New wave of phishing emails impersonating MetaMask with fake blue checkmarks circulating.
Regulation & Gov ·
A new wave of phishing emails impersonating MetaMask is circulating, with some fraudulent messages even mimicking blue verification checkmarks. The scam targets users of MetaMask, the self-custodial Ethereum wallet operated by Consensys that serves approximately 30 million monthly active users.
The attack leverages MetaMask's brand recognition and user trust to deceive recipients into compromising their credentials or private keys. Phishing campaigns have become increasingly sophisticated in the cryptocurrency space, with MetaMask itself flagging a broader rise of AI-driven crypto attacks ranging from fake Google security pages to malware affecting hundreds of browser extensions.
Users are advised to verify sender addresses directly and avoid clicking links in unsolicited emails claiming to be from MetaMask. The precise scope of this phishing wave—how many users have been targeted or how many have fallen victim—remains unclear. Standard security practices, such as checking official MetaMask channels before responding to account-related requests, remain the primary defense against such threats.