MetaMask Adds Human Support and AI Defenses Against Web3 Scams
MetaMask targets social engineering and address poisoning with AI-powered safeguards

MetaMask is redesigning its security tools as transnational cybercriminals use advanced technology to scale highly persuasive financial fraud. The self-custody cryptocurrency wallet, developed by Consensys, is rolling out protections aimed at the psychological manipulation and technical exploits behind modern web3 scams.
The changes include transfer warnings for lookalike addresses, first-time recipients, and suspicious destinations across MetaMask’s mobile and desktop versions. A separate “Added Protection” feature is designed to automatically revert a transaction when its execution state differs from the initial preview shown to the user. It will launch first through the desktop browser extension before reaching the mobile application.
Some scams do not begin with a technical attack. In “pig butchering” schemes, also known as romance and investment scams, perpetrators can spend weeks or months building rapport through WhatsApp, Telegram, and other communication platforms. Victims are then directed to send funds to fraudulent decentralized applications, or dApps, and wallet addresses.
Martin Peko, Staff Product Manager at MetaMask, said static warning prompts often fail because scammers prepare victims to ignore them. “This told us something specific: they either trusted the recipient far more than usual, or they were being actively coached past it,” Peko told Decrypt. “That’s what made us think a different kind of control was needed.”
MetaMask is therefore adding a direct route to priority customer support inside transaction warning screens. When an alert identifies a possible romance or investment scam, users can connect immediately with a human support representative to verify the transaction instead of receiving only an instruction to cancel it.
The wallet provider is also using artificial intelligence to keep pace with automated malicious actors. MetaMask works with web3 security firm Blockaid, whose systems identify threats in real time.
“Our security partner Blockaid uses LLMs [large language models] and classification models, within custom agent harnesses, to analyze unstructured content across websites and social feeds at scale,” Peko explained. Blockaid combines that work with static and dynamic analysis of on-chain bytecode and transaction flows to identify phishing and malicious behaviors.
![]()
Another target is “address poisoning.” Bad actors monitor public blockchains and use automated scripts to create vanity addresses that resemble those regularly used by a victim, sometimes matching the exact beginning and ending characters. They send a negligible, often zero-value, transaction to the victim’s wallet, placing the fraudulent address in the transaction history.
If the victim later copies an address from that history rather than checking the legitimate recipient, the lookalike address can receive the transfer. The new warnings and the Added Protection feature are intended to address this type of automated technical exploit as well as suspicious destinations identified during a transaction.
Blockaid was founded in 2022 by former Israeli military intelligence officers. The company raised $33 million in Series A funding in late 2023 to expand its real-time security scanning capabilities. MetaMask’s use of Blockaid’s security layer moves beyond static, database-driven blacklist warnings toward dynamic, context-aware risk assessments.
The changes come as law enforcement agencies pursue the financial infrastructure supporting romance and investment scams. In July, U.S. federal prosecutors seized more than $25 million in cryptocurrency tied to international romance fraud schemes that targeted thousands of people in the United States and Canada.
In early September, the U.S. Secret Service froze $52.8 million in digital assets connected to Xinbi Guarantee. Operating as an over-the-counter, or OTC, marketplace on Telegram, Xinbi served as a clearinghouse for transnational organized crime syndicates in Southeast Asia to wash proceeds from romance-investment operations.
The escalating regulatory pressure comes as commoditized cybercrime tools lower the barrier to launching sophisticated phishing websites and address spoofing contracts, increasing the need for native safeguards in retail wallets.
MetaMask’s security rollout also coincides with a restructuring at parent company Consensys. Founded by Ethereum co-founder Joseph Lubin in 2014, Consensys is separating its core consumer products, including MetaMask and the developer suite Infura, from its institutional blockchain and venture capital businesses.
The planned separation is scheduled for completion by the end of 2026 and is intended to streamline operations while positioning the individual business units to operate independently amid evolving global regulatory frameworks. Disclosure: Consensys is an investor in Dastan, the parent company of Decrypt.









