As cited
Copy frozen at (site build).
threat intel
Why Ask Credentials If There Are Secret Codes?
A phishing campaign targeting MetaMask cryptocurrency wallet users uses pressure tactics to trick victims into revealing their secret recovery phrase instead of traditional credentials. The attack bypasses multi-factor authentication protections by focusing on the password recovery process, with the phishing domain registered two days prior to the campaign.
Why it matters: MetaMask users should verify requests for recovery phrases through official channels only, as compromise of this phrase grants full wallet access regardless of other security measures in place.
- Source published
- First seen by Cybersecurity Tracker