MetaMask targeted by fake 2FA phishing on January 5, 2026 to steal seed phrases
On January 5, 2026, a phishing campaign impersonating MetaMask support pushed a fake two‑factor authentication process to harvest recovery phrases. SlowMist's CSO described the operation as highly polished, with look‑alike domains and branded emails. Although 2025's phishing losses fell from nearly $494 million to about $84 million, attackers are reappearing with refined tactics.