExtension system architecture is outside the audit scope, and the focus is specifically on the mUSD token contract implementation.\nBeyond the standard token and M0 framework functionality, the mUSD token incorporates additional administrative controls, including pausability mechanisms, account freezing capabilities, and forced transfer functionality for frozen assets.\n\n**Scope**\nM0 mUSD token [contract repository at b62fab7c3e867b700bd81dad2ab140e074d98f32](https://github.com/m0-foundation/mUSD/tree/b62fab7c3e867b700bd81dad2ab140e074d98f32)\n\nFor more information please see the following audit: https://diligence.security/audits/2025/08/metamask-usd-token/\n\n**Out of Scope**\n\nM0 framework and MExtension system architecture is outside the audit scope.\nIt's given that the below roles are operated by Consensys, and are therefore trusted. Insider threat is not an attack vector that is in scope.\n\n**Roles and Permissions**\n\n**Default Admin** - Able to change all the privileged roles in the system.\n\n**Proxy Admin Owner** - The mUSD token contract is upgradeable, and the Proxy Admin Owner is the address that can perform such an upgrade.\n\n**M0 Operational Administrators** - Able to modify the greater M0 framework properties that are defined outside the mUSD token, such as who is an approved swapper and what extensions can be swapped between each other.",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "metamask.io",
"asset_type": "URL",
"availability_requirement": "medium",
"confidentiality_requirement": "none",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "The root https://metamask.io webpage and the metamask.io DNS configuration.",
"integrity_requirement": "medium",
"max_severity": "critical"
},
{
"asset_identifier": "signature-insights.api.cx.metamask.io",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "The Signature Insights API receives off-chain signature requests (eth_signTypedData_v3, eth_signTypedData_v4, etc.) from MetaMask Extension & Mobile and decodes them into state changes to be rendered into human readable balance changes. These balance changes are shown in the confirmations windows when a user is signing an off-chain signature request for popular dapps such as OpenSea, Uniswap, and others.\n\nAPI docs: https://metamask-consensys.notion.site/Public-MetaMask-Signature-Insights-API-Documentation-189f86d67d688047851fed6656a3199a",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "snaps.metamask.io",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": "low",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "This is a directory that lists featured snaps available for installation on MetaMask.\n\n**Supporting Documentation**\n\n- https://github.com/MetaMask/snaps-directory",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "wallet.web3auth.io",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Web3Auth Wallet Services provide both a stand-alone wallet app, known as Torus Wallet, and a ready-to-use embedded wallet interface available directly within the Web3Auth SDK.",
"integrity_requirement": null,
"max_severity": "critical"
}
],
"out_of_scope": [
{
"asset_identifier": "*.api.cx.metamask.io",
"asset_type": "WILDCARD",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "APIs used by MetaMask wallet and Portfolio",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "Core Tier Assets",
"asset_type": "OTHER",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "MetaMask's Core Tier Assets are specific MetaMask assets which are paid out in accordance with our Core Tier bounty table. This table can be found on our program page, and includes the following assets:\n* MetaMask SDK\n* metamask.io\n* `https://metamask.github.io/phishing-warning/<vX.Y.Z>`\n* `https://signature-insights.api.cx.metamask.io`\n* Web3Auth Wallet Services and Its API",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "Message signing snap",
"asset_type": "OTHER",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "This snap is pre-installed on MetaMask and can be tested via RPC calls.\n\n- **Main documentation**: https://github.com/MetaMask/message-signing-snap/blob/main/docs/testing.md\n- **Testing video tutorial**: https://www.loom.com/share/93ce2929c2584cf89af87d76f61be978",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "Metamask Flask Extension",
"asset_type": "OTHER",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "Installation Link: https://chrome.google.com/webstore/detail/metamask-flask-developmen/ljfoeinjpaedjfecbmggjgodbgkmjkjk\n\nThis is an experimental playground for developers, where new or proposed features can be rolled out and tested before deploying them to the broader public.\n\n",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "Non-Core Tier Assets",
"asset_type": "OTHER",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "MetaMask's Non-Core Tier Assets are specific MetaMask assets which are paid out in accordance with our Non-Core Tier bounty table. This table can be found on our program page, and includes the following assets:\n\n* https://snaps.metamask.io\n",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "Snaps Development Packages",
"asset_type": "SOURCE_CODE",
"availability_requirement": "none",
"confidentiality_requirement": "low",
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "The Snaps development tools consist of a series of unrelated packages that can assist in the development of a snap. These tools are eligible for a bounty in cases where a victim can be impacted by exploiting one of the following tools (ex: achieving remote code execution by having a developer build your snap with snaps-cli).\n\nThese tools are as follows: \n\n- [create-snap](https://github.com/MetaMask/snaps/tree/main/packages/create-snap)\n- [snaps-browserify-plugin](https://github.com/MetaMask/snaps/tree/main/packages/snaps-browserify-plugin)\n- [snaps-cli](https://github.com/MetaMask/snaps/tree/main/packages/snaps-cli)\n- [snaps-rollup-plugin](https://github.com/MetaMask/snaps/tree/main/packages/snaps-rollup-plugin)\n- [snaps-simulator](https://github.com/MetaMask/snaps/tree/main/packages/snaps-simulator)\n- [snaps-webpack-plugins](https://github.com/MetaMask/snaps/tree/main/packages/snaps-webpack-plugins)",
"integrity_requirement": "low",
"max_severity": "none"
},
{
"asset_identifier": "Wallet Tier Assets",
