todayonchain.com

Metamask 2FA Scam Emerges, Phishing Attacks Sink 83% 2025

Cointelegraph
A new MetaMask phishing scam tricks users with fake 2FA verification to steal recovery phrases, despite overall phishing losses dropping significantly in 2025.

Summary

Blockchain security firm SlowMist has warned about a new phishing campaign impersonating MetaMask, which uses fake two-factor authentication (2FA) security warnings to lure users into providing their wallet recovery phrases on fraudulent domains. Once the 12-word seed phrase is shared, attackers steal the funds. This serves as a critical reminder that decentralized wallet protocols never request secret recovery phrases. Separately, a report from Scam Sniffer indicates that while phishing scams are a persistent threat, losses decreased by 83% year-over-year in 2025, falling to $83.3 million from $494 million in 2024, with the number of victims also dropping by 68%. The report noted that losses peak during active market periods, as phishing success correlates with overall user activity.

(Source:Cointelegraph)