MetaMask is a popular Ethereum wallet and gateway to Web3, delivered as a browser extension and mobile app that securely stores private keys and signs transactions.
Overview
MetaMask is a popular Ethereum wallet and gateway to Web3, delivered as a browser extension and mobile app that securely stores private keys and signs transactions. It is a high-value target in cybersecurity due to its role in enabling wallet access and interactions with decentralized apps, making users and seed phrases attractive targets for phishing, fake landing pages, and malware campaigns; recent reporting highlights AI-generated phishing and targeted crypto campaigns that threaten MetaMask users.
Related Threat Clusters
-
Malware Spread via Fake Polymarket Trading Bot Targets DeFi Developers
On July 1, 2026, security firm SlowMist identified a fake trading bot on GitHub designed to spread malware targeting Polymarket users and DeFi developers. The bot, named 'polymarket-arbitrage-bot', was promoted as a…
2 articles · Updated July 1, 2026 -
North Korean Hackers Utilize EtherHiding for Cryptocurrency Theft
The Google Threat Intelligence Group (GTIG) reports that North Korean threat actor UNC5342 has adopted a new technique called EtherHiding to deliver malware and facilitate cryptocurrency theft. This method embeds…
3 articles · Updated May 26, 2026 -
Torg Grabber Malware Targets 728 Crypto Wallets with Advanced Techniques
Torg Grabber, a new infostealer malware, is actively targeting 728 cryptocurrency wallet extensions and other applications, including password managers and communication tools. The malware employs the ClickFix technique…
2 articles · Updated March 27, 2026 -
FakeWallet Crypto Stealer Targets iOS Users via Phishing Apps
In March 2026, Kaspersky identified over twenty phishing applications in the Apple App Store that impersonate popular cryptocurrency wallets. These malicious apps redirect users to fraudulent web pages that mimic the…
7 articles · Updated April 20, 2026 -
Phishing Emails Targeting Robinhood Users Exploit Legitimate Infrastructure
Ripple's former CTO David Schwartz has issued a warning about a phishing campaign targeting Robinhood users through seemingly legitimate emails. These emails appear to originate from Robinhood's own email system,…
9 articles · Updated April 27, 2026 -
Trader Loses $1M in Ethereum Phishing Attack via Permit2 Exploit
A trader lost approximately $1 million in a phishing attack that exploited Uniswap's Permit2 feature. The attack involved the victim signing a fraudulent token approval request, which granted a malicious contract access…
6 articles · Updated July 9, 2026 -
North Korean Malware Campaign Targets Crypto Professionals with Fake Wallets
North Korean threat actors have initiated a campaign named Contagious Interview, targeting IT professionals in the cryptocurrency, Web3, and AI sectors. The operation involves deploying remote access backdoors and…
2 articles · Updated February 18, 2026 -
Trust Wallet Browser Extension Version 2.68 Vulnerability Leads to $6 Million in Losses
Trust Wallet has confirmed a security vulnerability in version 2.68 of its browser extension, leading to the theft of funds from hundreds of users, totaling at least $6 million. Users are advised to disable the…
41 articles · Updated December 26, 2025 -
WhatsApp Malware Campaign Targets Brazilian Crypto Users
A sophisticated malware campaign in Brazil is exploiting WhatsApp to target cryptocurrency users, deploying a banking trojan named 'Eternidade Stealer.' This malware hijacks devices, steals financial data, and spreads…
19 articles · Updated November 26, 2025 -
WhatsApp Security Flaw Exposes 3.5 Billion Phone Numbers
A security flaw in WhatsApp allowed researchers to extract phone numbers of 3.5 billion users. The exploit involved systematically checking numbers through the app's discovery feature, revealing profile photos for 57%…
56 articles · Updated November 18, 2025
Recent Intelligence Reports
- Crypto User Loses $999,999 in USDT to One Phishing Signature: How to Stay Safe — Beincrypto · July 9, 2026
- Trader Loses $1M After Approving Phishing Token on Ethereum — Kucoin · July 9, 2026
- DeFi devs, Polymarket trading bot users targeted in fresh info — Cryptopolitan · July 1, 2026
- EtherHiding — www.bleepingcomputer.com · May 26, 2026
- Ripple's CTO flags phishing emails targeting Robinhood users — Bitget · April 27, 2026
- FakeWallet crypto stealer spreading through iOS apps in the App Store — Securelist · April 20, 2026
- FakeWallet crypto stealer spreading through iOS apps in the App Store — Securelist · April 20, 2026
- FakeWallet crypto stealer spreading through iOS apps in the App Store — Securelist · April 20, 2026