MetaMask(メタマスク) Security Guide for Beginners

By Aytug Akyuz Published 18-minute read

Independent educational guide from Metadiscover. Not affiliated with MetaMask or Consensys Software Inc. No support, no advice.

Summary

  • MetaMask is self-custody wallet software. The person using it holds the keys, and no company can restore a lost Secret Recovery Phrase or a forgotten password.
  • Three secrets do three different jobs: the Secret Recovery Phrase is the master key, each account has its own private key, and the password only unlocks the app on one device.
  • The Secret Recovery Phrase belongs on paper, offline. It should never be typed into a website, sent to anyone, or kept in photos, cloud notes, email, or a password manager.
  • MetaMask states that its support team has no phone number, never contacts users first, and never asks anyone to verify, upgrade, or validate an account.
  • The scams MetaMask documents rely on persuasion rather than on breaking cryptography: fake support accounts, urgent messages, look-alike websites, airdrop claim pages, and unlimited token approvals.
  • Connecting to a site, signing a message, approving a token, and adding a network are separate permissions. Each one can be reviewed, limited, and removed.

This is an independent educational guide from Metadiscover, which is not affiliated with, endorsed by, or connected to Consensys Software Inc. or MetaMask. It does not provide technical support and does not recommend any product or service. The information reflects the official MetaMask help centre as of 2 September 2026; software features can change.

MetaMask (メタマスク) is a self-custody wallet application developed by Consensys Software Inc. It runs as a browser extension and as a mobile app, and it lets a person hold crypto-assets and interact with blockchain applications directly, without an intermediary holding the keys. That independence is the reason the software exists, and it is also why the security of a MetaMask wallet depends mostly on habits rather than on technology.

This guide explains, in plain English, how the security model works and what the official MetaMask help centre says about keeping a wallet safe. It is written for beginners, including readers in Japan who use the software in English or Japanese. It does not contain installation or troubleshooting instructions, it does not tell you what to buy or where to trade, and it does not describe how any attack is carried out. Terms are defined the first time they appear, and a glossary near the end lists the Japanese equivalents.

What MetaMask is, and what self-custody means

When you open an account with a bank or with a company that holds assets on your behalf, that company keeps the keys. If you forget your password, its staff can check your identity and let you back in. MetaMask works differently. It is non-custodial, or self-custody (自己管理(セルフカストディ)) software, and the help centre summarises this in one sentence: you are the custodian of your funds. When a wallet is created with a written Secret Recovery Phrase, the keys are generated on your own device and the phrase is never sent to Consensys or to anyone else. MetaMask also offers a sign-in option that uses a Google, Apple, or Telegram account, in which the phrase is backed up online as encrypted pieces that need both that account and your MetaMask password to reassemble.

Two consequences follow. First, no company holding assets on your behalf can move what the keys control, and MetaMask itself cannot open, empty, or freeze a wallet. Some tokens are issued by companies whose own contracts allow the issuer to block an address; that is a property of the token, not of the wallet. Second, nobody can reset access if the keys are lost. There is no account in the company's records to recover, because there is no account in that sense at all. The wallet is the keys, and the keys are protected by a short list of secrets described in the next section.

MetaMask connects to public blockchains, most commonly Ethereum and networks compatible with it, and lets websites known as decentralised applications, or dapps, propose transactions for you to approve. Every transaction leaves the wallet only after you confirm it on your own device.

The three secrets: recovery phrase, private keys, and password

Beginners often treat the words "password", "private key", and "recovery phrase" as interchangeable. They are not, and understanding the difference is the foundation of MetaMask security.

SecretWhat it isWhat it controlsCan it be reset?
Secret Recovery Phrase
シークレットリカバリーフレーズ(シードフレーズ)
A unique phrase of twelve words generated when the wallet is first created. Often called a seed phrase.Every account created from it. The help centre calls it the master key: whoever controls the phrase controls those accounts. Accounts imported by their own private key, accounts held on a hardware device, and accounts belonging to a second phrase are not derived from it and are not restored by it.No. For a wallet created with a written phrase, MetaMask never receives it and cannot restore it.
Private key
秘密鍵
A long secret value that belongs to one account. The private key of an account created from the phrase is derived from it; an imported account brings its own.That single account and whatever it holds.No. It can be recreated from the phrase, but not replaced.
Password
パスワード
A password chosen by the user on each device where MetaMask is installed.Only the local copy of the wallet on that device. It unlocks the app; it does not exist on any server.Only by restoring the wallet on that device from the Secret Recovery Phrase.

