Summary
The Rabby integration stored GridPlus pairing information in a form available to local compromise rather than protecting the credentials as sensitive wallet material. The V12 report documents the affected path, remediation trail, and bug-bounty outcome.
Bugflation rates the issue Medium because an attacker first needs local access to the browser profile or a separate storage-disclosure capability. Recovering the pairing values weakens the hardware-wallet trust boundary, but does not by itself authorize a transaction without the device’s confirmation flow.
Attribution
The accepted report and bounty satisfy Bugflation’s no-CVE inclusion rule. The claim that V12 discovered the issue autonomously is first-party, so attribution is labeled self-reported.
References
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.