SlowMist’s (CSO), @im23pds, has warned about a new phishing scam targeting MetaMask users with the “2FA verification” tactic. In this scenario, the attacker impersonates MetaMask’s official security alert page to create a sense of urgency and trust. Victims are redirected to a fake security page that reports suspicious activity on their wallet.
This page then guides users through a fake two-factor authentication process, designed very convincingly with elements such as a countdown timer and security confirmation messages. The ultimate goal is to trick users into entering their seed phrase or recovery phrase. Once obtained, the scammer can take full control of the wallet and drain all assets. Users must be extremely vigilant and never enter their seed phrase on any website or verification window.