<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=MetaMask_Phishing_InstallMetaMask.com</id>
	<title>MetaMask Phishing InstallMetaMask.com - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=MetaMask_Phishing_InstallMetaMask.com"/>
	<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=MetaMask_Phishing_InstallMetaMask.com&amp;action=history"/>
	<updated>2026-04-17T00:08:26Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.39.1</generator>
	<entry>
		<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=MetaMask_Phishing_InstallMetaMask.com&amp;diff=5680&amp;oldid=prev</id>
		<title>Azoundria: 30 minutes. This is a duplicate of the case we already have, and will be merged. Integrated significant information from the BleepingComputer article. Integrating information on warning tweet from MetaMask. Integrated tweets from victim dcon18. Found more links as sources. Added information from article update and tweet from Sean Roesner.</title>
		<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=MetaMask_Phishing_InstallMetaMask.com&amp;diff=5680&amp;oldid=prev"/>
		<updated>2024-04-22T18:01:31Z</updated>

		<summary type="html">&lt;p&gt;30 minutes. This is a duplicate of the case we already have, and will be merged. Integrated significant information from the BleepingComputer article. Integrating information on warning tweet from MetaMask. Integrated tweets from victim dcon18. Found more links as sources. Added information from article update and tweet from Sean Roesner.&lt;/p&gt;
&lt;a href=&quot;https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=MetaMask_Phishing_InstallMetaMask.com&amp;amp;diff=5680&amp;amp;oldid=4849&quot;&gt;Show changes&lt;/a&gt;</summary>
		<author><name>Azoundria</name></author>
	</entry>
	<entry>
		<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=MetaMask_Phishing_InstallMetaMask.com&amp;diff=4849&amp;oldid=prev</id>
		<title>Azoundria: Created page with &quot;{{Imported Case Study 2|source=https://www.quadrigainitiative.com/casestudy/metamaskphishinginstallmetamaskcom.php}} {{Unattributed Sources}}  Install MetaMask WebsiteUsers may go to install MetaMask by searching Google and clicking on the top result - a sponsored link which claims to be the MetaMask website. After installing the MetaMask extension and setting up a wallet, any funds sent there would be drained. If they choose to restore...&quot;</title>
		<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=MetaMask_Phishing_InstallMetaMask.com&amp;diff=4849&amp;oldid=prev"/>
		<updated>2023-07-25T15:18:31Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;{{Imported Case Study 2|source=https://www.quadrigainitiative.com/casestudy/metamaskphishinginstallmetamaskcom.php}} {{Unattributed Sources}}  &lt;a href=&quot;/cryptocurrencyhackscamfraudwiki/index.php?title=File:Installmetamask.jpg&quot; title=&quot;File:Installmetamask.jpg&quot;&gt;thumb|Install MetaMask Website&lt;/a&gt;Users may go to install MetaMask by searching Google and clicking on the top result - a sponsored link which claims to be the MetaMask website. After installing the MetaMask extension and setting up a wallet, any funds sent there would be drained. If they choose to restore...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{Imported Case Study 2|source=https://www.quadrigainitiative.com/casestudy/metamaskphishinginstallmetamaskcom.php}}&lt;br /&gt;
{{Unattributed Sources}}&lt;br /&gt;
&lt;br /&gt;
[[File:Installmetamask.jpg|thumb|Install MetaMask Website]]Users may go to install MetaMask by searching Google and clicking on the top result - a sponsored link which claims to be the MetaMask website. After installing the MetaMask extension and setting up a wallet, any funds sent there would be drained. If they choose to restore an existing wallet, all their current funds would also be drained. This is because they installed malware instead of the actual MetaMask extension.&lt;br /&gt;
&lt;br /&gt;
This is a global/international case not involving a specific country.&amp;lt;ref name=&amp;quot;newsdotbitcoin-11402&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;cryptophishingtwitter-11403&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;diegomazorotwitter-11404&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;johnnyehltwitter-11405&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;poloskucingtwitter-11406&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;davejevanstwitter-11407&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== About MetaMask ==&lt;br /&gt;
&amp;quot;A crypto wallet &amp;amp; gateway to blockchain apps&amp;quot; &amp;quot;Start exploring blockchain application in seconds. Trusted by over 1 million users worldwide.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;[A] fraudulent extension redirects victims to installmetamask.com, which is not an official site of Metamask. Per Whois information, the web domain was registered on November 29, 2020. Ciphertrace found out the first mention in Twitter of the fraudulent domain from a user who asked Metamask team about the site’s authenticity&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;According to an alert published by Ciphertrace, since December 2, 2020, they have been noticing “an uptick of alerts and comments” about crypto funds stolen via a Chrome browser extension posing as the ethereum (ETH)-based wallet Metamask.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;U.S.-based Ciphertrace posted an update on December 3, 2020, detailing that phisher behind Metamask’s fake extension keeps buying sponsored ads on Google, which appear when people search for “metamask” term.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;@Google is allowing a phisher to buy sponsored ads on their search results. When using crypto, try to use direct links, and if you need to use search, watch out for sponsored links.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
