Scam Watch

How can you recognize MetaMask phishing extension — Safery style seed exfiltration?

TLDR

Malicious extension impersonates MetaMask (e.g. 'Safery: Ethereum Wallet', Nov 2024). On seed import, extension encodes BIP 39 mnemonic into Sui style addresses and broadcasts microtxs from attacker mnemonic — reconstructable off chain....

How it works

Malicious extension impersonates MetaMask (e.g. 'Safery: Ethereum Wallet', Nov 2024). On seed import, extension encodes BIP 39 mnemonic into Sui style addresses and broadcasts microtxs from attacker mnemonic — reconstructable off chain....

Red flags

  • Urgent pressure to click, pay, or share codes immediately.
  • A link or sender that does not match the official organization.
  • Requests for card data, passwords, OTPs, wallet signatures, or bank transfers.

What to do

  1. 1Indicators: (1) publisher not 'ConsenSys Software Inc'; (2) URL has 'metаmask'/'meta mask'/'metamasq'; (3) demands 'all websites' permission; (4) odd outbound to non Infura RPCs (DevTools Network); (5) ChainPatrol blocked 29k threats Jan Oct 2024.
  2. 2WHAT TO DO: install only via metamask.io/download; pin legit extension; never enter seed into browser pop up.

Source

FAQ

Is MetaMask phishing extension — Safery style seed exfiltration a real scam pattern?

Yes. Treat the message, call, or payment request as suspicious until you verify it through an official channel.

What are the first warning signs?

Urgent pressure to click, pay, or share codes immediately.; A link or sender that does not match the official organization.; Requests for card data, passwords, OTPs, wallet signatures, or bank transfers.

What should I do first?

Indicators: (1) publisher not 'ConsenSys Software Inc'; (2) URL has 'metаmask'/'meta mask'/'metamasq'; (3) demands 'all websites' permission; (4) odd outbound to non Infura RPCs (DevTools Network); (5) ChainPatrol blocked 29k threats Jan Oct 2024.; WHAT TO DO: install only via metamask.io/download; pin legit extension; never enter seed into browser pop up.

Can LegalAudit check my case?

Yes. Start a free chat and paste the message, link, sender, or payment details for triage.