Introduction
We express our gratitude to the QTUM team for the collaborative engagement that enabled the execution of this dApp Security Assessment.
Document | |
|---|---|
| Name | MetaMask Snap Code Review and Security Analysis Report for QTUM |
| Audited By | Abdelfattah Ibrahim |
| Approved By | Ece Orsel |
| Website | https://qtum.org/→ |
| Changelog | 12/03/2026 - Preliminary Report |
| 03/04/2026 - Final Report | |
| Platform | Metamask Snap |
| Language | TypeScript, JavaScript |
| Tags | MetaMask Snap, Pentest (White-Box) |
| Methodology | https://docs.hacken.io/methodologies/dapp-audit-methodology→ |
Document
- Name
- MetaMask Snap Code Review and Security Analysis Report for QTUM
- Audited By
- Abdelfattah Ibrahim
- Approved By
- Ece Orsel
- Website
- https://qtum.org/→
- Changelog
- 12/03/2026 - Preliminary Report
- 03/04/2026 - Final Report
- Platform
- Metamask Snap
- Language
- TypeScript, JavaScript
- Tags
- MetaMask Snap, Pentest (White-Box)
Review Scope | |
|---|---|
| Repository | https://github.com/qtumproject/qtum-extension-wallet→ |
| Initial commit | 12f7594 |
| Final Commit | 2251452 |
Review Scope
- Initial commit
- 12f7594
- Final Commit
- 2251452
Audit Summary
The system users should acknowledge all the risks summed up in the risks section of the report
{FindingsVulnSeverityStatusTable}
Documentation quality
The README provides a user-facing FAQ and basic setup instructions. However, functional requirements and technical description are not detailed.
Code quality
The codebase is well-structured with clear separation of concerns: RPC handlers (rpc-request.tsx), UI components (helpers/ui/), helpers, parsers, and a separate connector package.
System Overview
The Qtum Wallet is an extension of MetaMask wallet. It is a proxy between the Qtum blockchain and MetaMask. The Qtum Snap allows you to hold the QTUM token, manage QRC20 tokens and NFTs, and connect to Qtum’s bridge that allows Web3 and DeFi between the Ethereum and Qtum blockchains.
Qtum MetaMask Snap simplifies the integration of MetaMask with the Qtum blockchain. It facilitates the storage and transfer of Ethereum ERC20 assets to and from the Qtum blockchain, using the Qtum Bridge, and other QRC20 assets like Circle Bridged USDC, allowing users to access the Qtum ecosystem seamlessly without needing additional wallets.
Findings
Code ― | Title | Status | Severity | |
|---|---|---|---|---|
| F-2026-1535 | Blind Signing in EthSignTypedDataV4 | fixed | High | |
| F-2026-1535 | Missing Origin Checks and Display in Snap Dialogs | fixed | Medium | |
| F-2026-1537 | Sensitive Wallet Management RPC Methods Exposed to dApps | fixed | Low | |
| F-2026-1537 | BIP38 Export Passphrase Input Not Masked | fixed | Low | |
| F-2026-1536 | Incorrect Token Balance Comparison Prevents Full-Balance Sends | fixed | Low | |
| F-2026-1535 | Insufficient Validation in WalletAddEthereumChain | fixed | Low | |
| F-2026-1535 | Vulnerable and Deprecated Dependencies | fixed | Low | |
| F-2026-1534 | Overly Broad Permissions | accepted | Low | |
| F-2026-1536 | Missing response.ok Check on Explorer API Calls | fixed | Observation | |
| F-2026-1536 | Usage of any Type Reduces Type Safety | fixed | Observation |
Appendix 1. Severity Definitions
Findings are categorized based on their potential impact and assigned a severity level using the Common Vulnerability Scoring System (CVSS) version 4.0: →
Severity | Description |
|---|---|
Critical | These issues present a major security vulnerability that poses a severe risk to the system. They require immediate attention and must be resolved to prevent a potential security breach or other significant harm. |
High | These issues present a significant risk to the system, but may not require immediate attention. They should be addressed in a timely manner to reduce the risk of the potential security breach. |
Medium | These issues present a moderate risk to the system and cannot have a great impact on its function. They should be addressed in a reasonable time frame, but may not require immediate attention. |
Low | These issues present no risk to the system and typically relate to the code quality problems or general recommendations. They do not require immediate attention and should be viewed as a minor recommendation. |
Severity
- Critical
Description
- These issues present a major security vulnerability that poses a severe risk to the system. They require immediate attention and must be resolved to prevent a potential security breach or other significant harm.
Severity
- High
Description
- These issues present a significant risk to the system, but may not require immediate attention. They should be addressed in a timely manner to reduce the risk of the potential security breach.
Severity
- Medium
Description
- These issues present a moderate risk to the system and cannot have a great impact on its function. They should be addressed in a reasonable time frame, but may not require immediate attention.
Severity
- Low
Description
- These issues present no risk to the system and typically relate to the code quality problems or general recommendations. They do not require immediate attention and should be viewed as a minor recommendation.
Appendix 2. Scope
The scope of the project includes the following repository:
Scope Details | |
|---|---|
| Repository | https://github.com/qtumproject/qtum-extension-wallet→ |
| Initial commit | 12f7594 |
| Final commit | 2251452 |
Scope Details
- Initial commit
- 12f7594
- Final commit
- 2251452
Assets in Scope
Appendix 3. Additional Valuables
Frameworks and Methodologies
This security assessment was conducted in alignment with recognised penetration testing standards, methodologies and guidelines, including the NIST SP 800-115 – Technical Guide to Information Security Testing and Assessment →, the Penetration Testing Execution Standard (PTES) →, and the OWASP Testing Guide →. These assets provide a structured foundation for planning, executing, and documenting technical evaluations such as vulnerability assessments, exploitation activities, and security code reviews. Hacken’s internal penetration testing methodology extends these principles to Web2 and Web3 environments to ensure consistency, repeatability, and verifiable outcomes.