MetaMask, Phantom and several other cryptocurrency wallet providers announced Wednesday a partnership with the Security Alliance to establish a real-time phishing defense network, responding to losses exceeding $400 million from phishing attacks in the first six months of 2025.
What to Know:
- The defense network connects MetaMask, Phantom, WalletConnect and Backpack to share phishing threat data in real time
- Phishing attacks caused the highest number of security incidents in early 2025, according to blockchain security firm CertiK
- The system allows security researchers worldwide to validate and report malicious websites across all participating wallets simultaneously
New Infrastructure Targets Evolving Threats
The MetaMask team said the initiative creates what the Security Alliance (SEAL) describes as a "decentralized immune system for crypto security where anyone from around the world can prevent the next major phishing attack." The network works with SEAL's verifiable phishing reports system, announced last week, which lets security researchers demonstrate that suspicious websites contain actual phishing content rather than false positives.
The verification process addresses a persistent challenge in cryptocurrency security. Traditional defense methods struggle to keep pace with crypto drainers, malicious tools that extract funds from digital wallets.
These threats have adapted their methods to circumvent standard protections.
Attackers now rotate landing pages more quickly when security blocklists update. They shift to offshore hosting when infrastructure providers impose restrictions. They employ cloaking techniques that hide malicious code from automated scanning systems.
Wallet Providers Coordinate Response
Ohm Shah, a security researcher at MetaMask, said the situation resembles "a constant cat and mouse game." The partnership with SEAL enables wallet development teams to respond faster and implement security research findings more efficiently, Shah said, "effectively throwing a wrench at the drainer's infra."
The network establishes an automated pipeline for threat intelligence.
When users submit phishing reports, the system validates them and distributes warnings across all participating wallets without requiring manual approval or special permissions. This structure reduces response times when new phishing campaigns emerge.
SEAL stated it wants to expand the data sharing system to additional wallet providers. The organization did not specify which companies might join or provide a timeline for expansion.
The announcement comes as phishing has become the dominant attack vector in cryptocurrency theft. CertiK, a blockchain security firm, identified phishing as responsible for the most security incidents during the first half of this year. The firm's data shows attackers successfully stole more than $400 million through these methods.
Understanding Crypto Security Terms
Phishing in cryptocurrency involves attackers creating fake websites or communications that impersonate legitimate services to steal private keys or seed phrases. Drainers are sophisticated tools that automatically extract all assets from a compromised wallet once a user grants malicious permissions. Blocklists are databases of known malicious addresses and websites that security systems use to warn or block users from interacting with threats.
Cloaking techniques allow malicious websites to display different content to security scanners than what actual users see, helping attackers avoid detection by automated systems.
Closing Thoughts
The phishing defense network represents an industry effort to address cryptocurrency theft through coordinated threat intelligence sharing. Whether the system can match the pace of evolving attack methods remains to be demonstrated as more wallet providers consider participation.