MetaMask Users Under Attack: Fake 2FA Scam Draining Wallets in Seconds

ccn.comОпубликовано 2026-01-05Обновлено 2026-01-05

Введение

MetaMask users are being targeted by a sophisticated phishing scam that uses fake two-factor authentication (2FA) prompts to steal seed phrases and drain wallets within seconds. The attack begins with fraudulent emails or social media messages impersonating MetaMask support, urging users to enable "mandatory 2FA" under false urgency. Victims are directed to convincing phishing sites that mimic MetaMask’s interface, complete with countdown timers. Once users enter their seed phrase, attackers gain full control of their wallets and immediately transfer all assets. Security firm SlowMist first reported the scam on January 5. While specific loss figures are still emerging, similar recent phishing campaigns have already stolen over $107,000 from hundreds of wallets. MetaMask emphasizes that it never asks for seed phrases via email and advises users to ignore unsolicited security alerts, verify sender addresses, manually type URLs, and use hardware wallets for high-value assets. Enabling authenticator-based 2FA and regularly revoking token approvals are also recommended precautions.

Key Takeaways

  • Scammers are targeting MetaMask users with fake “2FA security verification” pages that mimic official alerts.
  • The phishing sites use countdown timers and urgency to trick victims into entering their seed phrases.
  • Once the seed phrase is submitted, attackers gain complete control and can instantly drain wallets.

MetaMask, the leading non-custodial Ethereum wallet, is facing an active two-factor authentication (2FA) scam that has recently drained multiple user wallets.

Cybersecurity firm SlowMist flagged the attack on Jan. 5, noting that scammers lure victims through a series of fake web pages designed to closely mimic official MetaMask interfaces, ultimately tricking users into revealing their wallet seed phrases.

Try Our Recommended Crypto Exchanges
Sponsored
Disclosure
We sometimes use affiliate links in our content, when clicking on those we might receive a commission at no extra cost to you. By using this website you agree to our terms and conditions and privacy policy.
"}' data-trk="68df7fd8872238d510dfbf06" href="https://clicks.pipaffiliates.com/c?c=1104900&l=en&p=1" rel="nofollow" target="_blank">
XM.com<\/h3>"}' data-trk="68df7fd8872238d510dfbf06" href="https://clicks.pipaffiliates.com/c?c=1104900&l=en&p=1" rel="nofollow" target="_blank">

XM.com

promotions
Get 100% Bonus up to $100 on your first Deposit.<\/strong>"}' data-trk="68df7fd8872238d510dfbf06" href="https://clicks.pipaffiliates.com/c?c=1104900&l=en&p=1" rel="nofollow" target="_blank"> Get 100% Bonus up to $100 on your first Deposit.
Coins
28
Claim Offer
"}' data-trk="6899b9831836d97539c51aa6" href="https://www.bitunix.com/" rel="nofollow" target="_blank">
Bitunix<\/h3>"}' data-trk="6899b9831836d97539c51aa6" href="https://www.bitunix.com/" rel="nofollow" target="_blank">

Bitunix

promotions
Receive up to $100,000 worth of exclusive gifts for newcomers upon registration.<\/strong>"}' data-trk="6899b9831836d97539c51aa6" href="https://www.bitunix.com/" rel="nofollow" target="_blank"> Receive up to $100,000 worth of exclusive gifts for newcomers upon registration.
Coins
151
Claim Offer
"}' data-trk="67adf8d4f12aaec7e4808bf5" href="https://bonus.bitget.com/CCN12" rel="nofollow" target="_blank">
Bitget<\/h3>"}' data-trk="67adf8d4f12aaec7e4808bf5" href="https://bonus.bitget.com/CCN12" rel="nofollow" target="_blank">

Bitget

promotions
Earn rewards worth up to 5,000 USDT on your first deposit<\/strong>"}' data-trk="67adf8d4f12aaec7e4808bf5" href="https://bonus.bitget.com/CCN12" rel="nofollow" target="_blank"> Earn rewards worth up to 5,000 USDT on your first deposit
Coins
88
Claim Offer

What Happened?

The attack typically begins with a phishing email or link shared via social media, direct messages, or compromised websites.

Unlike legitimate 2FA setups, which rely on codes generated by apps or devices, this scam ultimately prompts users to enter their seed phrase.

This grants attackers full control and enables them to drain funds within seconds.

