Phony MetaMask 2FA flow mimics security checks to steal wallet recovery phrases
A phishing campaign targeting MetaMask users deploys a convincing 2FA-style workflow to capture wallet recovery phrases. According to SlowMist's chief security officer, attackers use near-identical domains and branded emails to impersonate MetaMask Support. The scheme underscores increasingly polished social engineering tactics despite reports of falling crypto phishing losses in 2025.