MetaMask announced the new wallet protection on September 14, 2026, targeting a category of crypto scams that often relies less on technical exploits and more on social engineering.
The feature is designed to intervene at the point when a user is preparing to send funds, asking questions and displaying alerts intended to expose warning signs before a transaction is completed.
The move comes as cryptocurrency users continue to face scams in which fraudsters build relationships with victims before persuading them to transfer money. Unlike attacks involving malicious smart contracts or compromised websites, these schemes can involve weeks or months of conversation before a victim is convinced to move funds.
MetaMask said the new wallet protection is intended to address that gap by bringing security checks into the transaction process itself.
The company pointed to data from the FBI’s Internet Crime Complaint Center, which linked $7.2 billion in losses to cryptocurrency investment scams in the United States during 2025. MetaMask argued that conventional security systems can struggle with these attacks because the transactions may not initially appear malicious when assessed through technical indicators alone.
The new system therefore focuses on the circumstances surrounding a transfer, rather than simply asking whether the destination is associated with known malicious code.
Last year, MetaMask, Phantom and WalletConnect launch real-time phishing defense after $400M stolen in 2025
How the wallet protection detects social scams
MetaMask’s wallet protection works by looking for indicators associated with romance and investment scams as a user prepares to send funds.
According to the company, the system includes a check from security firm Blockaid, which can flag destination addresses that have previously been identified as malicious. When MetaMask detects potential warning signs, users are presented with a series of questions intended to encourage them to reconsider the transaction.
Those questions are designed around common characteristics of social-engineering scams. Users may be prompted to consider whether they have actually met the person they are sending money to, whether they were promised guaranteed returns or whether they are being pressured to act quickly.
The approach reflects a middle ground between simply displaying a warning and automatically blocking a transaction.
MetaMask said it does not want to make the decision entirely on behalf of the user. Instead, the wallet protection is designed to create an additional moment of scrutiny before funds leave the wallet.
That distinction is important in a self-custodial wallet environment, where users ultimately retain control over their assets and transaction decisions. MetaMask’s existing security system already uses trust signals and security alerts to identify potentially dangerous websites, addresses, tokens and transactions.
Wallet protection targets romance and investment scams
Romance and investment scams present a particular challenge because the victim may voluntarily initiate the transaction.
In a conventional phishing attack, for example, a criminal might trick a user into connecting to a malicious website or signing a harmful transaction. Social scams can operate differently. The criminal first establishes credibility and trust, then gradually convinces the victim to transfer funds.
MetaMask described these schemes as attacks that rely on patience rather than code. Fraudsters may present themselves as friends, romantic partners or investment advisers and progressively increase pressure on their targets.
That makes wallet protection at the point of transfer particularly relevant. By asking questions immediately before a transaction, MetaMask is attempting to disrupt the final stage of the scam rather than relying solely on threat intelligence gathered beforehand.
The company also says the intervention is intended to have an educational effect. By showing users the warning signs associated with a suspicious transfer, the system could help them recognize similar approaches in future interactions.
However, the protection does not eliminate the underlying risks of self-custody. MetaMask continues to warn users never to share their Secret Recovery Phrase or private keys and notes that transactions on the blockchain generally cannot be reversed once completed.
MetaMask expands wallet protection across its platforms
The new wallet protection is now available on MetaMask Mobile version 8.11 and later and MetaMask Extension version 13.48 and later, covering all EVM networks, according to the company.
The rollout adds to a broader set of security measures MetaMask has introduced as cryptocurrency scams become increasingly varied. Its existing security alerts can identify signals linked to phishing, impersonation, malicious addresses and other harmful activity, while transaction simulations can assess whether an interaction could result in a loss of funds.
MetaMask’s wider security infrastructure also includes phishing protection, threat monitoring and integrations with security providers. The company has previously highlighted address-poisoning detection and other measures designed to respond to evolving attacks across the cryptocurrency ecosystem.
The latest wallet protection nevertheless focuses on a different vulnerability: the user’s own decision-making under social pressure.
Rather than treating every risky transaction as something that should automatically be stopped, MetaMask is placing an additional checkpoint between the decision to send and the transfer itself. For users facing increasingly sophisticated social-engineering campaigns, that pause could provide an opportunity to reconsider a transaction before it becomes irreversible.
The company’s approach also underscores a continuing challenge for the cryptocurrency industry. As technical security improves, scammers are increasingly able to exploit trust, urgency and human relationships rather than relying exclusively on vulnerabilities in blockchain infrastructure.