This is a global/international case not involving a specific country.&lt;br /&gt;
&lt;br /&gt;
The background of the exchange platform, service, or individuals involved, as it would have been seen or understood at the time of the events.&lt;br /&gt;
&lt;br /&gt;
Include:&lt;br /&gt;
&lt;br /&gt;
* Known history of when and how the service was started.&lt;br /&gt;
* What problems does the company or service claim to solve?&lt;br /&gt;
* What marketing materials were used by the firm or business?&lt;br /&gt;
* Audits performed, and excerpts that may have been included.&lt;br /&gt;
* Business registration documents shown (fake or legitimate).&lt;br /&gt;
* How were people recruited to participate?&lt;br /&gt;
* Public warnings and announcements prior to the event.&lt;br /&gt;
&lt;br /&gt;
Don't Include:&lt;br /&gt;
* Any wording which directly states or implies that the business is/was illegitimate, or that a vulnerability existed.&lt;br /&gt;
* Anything that wasn't reasonably knowable at the time of the event.&lt;br /&gt;
There could be more than one section here. If the same platform is involved with multiple incidents, then it can be linked to a main article page.&lt;br /&gt;
&lt;br /&gt;
== The Reality ==&lt;br /&gt;
This sections is included if a case involved deception or information that was unknown at the time. Examples include:&lt;br /&gt;
&lt;br /&gt;
* When the service was actually started (if different than the &amp;quot;official story&amp;quot;).&lt;br /&gt;
* Who actually ran a service and their own personal history.&lt;br /&gt;
* How the service was structured behind the scenes. (For example, there was no &amp;quot;trading bot&amp;quot;.)&lt;br /&gt;
* Details of what audits reported and how vulnerabilities were missed during auditing.&lt;br /&gt;
&lt;br /&gt;
== What Happened ==&lt;br /&gt;
The specific events of the loss and how it came about. What actually happened to cause the loss and some of the events leading up to it.&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+Key Event Timeline - MetaMask Phishing InstallMetaMask.com&lt;br /&gt;
!Date&lt;br /&gt;
!Event&lt;br /&gt;
!Description&lt;br /&gt;
|-&lt;br /&gt;
|December 6th, 2020 10:19:00 AM MST&lt;br /&gt;
|Site Removed&lt;br /&gt;
|The site is blacklisted.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Technical Details ==&lt;br /&gt;
This section includes specific detailed technical analysis of any security breaches which happened. What specific software vulnerabilities contributed to the problem and how were they exploited?&lt;br /&gt;
&lt;br /&gt;
== Total Amount Lost ==&lt;br /&gt;
The total amount lost is unknown.&lt;br /&gt;
&lt;br /&gt;
How much was lost and how was it calculated? If there are conflicting reports, which are accurate and where does the discrepancy lie?&lt;br /&gt;
&lt;br /&gt;
== Immediate Reactions ==&lt;br /&gt;
How did the various parties involved (firm, platform, management, and/or affected individual(s)) deal with the events? Were services shut down? Were announcements made? Were groups formed?&lt;br /&gt;
&lt;br /&gt;
== Ultimate Outcome ==&lt;br /&gt;
What was the end result? Was any investigation done? Were any individuals prosecuted? Was there a lawsuit? Was any tracing done?&lt;br /&gt;
&lt;br /&gt;
== Total Amount Recovered ==&lt;br /&gt;
There do not appear to have been any funds recovered in this case.&lt;br /&gt;
&lt;br /&gt;
What funds were recovered? What funds were reimbursed for those affected users?&lt;br /&gt;
&lt;br /&gt;
== Ongoing Developments ==&lt;br /&gt;
What parts of this case are still remaining to be concluded?&lt;br /&gt;
== General Prevention Policies ==&lt;br /&gt;
Never install a wallet through sponsored ads.&lt;br /&gt;
== Individual Prevention Policies ==&lt;br /&gt;
{{Prevention:Individuals:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Individuals:End}}&lt;br /&gt;
&lt;br /&gt;
== Platform Prevention Policies ==&lt;br /&gt;
{{Prevention:Platforms:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Platforms:End}}&lt;br /&gt;
&lt;br /&gt;
== Regulatory Prevention Policies ==&lt;br /&gt;
{{Prevention:Regulators:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Regulators:End}}&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references&amp;gt;&amp;lt;ref name=&amp;quot;newsdotbitcoin-11402&amp;quot;&amp;gt;[https://news.bitcoin.com/fraudulent-crypto-browser-extension-redirects-to-a-fake-metamask-domain/ Fraudulent Crypto Browser Extension Redirects to a Fake Metamask Domain – News Bitcoin News] (Oct 10, 2022)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;cryptophishingtwitter-11403&amp;quot;&amp;gt;[https://twitter.com/CryptoPhishing/status/1335634882039586829 @CryptoPhishing Twitter] (Jul 24, 2023)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;diegomazorotwitter-11404&amp;quot;&amp;gt;[https://twitter.com/diegomazoro/status/1332798029301215232 @diegomazoro Twitter] (Jul 24, 2023)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;johnnyehltwitter-11405&amp;quot;&amp;gt;[https://twitter.com/johnnyehl/status/1333861716598329355 @johnnyehl Twitter] (Jul 24, 2023)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;poloskucingtwitter-11406&amp;quot;&amp;gt;[https://twitter.com/polos_kucing/status/1335805555630366725 @polos_kucing Twitter] (Jul 24, 2023)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;davejevanstwitter-11407&amp;quot;&amp;gt;[https://twitter.com/davejevans/status/1334263010089598977 @davejevans Twitter] (Jul 24, 2023)&amp;lt;/ref&amp;gt;&amp;lt;/references&amp;gt;&lt;/div&gt;</summary>
		<author><name>Azoundria</name></author>
	</entry>
</feed>