The practical lesson is that the password protects against someone picking up your unlocked phone or laptop, while the Secret Recovery Phrase protects against everything else. A strong, unique password is worth having, but the phrase is what must never be exposed.

How to treat the Secret Recovery Phrase

The help centre's guidance on the Secret Recovery Phrase is short and unambiguous, and it is worth restating in plain terms.

  • It belongs offline. MetaMask's guidance is to write the twelve words down, in order, on paper or another durable material, and to keep that copy somewhere safe. It advises against storing the phrase online in any form, and names cloud storage and password managers as insecure places for it.
  • It does not belong in a photo library or an email inbox. Screenshots, photographs, notes apps, chat messages, and email are all places that other software can read and that attackers routinely search.
  • It is never entered on a website. MetaMask's documentation is explicit on this point. The only legitimate moment to enter it is when restoring the wallet inside the genuine MetaMask app or extension on a device you control.
  • It is never shared. That includes anyone who says they work for MetaMask. MetaMask will never ask for it. A request for the phrase, however polite or urgent, is the single clearest sign of a scam.
  • Understand what loss means. If the phrase is lost and the device holding the wallet is also lost or reset, the funds cannot be recovered. No company can help, because none of them has the phrase.

Many people keep a second written copy in a separate secure location, so that a fire or flood in one place does not destroy the only copy. Where and how to do that is a personal decision; the principle is that every copy must be physical, private, and offline.

If a phrase has ever been typed into a website, shown on a shared screen, or sent in a message, the safe assumption is that it is no longer secret. The help centre's guidance for a compromised wallet is to create a new wallet with a new phrase on a device you trust and send any remaining funds to it, because a phrase that may already be in someone else's hands cannot be made secret again; the same guidance states that transactions cannot be reversed and that MetaMask cannot intervene or recover funds.

How to recognise the genuine software

Cloned versions of popular wallets exist, and the help centre warns that some are programmed to record the Secret Recovery Phrase as it is typed. Recognising the real software is therefore part of security, not a separate topic.

  • MetaMask states that genuine copies are distributed only through its own metamask.io domain and the official browser and mobile app stores listed there, and that a copy offered anywhere else should be treated as a clone.
  • Search engine results and advertisements can include look-alike websites whose names differ from the genuine domain by a letter or two. Reading the address bar carefully, and using a saved bookmark once the correct address is known, reduces this risk.
  • The genuine software behaves predictably. The help centre states that MetaMask will never pop up without you initiating a transaction. A window that appears on its own, asking for the phrase or for approval of something you did not start, is not MetaMask behaving normally.

What MetaMask says about its official channels

Many of the scams described in MetaMask's help centre begin with someone pretending to be support staff. MetaMask publishes the following facts about its own channels, and they make these impostors easy to identify.

  • There is no phone number. MetaMask Support does not have one and will never speak to a user on the phone. Anyone who calls, or asks you to call, is not MetaMask.
  • MetaMask never makes first contact. Its support team does not approach users. Unsolicited messages, direct messages on social platforms, and messaging-app contacts claiming to be MetaMask are all impostors.
  • Official replies come through official channels only. Genuine replies come from the official help centre and from email addresses at the metamask.io domain. Messaging apps, social media direct messages, and text messages are listed as channels MetaMask does not use.
  • There is nothing to verify. MetaMask will never ask a user to verify an account, complete an identity check, upgrade, validate, or synchronise a wallet, and threats of account closure are named as a scam marker.

The same logic applies to this website. Metadiscover publishes articles; it is not a support channel, it cannot see or affect any wallet, and it will never ask a reader for a phrase, key, or password.

