New MetaMask Phishing Scam Mimics 2FA to Steal Wallets
-

A new phishing campaign targeting MetaMask users is spreading rapidly, using a highly realistic “two-factor authentication” (2FA) flow to trick victims into revealing their wallet recovery phrases. The scam demonstrates how social engineering tactics continue to evolve, even as overall crypto phishing losses declined sharply in 2025.
Attackers rely on trust and urgency, framing the scam as a mandatory security upgrade. By exploiting the familiarity of 2FA—a tool users associate with safety—the operation lowers suspicion and increases the likelihood that victims comply before realizing anything is wrong.
-
fake 2fa scam is nasty, using “security upgrade” language is such a trust hack
-
Have Trump to bomb them.