MetaMask Security Alerts by Blockaid: the new normal for a safer transaction experience | MetaMask News (2024)

MetaMask Security Alerts is now the default transaction feature for Extension and Mobile users across multiple networks. We collaborated with Blockaid on making this feature unique by adding a level of privacy so that the transaction is never shared with third parties when offering necessary scam alerts.

We launched the security alerts in October 2023 under “Experimental” settings for Extension users on Ethereum only. After a successful period, we’re excited to roll this out as default across more networks to Mobile and Extension users for a safer transacting experience. We anticipate this integration will save assets worth hundreds of millions of dollars this year alone.

MetaMask Security Alerts by Blockaid: the new normal for a safer transaction experience | MetaMask News (1) Source: Blockaid

What networks are supported?


Make sure your Extension and Mobile apps are updated to the latest version (v11.10 and v7.17 respectively) to enjoy security coverage across these networks:

  1. Ethereum
  2. Linea
  3. BNB chain
  4. Polygon
  5. Arbitrum
  6. Optimism
  7. Avalanche

Increased user adoption = increased security measures


We witnessed a surge of people installing and using MetaMask in the last quarter. From September 2023 until January 2024, MetaMask's Monthly Active Users surged by +55%, signifying a crucial phase for web3.

While it’s a promising sign of growing web3 adoption, we need to ensure that our users are equipped to keep journeying through this burgeoning crypto space because the scammers don’t sleep.

Attack vectors affecting DeFi are sophisticated and diverse, with hackers exploiting both on-chain and off-chain vulnerabilities. In particular, the compromise of private keys, price manipulation attacks, and smart contract exploitation drove DeFi hacking losses in 2023. pic.twitter.com/7ZShsNjL8t

— Chainalysis (@chainalysis) January 24, 2024

Since December alone we’ve seen many high profile attacks in the industry. During the Ledger Connect Kit incident, nearly 100 frontend dapps were compromised yet every MetaMask user who opted into the Blockaid security alerts was 100% protected, preventing ~$1.15M worth of assets from being stolen.

Unintended transaction outcomes (like unwittingly approving a transaction from a phisher that drains your wallet) remain one of the top fund loss incidents reported by our users. We hope implementing these security alerts helps safeguard you from diverse attack vectors.

Additional ways to practice good security hygiene


Self-custody is a big responsibility. Since you’re ultimately in charge of your account, you’re the only one who can manage dapp permissions and sign transactions. Stay informed and vigilant against scammers!

While we can implement all the tools in the world to try and keep you as safe as possible (which we are), good security hygiene is paramount to navigating this (sometimes scary) maze.

  • We have a dedicated team at MetaMask who keep up with the latest attack vectors and publish security reports each month. Read them for a deeper dive and to know what to look out for.
  • Install Security Snaps! Your wallet can never have too many shields. Browse and install community-built features here.
  • Educate your friends getting into web3. MetaMask Learn provides a good high-level overview of the basics, and puts them to the test with this interactive security lesson. Build better habits together.
  • If you’re a developer, learn how open source tool LavaMoat offers triple-point protection in the software development cycle and add it to your build system in just 1 hour to defend your app from an attack.

Just last year, over $1.7 billion of crypto was stolen. Don’t be part of a stat this year. Remember, when in doubt, just don’t interact.

Establishing new security standards


A 2023 survey conducted by Morning Consult for Consensys revealed that 76% of participants prioritize security when selecting a wallet. Just as the transition from HTTP to HTTPS introduced a security standard that protected users and built trust in the internet, the web3 ecosystem needs similar protective measures tailored to our unique environment. This involves tools and protocols that alert users to potential security risks associated with certain dapps—Blockaid’s research finds that 1 in 10 dapps are malicious—ensuring that only secure and verified transactions take place.

For web3 to move beyond this interesting corner of the internet and become mainstream, users need to feel confident that their assets and data are secure. Help us improve this feature by reporting false positives.

MetaMask Security Alerts by Blockaid: the new normal for a safer transaction experience | MetaMask News (2)

We hope you enjoy the new transaction experience! Stay safe out there.

MetaMask Security Alerts by Blockaid: the new normal for a safer transaction experience  | MetaMask News (2024)

FAQs

MetaMask Security Alerts by Blockaid: the new normal for a safer transaction experience | MetaMask News? ›

MetaMask Security Alerts is now the default transaction feature for Extension and Mobile users across multiple networks. We collaborated with Blockaid on making this feature unique by adding a level of privacy so that the transaction is never shared with third parties when offering necessary scam alerts.

What is BlockAid on MetaMask? ›

Blockaid shares the database to a MetaMask server, which, in turn, is passed on to your MetaMask instance every few hours to make sure your wallet is up to date with the latest threats.

Is MetaMask legal in the US? ›

Yes. MetaMask is a trusted crypto wallet used by more than 30 million people worldwide, with security features like encryption, Blockaid, and seed phrases. It is, however, a hot wallet, and is best used in combination with a compatible hardware wallet.

