In a Twitter thread posted on April 18, MetaMask warned iOS users about the dangers of losing their funds if their Apple password “isn’t strong enough” thereby leading to the attacker being able to phish their account credentials. To fix the issue, users can disable automatic iCloud backups for MetaMask as detailed:
The warning from MetaMask came in response to reports from an NFT collector who stated on April 15 that their entire wallet containing $650,000 worth of digital assets and NFTs was wiped via this specific security issue.
The NFT investor claimed that he obtained a phone from an Apple worker, asking for a code to demonstrate that he owned the Apple account on his cell phone. Upon obtaining the 2FA code, the attacker entered it into the victim’s Apple account, got access to his iCloud and extracted the MetaMask wallet password information, and stole all the assets in the wallet.
The MetaMask user, who posted this also promised to give away a $100,000 bounty to anyone who helps in getting his digital assets back.