Users receive unsolicited emails posing as “MetaMask Support,” with subject lines such as “2FA – Protect Your Wallet” or “Action Required: Secure Your Wallet with 2FA.”

The emails claim that 2FA is becoming mandatory to prevent unauthorized access and often impose a fake deadline to create urgency.

They feature the MetaMask fox logo and include a button labeled “Enable 2FA Now!”

Metamask users received malicious emails asking them to update their seed phrase. Source: X

Clicking the button redirects users to a phishing site with a domain closely resembling MetaMask’s, often using typosquatting techniques such as “matamask” instead of “metamask.”

The site displays a fake security alert warning of potential risks and urges immediate action.

Users are then guided to a counterfeit 2FA verification interface that includes realistic elements, such as countdown timers (e.g., “Complete in 5 minutes or risk account restriction”), to pressure quick compliance.

The final step asks users to enter their 12- or 24-word seed phrase under the pretense of “verifying wallet ownership” or “completing security setup.”

Some versions include a fake “authenticity check” to build trust.

Once entered, the phrase is sent to the attackers, who can import the wallet elsewhere and transfer all assets instantly.

Users Risk Losing Their Total Holdings

MetaMask itself is not technically vulnerable; the exploit relies on social engineering and user error.

As this specific 2FA variant was first publicly reported on Jan. 5, 2026, detailed loss figures have not yet been widely disclosed.

However, early indicators suggest a rapid potential for loss due to the direct theft of seed phrases.

Similar MetaMask phishing campaigns, such as the “mandatory update” scam, were flagged by on-chain investigator ZachXBT just days prior.

These scams have drained over $107,000 from hundreds of wallets across EVM chains.

Victims typically lose small amounts per wallet ($500–$2,000), making the thefts initially harder to detect and trace.

Funds are funneled to attacker-controlled addresses, often in stablecoins or ETH, with total ecosystem losses from MetaMask-related scams estimated in the millions annually.

If you’ve fallen victim, immediately disconnect the wallet from suspicious sites and transfer any remaining funds to a new wallet.

Staying vigilant is key in Web3; MetaMask emphasizes that security begins with user awareness.

How To Avoid Such Scams

First and foremost, it’s crucial for users holding assets in online wallets and self-custodial wallets to be wary of such attacks.

Always remember: no wallet, whether hardware or software, custodial or non-custodial, should ever ask for your seed phrase.

However, due to the sophistication of these scams, it’s hard to detect them all the time.

Here’s a step-by-step guide to always double-check any such emails, creating urgency:

  • Ignore unsolicited emails claiming to be from MetaMask; official ones never create a sense of urgency or request seed phrases.
  • Check the sender domains for legitimacy: [email protected] or [email protected].
  • Manually type URLs instead of clicking links. Hover over buttons to inspect destinations.
  • Never enter your seed phrase anywhere except during initial wallet setup or recovery on a trusted device. Store it offline and use a hardware wallet for high-value assets to require physical confirmation for transactions.
  • Enable real 2FA on related accounts using authenticator apps instead of SMS. Disable iCloud backups for sensitive apps to prevent access via Apple ID scams.
  • Regularly revoke token approvals using tools like MetaMask Portfolio to limit access to malicious contracts.

Top Picks for Ethereum
  • Best Exchanges for Ethereum Get A Great Offer When You Join These Exchanges
  • Buy Ethereum Fast & Easy How To Buy Ethereum With a Credit Card Now
  • Best Online Casinos for Ethereum See Our Picks for the Best Crypto Gambling Sites

Связанные с этим вопросы

QWhat is the main tactic scammers use in the fake 2FA attack on MetaMask users?

AScammers use phishing emails or links that mimic official MetaMask alerts, complete with countdown timers and a sense of urgency, to trick users into entering their seed phrases on fake websites.

QWhat is the ultimate goal of the attackers once they obtain a user's seed phrase?

AOnce the seed phrase is obtained, attackers gain complete control over the user's wallet and can instantly drain all the funds and assets from it.

QAccording to the article, what is a key indicator that an email claiming to be from MetaMask support is a scam?

AA key indicator is that the email creates a sense of urgency, such as imposing a fake deadline, and requests the user's seed phrase, which legitimate MetaMask support would never do.

QWhat proactive step can users take to limit the damage from malicious smart contracts?

AUsers can regularly revoke token approvals using tools like the MetaMask Portfolio to limit the access that malicious contracts have to their funds.