Who is the security provider for MetaMask? ›

MetaMask partnered with Tel Aviv–based Blockaid, a Web3 security provider, to develop the alerts. Last year, Blockaid announced that it raised a $33 million Series A. Its security solution involves scanning blockchains for wallets held by bad actors and then warning customers not to transact with them.

How do I make sure my MetaMask is secure? ›

Basic MetaMask Safety Tips
  1. 1) Never share your secret phrase. ...
  2. 2) Download MetaMask only from the official website. ...
  3. 3) Use a strong password for your wallet. ...
  4. 4) Connect to only websites you trust. ...
  5. 5) Turn on these recommended security settings. ...
  6. 6) Lock or log out from MetaMask when not in use. ...
  7. 7) Use multiple MetaMask wallets.

How does the Blockaid work? ›

Blockaid is an access-policy enforcement system that preserves application semantics and is compatible with existing web frameworks. It intercepts database queries from the application, attempts to verify that each query is policy-compliant, and blocks queries that are not.

Is MetaMask completely safe? ›

Is MetaMask safe? Yes. MetaMask is one of the most trusted cryptocurrency wallets for the Ethereum blockchain.

Is MetaMask safer than Coinbase? ›

All transactions are secured by a 12-word seed phrase, ensuring high safety. Additionally, MetaMask can be integrated with hardware wallets like Ledger Nano, adding an extra layer of protection. Coinbase Wallet, on the other hand, emphasizes security through encryption and multi-factor authentication.

Can the IRS track MetaMask? ›

MetaMask does not directly report your crypto holdings or transactions to the IRS or any other tax authorities.

What country is MetaMask based out of? ›

Based in New York, MetaMask is a decentralized Ethereum wallet that was launched by Aaron Davis in 2016 and is currently operated by ConsenSys.

What if I get scammed with MetaMask? ›

Just email phishing@phishfort.com with the email headers and any relevant details about the scam. Report the scammer's public address on the block explorer, if possible.

What is the 12 word phrase in MetaMask? ›

Your Secret Recovery Phrase (SRP) is a unique 12-word phrase that is generated when you first set up MetaMask. Your funds are connected to that phrase. If you ever lose your password, your SRP allows you to recover your wallet and your funds.

Can someone track my MetaMask wallet? ›

IP tracking - If the Metamask wallet has been used on a public Wi-Fi network or other unsecured network, it may be possible to use IP tracking to attempt to locate the real-world location of the device used to access the wallet.

How do you know if your MetaMask wallet is compromised? ›

If you notice that unauthorized outgoing transactions are occurring from your wallet, your wallet has likely been compromised. This may have occurred through a variety of means including, but not limited to: Downloading malicious software. Inputting personal information on a phishing website.

What is more secure than MetaMask? ›

The best overall Metamask alternative is Zengo Wallet. Other similar apps like Metamask are Coinbase Wallet, OKX, Venly, and Trust Wallet. Metamask alternatives can be found in Blockchain Payment Systems but may also be in Cryptocurrency Wallets or Cryptocurrency Exchanges.

Which is more secure MetaMask or trust wallet? ›

In terms of security and privacy, Trust Wallet and MetaMask are both very secure and private wallets. Both wallets use encryption, recovery phrase backup, biometric authentication, etc. to safeguard your funds and data. Both wallets also do not require any personal information from their users.

What is MetaMask secret? ›

MetaMask has three different types of secret that are used in different ways to keep your wallet, and your accounts, private and safe: The Secret Recovery Phrase, the password, and private keys. We'll walk you through these secrets one at a time.

What does MetaMask injected mean? ›

MetaMask injects the provider API into websites visited by its users using the window. ethereum provider object. You can use the provider properties, methods, and events in your dapp. Note. MetaMask supports EIP-6963, which introduces an alternative wallet detection mechanism to the window.

What is token detection in MetaMask? ›

First of all, you can enable an advanced feature that automatically detects tokens held by your address, and adds them to your wallet. This will use lists of tokens aggregated from various community token lists; MetaMask doesn't keep a proprietary list of 'accepted' or 'valid' tokens.

Why do I need MetaMask with ledger? ›

Connecting an account on your Ledger with a Metamask wallet allows you to protect your private keys, sign transactions offline, and still access all of the apps and platforms you want. Essentially it provides you with a physical U2F.

Top Articles
Latest Posts
Article information

Author: Domingo Moore

Last Updated:

Views: 5981

Rating: 4.2 / 5 (73 voted)

Reviews: 80% of readers found this page helpful

Author information

Name: Domingo Moore

Birthday: 1997-05-20

Address: 6485 Kohler Route, Antonioton, VT 77375-0299

Phone: +3213869077934

Job: Sales Analyst

Hobby: Kayaking, Roller skating, Cabaret, Rugby, Homebrewing, Creative writing, amateur radio

Introduction: My name is Domingo Moore, I am a attractive, gorgeous, funny, jolly, spotless, nice, fantastic person who loves writing and wants to share my knowledge and understanding with you.