New Registrations
MetaMask phishing domains
Newly registered lookalikes - tracked daily
MetaMask phishing domains
Newly registered lookalikes - tracked daily
Tracked (7d)
7
New (24h)
4
vs avg
—
Recently registered domains — may be used for phishing. Screenshots show parking pages while domains warm up. Use for Threat Hunting or watchlists.
| Last check (UTC) | First seen (UTC) ▾ | URL | Screenshot | Flags | Details |
|---|---|---|---|---|---|
| 2026-06-24 02:09 | 2026-06-24 02:09 | ![]() |
Details | ||
| 2026-06-24 01:39 | 2026-06-24 01:39 | ![]() |
Details | ||
| 2026-06-24 01:39 | 2026-06-24 01:39 | ![]() |
Details | ||
| 2026-06-24 01:39 | 2026-06-24 01:39 | ![]() |
Details | ||
| 2026-06-23 01:50 | 2026-06-23 01:50 | ![]() |
Details | ||
| 2026-06-20 02:26 | 2026-06-20 02:26 | ![]() |
Details | ||
| 2026-06-19 03:01 | 2026-06-19 03:01 | ![]() |
Details |
Recently registered domains — may be used for phishing. Screenshots show parking pages while domains warm up. Use for Threat Hunting or watchlists.
| URL | Screenshot | Details |
|---|---|---|
| https://wallet-metamask.biz
|
![]() |
Details |
| https://metamaskverifyweb3.com
|
![]() |
Details |
| https://metamaskcare.com
|
![]() |
Details |
| https://metamask-transit.biz
|
![]() |
Details |
| https://metamaskrewards.biz
|
![]() |
Details |
| https://metamaskinvestigation…
|
![]() |
Details |
| https://metamaskpro.xyz
|
![]() |
Details |
AIHow to verify a real MetaMask URL
- Legitimate MetaMask URLs always end in
metamask.io(e.g.www.metamask.io,account.metamask.io). Anything else — including look-alike typosquats, hyphenated variations, or unfamiliar TLDs like.xyz/.top/.vip— is not MetaMask. - The domains listed above were registered within the last 7 days. New-domain age is itself a signal — MetaMask has owned
metamask.iofor years; brand-new look-alikes are almost never legitimate. - If you got the link from email, SMS, or social media, do not click it. Open
metamask.iofrom your browser bookmark or type the domain manually. - Real MetaMask pages almost never ask for credentials immediately after clicking from a message — treat any such redirect as a phishing attempt until the domain is verified.