Common scam patterns and the safe response

The help centre maintains a catalogue of the schemes that target its users. The list below describes what each one looks like from the outside and what the safe response is. It deliberately does not explain how any of them is carried out.

  • Fake support accounts. A profile with a familiar logo and a plausible name offers to help, usually by direct message, and eventually asks for the phrase or for a screen share. Safe response: nobody legitimate will ever need the phrase, so the conversation can end there.
  • Urgent messages. An email or text warns that the wallet will be restricted, requires an upgrade, or must be confirmed by a deadline, and provides a link. Japanese-language versions imitating official notices circulate as well. Safe response: the software has no accounts to restrict, and the sender's actual address rarely matches the organisation named in the message.
  • Look-alike websites. A site copies the appearance of a wallet or an application and asks the visitor to import or restore a wallet. Safe response: importing a wallet into a website is never a legitimate step, so the page can be closed.
  • Airdrop and claim pages. Unexpected tokens appear in the wallet with instructions to visit a site and claim them, or an offer promises free assets in return for connecting the wallet. The help centre's guidance is simple: unexpected tokens can be ignored, and a graph showing a dramatic rise is not a reason to believe the rise will continue.
  • Address poisoning. The help centre describes tiny transfers sent from an address that closely resembles one you have used before, in the hope that you will copy the wrong address from your history later. Safe response: check the whole address, not just the first and last characters, and use the wallet's contacts feature instead of transaction history.
  • Signature phishing. A site asks you to sign a message that appears harmless but grants it permission to move assets later. Safe response: a signature request that cannot be read and understood can be declined.
  • Recovery services. After a loss, an offer arrives from a person or company promising to retrieve the funds, usually for a fee paid in advance. Transactions on a public blockchain cannot be reversed by a third party, so these offers are a second scam aimed at the victim of the first.

The thread running through every pattern is pressure: urgency, flattery, or the promise of easy money. A calm general rule is that any request that would expose the phrase, hand over a signature you do not understand, or move assets under time pressure can be declined; a genuine service does not depend on haste.

Connections, signatures, and token approvals

Using MetaMask with an application involves three separate kinds of permission. Beginners often assume that connecting to a site is the dangerous step; in fact, each permission has its own scope.

Connecting to a site

The help centre explains that connecting lets a site see the addresses of the accounts you selected and suggest transactions for those accounts. The site cannot move anything on its own: every transaction it suggests still has to be approved by you. Connections are granted per account and per network, can be reviewed at any time, and can be removed. The help centre also notes that MetaMask cannot guarantee the safety or reliability of any application.

Signing a message

A signature (署名) proves that the holder of a private key agreed to a piece of text. Some signatures are harmless, for example proving that you own an address in order to log in. Others authorise an application to act on your behalf later, which is exactly what signature phishing exploits. MetaMask's guidance is to treat a signature request with the same care as a transaction and to decline requests that were not initiated by the user or cannot be read.

Token approvals and spending caps

A token approval (トークンの承認) gives an application permission to move a certain amount of a particular token from your account. The help centre describes the spending cap as the maximum amount the application may move. MetaMask asks for that limit when the approval is requested and lets the user enter a custom amount, and the help centre states that granting an unlimited allowance is never the safest choice. Approvals persist until they are changed, so the help centre recommends reviewing them periodically and revoking those that are no longer needed.

Networks, and why an unknown network is a risk

MetaMask can connect to many blockchain networks (ネットワーク), and websites can ask the wallet to add a new one. A network entry consists of a name, a connection address known as an RPC URL, a chain identifier, a currency symbol, and a block explorer address.

The help centre is explicit that MetaMask does not verify custom networks, and that even when its checks pass, the network could be malicious or misrepresented by the website that requested it. A dishonest network provider can lie about the state of the blockchain, withhold transactions, record your activity, and associate that activity with your internet address. MetaMask places the work of verifying any custom network on the reader, and it suggests checking the network name and chain identifier against an independent chain registry and against the network's own documentation before accepting a request to add it.