QWhat type of wallet does the article recommend for users holding high-value assets, and why?

AThe article recommends using a hardware wallet for high-value assets because it requires physical confirmation for transactions, adding a significant layer of security.

Похожее

SemiAnalysis Dissects Huawei's Kirin 9030: Process Technology Halted, So They Folded the Chip

SemiAnalysis has published a detailed teardown report on the HiSilicon Kirin 9030 Pro chipset found in Huawei's Mate 80 Pro. Fabricated using SMIC's most advanced N+3 node without EUV lithography, the analysis reveals significant technical achievements and strategic shifts. The report indicates SMIC's N+3 has achieved transistor density comparable to TSMC's N6 (113.4 vs 107.7 MTr/mm²), primarily through aggressive use of Self-Aligned Quadruple Patterning (SAQP) for its metal layers. This results in a notably small 32.5nm M0 metal pitch. However, SemiAnalysis notes this achievement comes with significantly higher process complexity, cost, and potential yield challenges compared to competitors using more advanced tools. The Kirin 9030 design maximizes this constrained density. While its GPU performance has improved ~70% and matches Qualcomm's 2022 flagship level, the CPU core's IPC lags behind current top-tier designs from Apple and Qualcomm, a gap attributed to the underlying manufacturing technology rather than design capability. Facing long-term restrictions on advanced tools, Huawei is charting a new path. The report highlights the company's "LogicFolding" roadmap, a 3D stacking technique aimed at shortening signal paths to boost performance and efficiency. The goal is to reach 5GHz frequency and a projected density of 295 MTr/mm² by 2031. SemiAnalysis concludes that export controls have not halted China's chip progress but have fundamentally altered its trajectory, making it more expensive and complex. This has spurred innovation in alternative areas like 3D stacking and domestic EDA tool development, with Huawei's supply chain also beginning to integrate Chinese memory from CXMT.

marsbit25 мин. назад

SemiAnalysis Dissects Huawei's Kirin 9030: Process Technology Halted, So They Folded the Chip

marsbit25 мин. назад

How Will the Price Move Before SpaceX's Next Share Unlock?

TL;DR Investors buying SPCX after SpaceX's IPO are not simply investing in a typical tech stock. It’s a high-valuation asset driven by Musk's narrative, Starlink, and space transport potential, but with a key twist: a very small initial float of ~4% has led to significant post-listing price appreciation. The current price action reflects a timing gap. Before the first lock-up expiration (estimated around August, subject to official confirmation), scarcity and high demand could continue to push prices up. Short-term bulls focus on low float, FOMO, and potential index inclusion. However, bears point to the supply dynamics that will change post-lockup. Existing shareholders still hold over 95% of shares, which will be released in stages starting from the first unlock window. This introduces future selling pressure from low-cost holders. The upcoming Q2 earnings report is a critical catalyst before the unlock. It will test whether the company's fundamentals can justify the current ~$2.1T valuation. Strong results could support the pre-unlock momentum, while weak figures could amplify concerns about future supply. The trading thesis is shifting from immediate scarcity ("can't buy enough") to evaluating future absorption capacity ("who will buy when more supply hits"). The path ahead hinges on the specifics of the unlock schedule, Q2 earnings performance, and whether anticipated passive index buying materializes.

marsbit46 мин. назад

How Will the Price Move Before SpaceX's Next Share Unlock?

marsbit46 мин. назад

Bitcoin Short-Term Bullish Structure Validated, HYPE Low-Entry Window Opens | Guest Analysis

