Is MetaMask – Crypto Wallet safe?

Clean risk

MetaMask sends transaction details to its Blockaid security-alerts API by default to check for threats before signing.

When a user initiates a transaction or signing request, MetaMask transmits the full JSON-RPC request body — including wallet address, recipient, value, and calldata — to security-alerts.api.cx.metamask.io for threat validation. This is the Blockaid phishing/drainer detection feature and is active by default. A local WASM model is used as a fallback only if the remote API is unavailable.

MetaMaskv13.42.0.0Firefox Add-ons
0Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Data recipients

security-alerts.api.cx.metamask.io
Updated 17 September 2026amo-725460