"asset_type": "OTHER",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "MetaMask's Wallet Tier Assets are specific MetaMask assets which are paid out in accordance with our Wallet Tier bounty table. This table can be found on our program page, and includes the following assets:\n\n* MetaMask Extension\n* MetaMask Mobile (io.metamask.Metamask, io.metamask)\n* MetaMask Snaps",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "api-dashboard.web3auth.io",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "API used by the The Web3Auth Dashboard",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "card.metamask.io",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "All content is entirely owned, operated, and managed by Baanx. \n\nFor any vulnerabilities related this domain, or any of its subdomains, please send an email to the following email address: security@baanx.com.\n\nPlease also CC: baanx-disclosure@consensys.net.\n\nIf you do not receive a response within 1 week, please submit a report to us as well and we will assist you with getting in contact with Baanx. ",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "community.metamask.io",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "Vulnerability reports related to this domain should be directed to the Discourse bug bounty program: https://hackerone.com/discourse",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "dashboard.web3auth.io",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "The Web3Auth Dashboard is a centralized platform to manage your projects, configurations, and wallet integrations for MetaMask Embedded Wallets",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "developer.metamask.io",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "MetaMask Developer provides instant and scalable API access for web3 dapp developers.\n\nBounty Tier: Core\n\n",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "https://*.metamask.io",
"asset_type": "WILDCARD",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "**Please ensure you are not reporting a subdomain that is explicitly listed as being out of scope.** \n\nBounty eligibility is determined based on the impact that can be demonstrated by exploiting the affected asset.",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "https://github.com/Web3Auth/web3auth-web",
"asset_type": "SOURCE_CODE",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "MetaMask Embedded Wallets (Web3Auth SDK) is a pluggable embedded wallet infrastructure that simplifies Web3 wallet integration and user onboarding",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "https://metamask.github.io/",
"asset_type": "OTHER",
"availability_requirement": "medium",
"confidentiality_requirement": "none",
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "This domain is the root of various static GitHub pages applications which range from test sites, to development tools, to production security controls. Vulnerabilities which can be used to have impact on an in-scope asset will still be considered for a bounty.",
"integrity_requirement": "medium",
"max_severity": "none"
},
{
"asset_identifier": "https://mmi-support.metamask.io/",
"asset_type": "URL",
"availability_requirement": "not_defined",
"confidentiality_requirement": "not_defined",
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "",
"integrity_requirement": "not_defined",
"max_severity": "none"
},
{
"asset_identifier": "https://support.metamask.io/",
"asset_type": "URL",
"availability_requirement": "not_defined",
"confidentiality_requirement": "not_defined",
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "",
"integrity_requirement": "not_defined",
"max_severity": "none"
},
{
"asset_identifier": "https://user-storage.api.cx.metamask.io",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "The User Storage API helps developers synchronize data across multiple clients and devices in a privacy-preserving way. All data saved in the user storage database is encrypted client-side to preserve privacy.\nDocumentation can be found in this [Doc](https://docs.google.com/document/u/1/d/e/2PACX-1vRzlbxKTKQ4x8mvUEUs8hv-fcGsi0W717Pbg2_Rk3lcoM5PuSCI66JUWaWdL_Vz0GNMbZU4aYaC2rcQ/pub)",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "https://www.npmjs.com/search?q=%40metamask",
"asset_type": "OTHER",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "Vulnerabilities within npm packages in the @metamask namespace that do not pose a risk to MetaMask users",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "permissionless.snaps.metamask.io",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "An experimental directory for permissionless snaps. Is currently under development, and may potentially be put in scope in the future. ",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "portfolio.metamask.io (app.metamask.io)",
"asset_type": "URL",
"availability_requirement": "not_defined",
"confidentiality_requirement": "not_defined",
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "The Portfolio dApp allows Metamask users to see an aggregated view across multiple different Metamask accounts. It also allows users to access popular on-chain primitives like Swaps, Bridging, Staking, and more.",
"integrity_requirement": "not_defined",
"max_severity": "none"
},
{
"asset_identifier": "travel.metamask.io",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "All content is entirely owned, operated, and managed by entravel.com.\n\nFor any vulnerabilities related this domain, or any of its subdomains, please send an email to bugbounty@entravel.com.\n\nIf you do not receive a response within 1 week, please submit a report to us as well and we will assist you with getting in contact with them.",
"integrity_requirement": null,
"max_severity": "none"
}
]
}
}MetaMask Browser Extension· criticalMetaMask SDK· criticalSnaps· criticalThird Party Snaps· nonemetamask.github.io/phishing-warning/<vX.Y.Z>· criticalio.metamask· criticalmUSD Stablecoin· criticalapi-dashboard.web3auth.iocard.metamask.iocommunity.metamask.iodashboard.web3auth.iodeveloper.metamask.iommi-support.metamask.io/support.metamask.io/user-storage.api.cx.metamask.iopermissionless.snaps.metamask.ioportfolio.metamask.io (app.metamask.io)Snaps Development Packagesgithub.com/Web3Auth/web3auth-webCore Tier AssetsMessage signing snapMetamask Flask ExtensionNon-Core Tier AssetsWallet Tier Assetsmetamask.github.io/www.npmjs.com/search?q=%40metamask