Beware! Phishing emails disguised as MetaMask have led to the theft of hundreds of wallets, with losses exceeding $100,000
Recently, ZachXBT revealed a widespread cryptocurrency wallet theft incident, resulting in total losses of over $107,000.
Unlike previous attacks targeting large assets, this time the attacker employed a "scattershot" strategy, stealing small amounts of no more than $2,000 from hundreds of wallets. This approach is less likely to trigger alarms but can accumulate over time, allowing the attack to spread quietly.
The success of this wave of attacks is due to the New Year holiday window, which led to a shortage of developers and customer service staff, and users' inboxes being flooded with promotional emails, greatly reducing vigilance. Taking advantage of this, the attacker sent well-crafted phishing emails to users.
The attacker not only used MetaMask's festive logo with a party hat but also themed the email with "Mandatory Update + Happy New Year," creating an urgent official appearance to lure many users to click on links.
The effectiveness of such attacks hinges on their precise exploitation of user habits and psychology.
The sender information appears as a seemingly MetaMask-related name "MetaLiveChain," and the "Unsubscribe" link in the body even points to a legitimate marketing platform, with the core purpose of tricking users into clicking the link and signing a malicious "contract authorization."
Once the user signs, the attacker gains permission to transfer specific tokens from the wallet without needing to steal the complete seed phrase.
According to Chainalysis data, approximately 158,000 personal wallet thefts occurred in 2025, affecting at least 80,000 victims, with the total stolen assets dropping to about $713 million during the same period.
Overall, the current trend in crypto thefts is shifting toward "small amounts, high frequency." Although the average value per case has decreased, cases of personal wallet theft have surged, affecting many users, reflecting a change in attacker strategies.
Individual investors should remain vigilant, avoid clicking suspicious links, never disclose seed phrases, and proactively strengthen security by adding verification steps. True security is not about eliminating all risks but about keeping potential losses within manageable limits.
#MetaMaskPhishingAttack
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
Beware! Phishing emails disguised as MetaMask have led to the theft of hundreds of wallets, with losses exceeding $100,000
Recently, ZachXBT revealed a widespread cryptocurrency wallet theft incident, resulting in total losses of over $107,000.
Unlike previous attacks targeting large assets, this time the attacker employed a "scattershot" strategy, stealing small amounts of no more than $2,000 from hundreds of wallets. This approach is less likely to trigger alarms but can accumulate over time, allowing the attack to spread quietly.
The success of this wave of attacks is due to the New Year holiday window, which led to a shortage of developers and customer service staff, and users' inboxes being flooded with promotional emails, greatly reducing vigilance. Taking advantage of this, the attacker sent well-crafted phishing emails to users.
The attacker not only used MetaMask's festive logo with a party hat but also themed the email with "Mandatory Update + Happy New Year," creating an urgent official appearance to lure many users to click on links.
The effectiveness of such attacks hinges on their precise exploitation of user habits and psychology.
The sender information appears as a seemingly MetaMask-related name "MetaLiveChain," and the "Unsubscribe" link in the body even points to a legitimate marketing platform, with the core purpose of tricking users into clicking the link and signing a malicious "contract authorization."
Once the user signs, the attacker gains permission to transfer specific tokens from the wallet without needing to steal the complete seed phrase.
According to Chainalysis data, approximately 158,000 personal wallet thefts occurred in 2025, affecting at least 80,000 victims, with the total stolen assets dropping to about $713 million during the same period.
Overall, the current trend in crypto thefts is shifting toward "small amounts, high frequency." Although the average value per case has decreased, cases of personal wallet theft have surged, affecting many users, reflecting a change in attacker strategies.
Individual investors should remain vigilant, avoid clicking suspicious links, never disclose seed phrases, and proactively strengthen security by adding verification steps. True security is not about eliminating all risks but about keeping potential losses within manageable limits.
#MetaMaskPhishingAttack