Collected research
Metamask Snaps: Playing in the Sand
MetaMask Snaps: playing in the sand
MetaMask Snaps run untrusted extension code behind an isolated iframe, LavaMoat and Secure ECMAScript, with an RPC allow-list deciding which wallet methods a snap may call. The article documents a permission bypass: arguments are validated, then re-serialised by a sanitiser that honours a caller-supplied toJSON method, so the object reaching the wallet differs from the one approved. A snap without the ethereum-provider endowment could thus issue blocked RPC calls.
Record
- Document
- MetaMask Snaps: playing in the sand
- Researcher
- Bruno Halltari and Caue Obici
- Published by
- OtterSec
- Date
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Bruno Halltari and Caue Obici, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .