All findings

v12-rabby-gridplus-pairing-credentials medium

V12 finds plaintext GridPlus pairing credentials in Rabby Wallet

V12 reports that its autonomous audit found Rabby Wallet storing sensitive GridPlus hardware-wallet pairing material in plaintext; the report received a bug bounty.

Bug class
Plaintext storage of hardware-wallet pairing credentials
Affected codebase
Rabby Wallet GridPlus integration
Credited system
V12
Disclosed
June 25, 2026
Attribution
Self-reported attribution
Severity
medium
Source status: V12's public proof-of-concept repository supplies the autonomous-discovery claim and documents disclosure acceptance and a $50 bounty. Medium is an editorial rating: exploitation requires local browser-profile read access or another storage-disclosure primitive, and the pairing secrets do not by themselves bypass hardware confirmation. No CVE was public at indexing time.

Summary

The Rabby integration stored GridPlus pairing information in a form available to local compromise rather than protecting the credentials as sensitive wallet material. The V12 report documents the affected path, remediation trail, and bug-bounty outcome.

Bugflation rates the issue Medium because an attacker first needs local access to the browser profile or a separate storage-disclosure capability. Recovering the pairing values weakens the hardware-wallet trust boundary, but does not by itself authorize a transaction without the device’s confirmation flow.

Attribution

The accepted report and bounty satisfy Bugflation’s no-CVE inclusion rule. The claim that V12 discovered the issue autonomously is first-party, so attribution is labeled self-reported.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.