Fake Metamask 2FA Security Checks Lure Users Into Sharing Recovery Phrases

On Jan. 5, 2026, cybersecurity firm SlowMist and multiple reports warned of a sophisticated phishing campaign that used counterfeit “2FA security verification” prompts to harvest MetaMask users’ Secret Recovery Phrases (SRPs). The operation combined cloned domains, spoofed communications, and psychological pressure to trigger immediate disclosure of recovery credentials and enable rapid asset withdrawals.