leather-io / desktop

Manage STX tokens and Stacking
https://leather.io/
191 stars 71 forks source link

[4.10.0] Bug: <HIRO DESKTOP WALLET DRAINED NEVER CONNECTED TO ANY DAPPS OR STAKING> #1210

Closed CRYPTOforCHANGE365 closed 1 year ago

CRYPTOforCHANGE365 commented 1 year ago

Bug found testing Hiro Wallet build undefined, 4.10.0.

314159265359879 commented 1 year ago

Your wallet getting drained is very serious, and I am very sorry that happened to you.

The Hiro Wallet Desktop does not connect to any dapps, only the Extension does that. Stacking through the Desktop wallet is non-custodial meaning the Stacks would remain in your wallet if you participate in Stacking through the wallet.

The only way someone could drain your wallet is if they have access to your Secret Key. When you do not use a hardware device (Ledger) the wallet will store an encrypted version of your Secret Key on the computer that can only be decrypted with the password you set when setting up the wallet.

If a hacker does not have your Secret Key, A hacker would have to have access to your computer and know the password to get to your funds.

Please email me for further assistance investigating this case. wallet at hiro.so

friedger commented 1 year ago

Support ticket, not about code.