Is MetaMask – Crypto Wallet safe?
Clean risk
MetaMask sends transaction details to its Blockaid security-alerts API by default to check for threats before signing.
When a user initiates a transaction or signing request, MetaMask transmits the full JSON-RPC request body — including wallet address, recipient, value, and calldata — to security-alerts.api.cx.metamask.io for threat validation. This is the Blockaid phishing/drainer detection feature and is active by default. A local WASM model is used as a fallback only if the remote API is unavailable.
0Risk
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Data recipients
security-alerts.api.cx.metamask.io