In one of the most recent hacking incidents, an attacker managed to steal a person’s entire collection of cryptocurrencies and NFTs worth more than $650,000, from their MetaMask crypto wallet, as reported by CNET on April 18. A few days before, the victim, Domenic Iavocone, took to Twitter to convey what exactly happened: According to Iavocone, the stolen assets included $160,000 worth of Ethereum (ETH), a Mutant Ape Yacht Club NFT worth an estimated $80,000, as well as $100,000 in ApeCoin (APE) and $250,000 in Tether (USDT). Clearly, the hackers deployed a sophisticated phishing technique to gain access to the victim’s iCloud account. However, this did not explain how they gained access to his MetaMask wallet, which requires a 12-word seed phrase to enter. Iavocone didn’t have this seed phrase written down in any document stored on iCloud.

Using iCloud backup to get to the wallet

To provide an explanation, a security expert nicknamed Serpent said that iCloud automatically stores the seed phrase file of the person’s wallet if the MetaMask app is used on iPhone. In other words, gaining access to someone’s iCloud account will automatically grant access to their seed phrase file in such a case. According to Serpent, “it’s going to happen to a lot more people” and the key to avoiding such unfortunate events is to: It is worth noting that a cold wallet, also called a hardware wallet or cold storage, is a physical device resembling a USB drive that stores an individual’s private keys and cryptocurrency completely offline, away from any attacks exploiting online software.

MetaMask details how to disable iCloud backup

In the meantime, MetaMask has posted on its Twitter account the instructions on how to disable this backup: Considered a hot wallet, MetaMask is one of the most popular software cryptocurrency wallets for holding ERC-20 tokens and interacting with decentralized apps (dApps) on the Ethereum and Binance Smart Chain (BSC) networks.