**Market Analysis Summary (Week of June 2026)** **Overall Market Context:** The market environment is exceptionally complex, with the unexpected US-Iran agreement and the reopening of the Strait of Hormuz triggering a global asset repricing and significant volatility. This heightened noise underscores the importance of a structured analytical framework. **Bitcoin (BTC) Analysis & Strategy:** * **Current Status:** The price has climbed above $65,000, currently in a rebound phase (segment 38-39) following a complex 12-segment correction from the May high of $82,850. * **Key Levels:** * **Primary Resistance:** $69,500–$70,500. A successful breakout above $65,000 targets this zone. * **Primary Support:** $65,000 (immediate), followed by $59,000–$60,000 and $55,000. * **Weekly Outlook & Strategy:** The focus is on the confirmation of the $65,000 level. * **Bullish Scenario (Hold $65K):** A move toward the $69.5K–$70.5K resistance zone is anticipated, which is a potential area for initiating medium-term short positions. * **Bearish Scenario (Break below $65K):** A retest of the $60,000–$62,000 support range is likely. * **Medium-Term Strategy:** Currently neutral. Plan to establish short positions (up to 60% allocation) either in the $69.5K–$70.5K resistance zone upon signs of rejection, or on a confirmed breakdown below $65,000 and further below $59K–$60K. * **Short-Term Strategy:** Utilize 30% capital for scalping opportunities based on support/resistance levels, using 30/60-minute charts. **HYPE Analysis & Strategy:** * **Current Status:** The price has stabilized around $52 after a four-segment decline from the June high of $75.87 and is now in a rebound (segment 50-51). * **Key Levels:** * **Primary Resistance:** $62.50–$64.57. Watch for potential rejection here to form a lower high. * **Primary Support:** $52–$55.50, followed by $47–$49. * **Weekly Outlook & Strategy:** Adopt a "buy on dips, avoid chasing rallies" approach. * **Core View:** Monitor the price action and potential formation of a lower high ("endpoint 51") in the $62.50–$64.57 resistance zone. * **Short-Term Strategy:** Consider light long positions (max 30% allocation) if the price finds support and shows reversal signals in the $52–$54.50 or deeper $47–$49 support zones, confirmed by proprietary quantitative bottom signals. **Trade Review:** Last week's HYPE short-term long trade, executed based on proprietary "Price Difference" and "Momentum" model signals, yielded a profit of approximately 11.88%. The entry was near $54.39 and exit near $60.85. **Risk Management Reminder:** Always set an initial stop-loss upon entry. Move stop-loss to breakeven at +1% profit, then trail it upwards to lock in gains as the trade progresses. *Disclaimer: All analysis, models, and strategies are based on personal technical analysis for educational purposes only, not investment advice. The market carries inherent risk.*

Odaily星球日报50 мин. назад

Bitcoin Short-Term Bullish Structure Validated, HYPE Low-Entry Window Opens | Guest Analysis

Odaily星球日报50 мин. назад

Bitcoin Short-Term Bullish Structure Validated, HYPE Accumulation Window Opens | Guest Analysis

**Bitcoin and HYPE Market Analysis: Short-Term Outlook and Trading Strategies** This market analysis examines Bitcoin (BTC) and HYPE amid volatile conditions, providing short-term outlooks and specific trading strategies. **Key Outlooks:** * **Bitcoin (BTC):** Focus is on whether BTC's recent move above $65,000 holds. A successful breakout could lead to a test of the $69,500-$70,500 resistance zone, where medium-term short positions are considered. A failure, breaking below $65,000, may trigger a decline towards the $59,000-$60,000 support area. * **HYPE:** The token completed a four-wave correction and is now rebounding. The key resistance zone is $62.5-$64.57. The trading strategy is "buy on dips," looking for entry opportunities near the $52-$54.5 or deeper $47-$49 support zones, pending confirmation from proprietary models. **BTC Trading Strategy:** * **Medium-term:** Primarily looking to establish short positions (up to 60% allocated capital) if price rallies to the $69,500-$70,500 resistance area and shows signs of reversal. Alternative plans involve initiating shorts on a breakdown below $65,000. * **Short-term:** Allocate up to 30% capital for intraday "spread" trades based on support/resistance levels on 30/60-minute charts. **HYPE Trading Strategy:** * **Short-term:** Adopt a dip-buying approach. Consider light long positions (under 30% capital) when price tests key support levels ($52-$54.5 or $47-$49) and shows stabilization, confirmed by proprietary "Price Spread" and "Momentum Quant" models. **Trade Recap:** The analysis reviews a successful HYPE long trade from the previous week, executed at ~$54.39 and closed at ~$60.85 for an ~11.88% gain, based on signals from the aforementioned models. **Risk Management Emphasis:** The article stresses strict capital allocation (under 30-60%), immediate initial stop-loss placement, and a trailing stop-loss protocol to lock in profits as trades move favorably. ***Disclaimer:** All analysis, models, and strategies are for educational purposes based on technical analysis, not investment advice. Markets are volatile; trade with caution.*

marsbit53 мин. назад

Bitcoin Short-Term Bullish Structure Validated, HYPE Accumulation Window Opens | Guest Analysis

marsbit53 мин. назад

Торговля

Спот
Фьючерсы
活动图片