Выполняйте поиск по отслеживаемым доменам и просматривайте сохраненные доказательства, данные об обнаружениях и последние данные о доступности.
206,494
Всего отслеженных
201,235
Обнаружено VT
87,305
Последнее появление: активен
119,189
По последним данным — недоступно
0
VT — в процессе рассмотрения
How This Attack Works
MetaMask phishing attacks are sophisticated schemes designed to steal user credentials and cryptocurrency. Understanding the attack process is crucial for prevention.
STEP 1
Setup Fake Домены
Attackers register domains mimicking legitimate MetaMask sites, such as metamaskwallet-restore.com, to deceive users.
STEP 2
Lure Victims
Phishers use emails, ads, or social media to direct users to these fraudulent sites, often with urgent security alerts.
STEP 3
Harvest Credentials
Users are prompted to enter their wallet credentials, which are then captured by attackers.
STEP 4
Execute Transactions
With access to the wallet, attackers transfer funds to their own accounts, often using smart contracts to automate the theft.
Technical Analysis
MetaMask phishing scams often involve the use of cleverly designed websites that mirror the official MetaMask interface. These sites utilize HTML/CSS for visual replication and JavaScript to handle form submissions that collect sensitive information. Attackers often leverage phishing kits, which are pre-configured tools that automate the creation of fake websites. These kits can include scripts for intercepting and redirecting blockchain transactions. By exploiting smart contract functions like 'transfer' and 'approve', attackers can move funds without further user interaction. The infrastructure involves a network of domains registered under top registrars like MarkMonitor, Inc. and CSC Corporate Домены, Inc. to lend credibility. Attackers typically host these malicious sites on cloud platforms, using services like OVH, SAS for anonymity and scalability.
Real Cases
MetaMask Mega Hack (2023)
$50 million stolen
In 2023, a large-scale phishing operation used over 100 domains to steal $50 million in cryptocurrency from MetaMask users.
Crypto Wallet Heist (2024)
$30 million stolen
A sophisticated campaign targeted MetaMask users with fake wallet recovery sites, leading to $30 million in losses.
Blockchain Break-in (2024)
$20 million stolen
Phishers exploited smart contract vulnerabilities and phishing domains to drain $20 million from user wallets.
How to Detect
Unusual domain names like metamaskwallet-restore.com
Срочно security emails urging immediate action
Requests for seed phrases or private keys
Unexpected pop-ups or redirects when accessing MetaMask
Misspelled URLs or websites with slight alterations
How to Protect Yourself
1
Always verify the URL before entering credentials
2
Use browser extensions that block known phishing sites
3
Enable two-factor authentication if possible
4
Keep your browser and wallet software updated
5
Отчет suspicious sites to cybersecurity platforms like PhishDestroy
Frequently Asked Questions
Data sourced from PhishDestroy threat intelligence database — 4,843 domains tracked for this threat type
MetaMask Phishing 4,843 domains

enabled-meta.accounts-admin-agency.com

metamaskloginw.webflow.io

seduce-fjhtcxulyk.edgeone.app

active-meta.accounts-admin-agency.com

fish44.com

metamask-download.com

metamaskverifyweb3.com

l2unity.ltd

metanask-download.com

wallet-meta-mask-cdn-us.vercel.app

imtouken.com

metamask-log-web.square.site

metamask-portal.yzz.me

metamasklogini.webflow.io

metamaskwallet.to

metasuites.pro

profile-meta.accounts-admin-agency.com

tool-meta.invoice-ads-manager.com

www.metamask.tasheeltheqa.com

1wfqxn.life

about-meta-home.pineapple.page

aitokentrust.com

alt-layer.com

backoffice.myvibe.co

bifrostsnetwork.app

bittrapro.com

bonzofinance.net

cc-metamask.com.cn

connect-metamask-login.square.site

marketplace.metadscredit.com

matmksjhlgin.webflow.io

melltnnhk-wollet.gitbook.io

meta-mekssign.godaddysites.com

metaameklogin.webflow.io

metaamoskk-laggeeniss.godaddysites.com

metamask-quest.xyz

metamask-security.co

metamaskinsurance.live

metamaskloginu.blogspot.com

metamaskukbtc9.com

metamesklgi.webflow.io

metamskwallet.boxmode.io

methamshklkoin.godaddysites.com

metiiimask-extensio.webflow.io

metimasklogisn.github.io

metomask.me

metumskusa-logiiin.github.io

metuumaskwallat.webflow.io

mtaextesion.gitbook.io

mut-tamask-wellat.webflow.io

near-intents.net

portfolio-bilget.com

quizzical-wescoff-9b0b22.netlify.app

safe--metamasck-wallet.framer.media

trezur-start-base-faqs-io.typedream.app

18821.xyz

al-meta.accounts-admin-agency.com

ambientfinance.net

app.metamaskrewards.biz

claimslab.pro

diwebaifi.com

en-meta.blogspot.com

extension-metamasks.webflow.io

hels-metamusk-log.pineapple.page

io-metamask-login.framer.media

m.exerecetpxiexi.cc

meateemasklugn.webflow.io

mertamasjkogin.webflow.io

meta-mask-loogiss.godaddysites.com

meta-mask-template.webflow.io

metacheck.pro

metamaio-swap.com

metamakslogi.godaddysites.com

metamask-extension-get.created.app

metamask-login-11.gitbook.io

metamask.hk.cn

metamask88.com

metamaskauth.yzz.me

metamasktiologin.webflow.io

metamaskusdt.com

metamaskxalog.webflow.io

metamvuask-wa-llet.webflow.io

metart-web-start.pages.dev

metasmhkloin.webflow.io

metauslkocxzgimens.gitbook.io
Процесс реагирования на угрозы
Как мы проверяем каждый домен в этом разделе и нейтрализуем подтверждённые угрозы. Полная визуализация конвейера →
Проверка по источникам данных об угрозах— каждый домен сканируется и сверяется со следующими источниками:
urlscan.ioСнимок экрана · DOM · HTTPVirusTotal90+ AV enginesGoogle Safe BrowsingTransparency ОтчетCloudflare RadarDNS · certs · categoriesAlienVault OTXThreat-intel pulsesWayback MachineHistorical evidenceabuse.ch ThreatFoxIOC correlationcrt.shCertificate TransparencyDNS Безопасность FiltersQuad9 · AdGuard · CleanBrowsingWeb-ПроверитьFull surface scan
Передача данных партнёрам— подтверждённые детекты передаются 29 партнёрам:
GoogleSafe BrowsingGoogleWeb Risk APIMicrosoftSmartScreenVirusTotalDetection feedCloudflareRadar / 1.1.1.1YandexSafe BrowsingURLScan.ioPublic scanESETWebGuardBitdefenderThreat exchangeNortonSafe WebSymantecОбзор сайтаAviraCloud detectionAvast / AVGWeb Shield«Касперский»OpenTIPDr.WebOnline scannerNetcraftЛиквидация APIPhishTankVerified voteAPWG eCXBulk feedPhishStatsOpen feedPhish.ОтчетHosting abuseSpamhausDBL feedPolySwarmMarketplaceCheckPhishBolster scanQutteraMalware scanURLquerySandboxCriminal IPAsset intelCRDFThreat CenterScamadviserTrust scoreMyWOTWeb of Trust