Skip to content

[Security] Critical vulnerability in backup encryption — requesting private disclosure channel #1318

@0xFFFForge

Description

@0xFFFForge

Hi Flow Wallet team,

I'm a security researcher. During a review of the Flow Reference Wallet Chrome extension (currently distributed on Chrome Web Store), I identified multiple critical cryptographic vulnerabilities in the Google Drive backup encryption implementation.

These issues allow offline extraction and brute-force decryption of wallet private keys from cloud backups with minimal computational cost.

Severity: 2× Critical, 1× High
Affected component: Backup encryption (Google Drive cloud backup feature)
Status: Verified with working PoC against the production Chrome Web Store build (v2.9.4)

I do NOT want to disclose details publicly. The HackenProof bug bounty program for Flow Wallet is currently closed (83 days until reopening), and this repository has no SECURITY.md or private vulnerability reporting enabled.

Could you please provide a secure channel (email, private advisory, or similar) so I can share the full report and proof-of-concept?

Thank you.

@zzggo @lmcmz @caosbad

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions