Rabby Wallet released an update on Aug. 11 to fix a vulnerability in its browser extension that could enable silent signature extraction and potentially drain funds under a narrowly defined set of conditions. Users had to connect the wallet to a malicious DApp, manually set the auto-lock timer to 10 minutes, leave it locked for about 10 minutes, and then unlock it. Rabby said its mobile app was not affected, other timer settings were unaffected, and it had detected no actual exploitation. The issue was reported on Aug. 20 by BlockBeats, citing statements from the security agent V12 and Rabby Wallet.