Crypto wallet MetaMask has announced that its users were victims of a 2FA security verification phishing scam, urging users to be vigilant.Crypto wallet MetaMask has announced that its users were victims of a 2FA security verification phishing scam, urging users to be vigilant.

MetaMask users targeted in fake 2FA security verification scam

2026/01/05 15:13
4 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

Crypto wallet MetaMask has announced that its users were victims of a 2FA security verification phishing scam, urging users to be vigilant. The fake email requested that MetaMask users update their 2FA security verification credentials by January 4, 2026, or else they would have limited access to key wallet features. 

23pds, partner and CISO at blockchain security firm SlowMist, was among the first industry KOLs to issue this phishing notice on social media early on January 5. The security researcher also cautioned MetaMask users to remain vigilant when handling emails from the crypto wallet firm.

Scammers impersonating MetaMask security pages attempted to trick users into completing a two-factor authentication process, with the actual goal of stealing their mnemonic phrases. The scam process involved creating and sending out links to fake security alert pages, 2FA verification interfaces, and countdown prompts, ultimately requesting users to enter their wallets’ mnemonic phrases. 

Meskauskas explains how to avoid MetaMask 2FA scam 

Malware researcher and internet security professional Tomas Meskauskas released an article a little over a month ago explaining how to avoid the 2FA activation email phishing scam. The report urged MetaMask to always check and verify the sender’s email address, among other minor details. Specifically, users were warned not to blindly trust emails from companies that appear to be legitimate.

Last year, the Australian cybersecurity service provider MailGuard identified and blocked a phishing email claiming to detect unusual activity on MetaMask user accounts. The email also requested that recipients activate their 2FA authentication without delay to prevent their accounts from being temporarily disabled.  

MailGuard warned that one cleverly worded email is all it takes for scammers to steal sensitive data from users or spread malware attachments and links. The computer security firm advised all recipients of such emails from MetaMask to delete them immediately to protect their crypto assets.

MetaMask has experienced several similar attacks since the 2022 security flaw in Apple’s cloud storage, when reports of stolen funds surfaced on social media. The ConsenSys-backed crypto wallet disclosed that the stolen digital assets included NFTs worth 132.86 ETH (~$402,980) and over $250,000 worth of APE (Apecoin), totaling over $650,000 in losses.  

MetaMask needs proactive anti-phishing measures

The cybersecurity team from blockchain security firm Halborn previously urged MetaMask and other crypto-related companies to proactively establish processes for managing phishing attacks. According to Halborn, such crypto companies must have these processes in place since no one can detect every phishing email. 

The blockchain security firm further stated that it is also important for MetaMask and similar companies to initiate incident response immediately after a phishing attack on users is identified, to minimize potential damage. It also noted that having a professional incident response team on call can make a significant difference between a major attack and a non-event. 

Meanwhile, the Halborn cybersecurity team urged MetaMask users to make it a habit of always activating their 2FA or MFA through the official platforms and keeping them up to date. It also noted that email security systems can help to detect and block potential phishing attacks, and using multi-factor authentication minimizes the impact of compromised credentials. 

The MetaMask support team has also advised users that the company will never send random confirmation emails, even when their wallets are connected to their Google or Apple accounts. The team also clarified that the company never asks for its users’ Apple or Google account details. 

MetaMask also emphasized that it will not and cannot initiate email correspondence with users unless a special request is made through the support team. It categorically stated that it does not request secret recovery phrases from its users, regardless of the circumstances.

The smartest crypto minds already read our newsletter. Want in? Join them.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.
Tags:

You May Also Like

US Jobs Miss Fails to Stop Bitcoin Erasing Its $74,000 Breakout Attempt

US Jobs Miss Fails to Stop Bitcoin Erasing Its $74,000 Breakout Attempt

The post US Jobs Miss Fails to Stop Bitcoin Erasing Its $74,000 Breakout Attempt appeared on BitcoinEthereumNews.com. Bitcoin (BTC) slipped under $70,000 around
Share
BitcoinEthereumNews2026/03/07 13:50
CEO Sandeep Nailwal Shared Highlights About RWA on Polygon

CEO Sandeep Nailwal Shared Highlights About RWA on Polygon

The post CEO Sandeep Nailwal Shared Highlights About RWA on Polygon appeared on BitcoinEthereumNews.com. Polygon CEO Sandeep Nailwal highlighted Polygon’s lead in global bonds, Spiko US T-Bill, and Spiko Euro T-Bill. Polygon published an X post to share that its roadmap to GigaGas was still scaling. Sentiments around POL price were last seen to be bearish. Polygon CEO Sandeep Nailwal shared key pointers from the Dune and RWA.xyz report. These pertain to highlights about RWA on Polygon. Simultaneously, Polygon underlined its roadmap towards GigaGas. Sentiments around POL price were last seen fumbling under bearish emotions. Polygon CEO Sandeep Nailwal on Polygon RWA CEO Sandeep Nailwal highlighted three key points from the Dune and RWA.xyz report. The Chief Executive of Polygon maintained that Polygon PoS was hosting RWA TVL worth $1.13 billion across 269 assets plus 2,900 holders. Nailwal confirmed from the report that RWA was happening on Polygon. The Dune and https://t.co/W6WSFlHoQF report on RWA is out and it shows that RWA is happening on Polygon. Here are a few highlights: – Leading in Global Bonds: Polygon holds 62% share of tokenized global bonds (driven by Spiko’s euro MMF and Cashlink euro issues) – Spiko U.S.… — Sandeep | CEO, Polygon Foundation (※,※) (@sandeepnailwal) September 17, 2025 The X post published by Polygon CEO Sandeep Nailwal underlined that the ecosystem was leading in global bonds by holding a 62% share of tokenized global bonds. He further highlighted that Polygon was leading with Spiko US T-Bill at approximately 29% share of TVL along with Ethereum, adding that the ecosystem had more than 50% share in the number of holders. Finally, Sandeep highlighted from the report that there was a strong adoption for Spiko Euro T-Bill with 38% share of TVL. He added that 68% of returns were on Polygon across all the chains. Polygon Roadmap to GigaGas In a different update from Polygon, the community…
Share
BitcoinEthereumNews2025/09/18 01:10
SushiSwap (SUSHI) Price Prediction 2026, 2027-2030: Future Outlook, Targets, and Long-Term Forecast

SushiSwap (SUSHI) Price Prediction 2026, 2027-2030: Future Outlook, Targets, and Long-Term Forecast

The post SushiSwap (SUSHI) Price Prediction 2026, 2027-2030: Future Outlook, Targets, and Long-Term Forecast appeared first on Coinpedia Fintech News Story Highlights
Share
CoinPedia2026/03/07 14:37