Hardware wallets, explained as a concept

A hardware wallet (ハードウェアウォレット) is a small physical device that holds the Secret Recovery Phrase and private keys outside the computer or phone. The help centre describes it as a firewall between attackers and your keys: MetaMask prepares a transaction, sends it to the device, the device signs it internally, and only the signed transaction returns to the computer to be broadcast. The phrase itself never touches an internet-connected machine, which is, in the help centre's words, the whole point of the device.

Two facts from the help centre are worth knowing before reading anything else about these devices. First, MetaMask documents compatibility with several families of device, connected either over USB or by scanning QR codes, and the current list is maintained on its hardware wallet hub. Second, an existing MetaMask Secret Recovery Phrase should never be imported into a hardware device, because a phrase that has already lived on an internet-connected machine would undermine the reason for having the device.

Whether a hardware wallet is worthwhile depends on how much someone holds and how comfortable they are managing a device. The help centre describes hardware wallets as the safest way to store larger holdings; this guide does not recommend any product and does not cover where or whether to obtain one.

Built-in warnings and settings worth knowing

  • Deceptive site warnings. When a site appears on the public block-list of known phishing domains that MetaMask maintains, MetaMask shows a full-screen warning before allowing a connection. The help centre recommends not connecting to sites that trigger it.
  • Security alerts. MetaMask shows alerts, enabled by default in the extension and the mobile app, that flag transactions and signature requests matching known scam and phishing patterns. Its documentation says where the setting can be changed; because settings change between versions, readers should check the current help centre rather than relying on a description here.
  • Updates. Updates obtained through the official store the software came from keep these protections current.
  • Locking. The wallet can be locked manually and locks itself after a period of inactivity, so that a device left unattended does not expose an open wallet.

What the official guidance adds up to

Read together, the statements quoted above describe six habits.

  1. The Secret Recovery Phrase exists only on paper, in one or two private places, and is never typed anywhere except inside the genuine app when restoring a wallet.
  2. A copy that did not come from MetaMask's own domain or the official app stores is treated as a clone, and the address is checked every time.
  3. Nobody from support will ever call, message first, or ask to verify anything. Anyone who does is an impostor.
  4. Connections, signatures, and token approvals are separate permissions, each read before it is accepted, with spending caps limited and old approvals reviewed.
  5. MetaMask does not verify custom networks, so a network addition is checked against that network's own documentation.
  6. A request that creates urgency or promises easy money is, in the help centre's account, a reason to stop rather than to hurry.

A note for readers in Japan

MetaMask's help centre is available in Japanese, and it uses the term シークレットリカバリーフレーズ for the Secret Recovery Phrase while recognising シードフレーズ as the everyday synonym. Japanese law refers to crypto-assets as 暗号資産, though 仮想通貨 remains common in conversation. On its crypto-asset information page, Japan's Financial Services Agency warns about emails and videos that impersonate the agency itself, and the same calm rule applies to those as to the patterns described above: a genuine organisation will not ask for a phrase, a key, or a password.

Glossary in English and Japanese

English termJapanese termMeaning
MetaMaskメタマスクSelf-custody wallet software developed by Consensys Software Inc.
WalletウォレットSoftware or a device that stores keys and creates transactions.
Self-custody自己管理(セルフカストディ)An arrangement in which the user, not a company, holds the keys.
Secret Recovery Phraseシークレットリカバリーフレーズ(シードフレーズ)The twelve-word master key from which every account in the wallet is derived.
Private key秘密鍵The secret belonging to one account that authorises its transactions.
PasswordパスワードA local secret that unlocks the app on one device.
AddressアドレスA public identifier that can receive transactions.
PhishingフィッシングDeception designed to obtain secrets or signatures.
Scam詐欺A fraudulent scheme intended to take assets.
Signature署名Cryptographic proof that a key holder agreed to a message or transaction.
Token approvalトークンの承認Permission for an application to move a set amount of a token.
NetworkネットワークA blockchain that the wallet can connect to.
Hardware walletハードウェアウォレットA physical device that keeps keys offline and signs transactions internally.
Crypto-asset暗号資産(仮想通貨)A digital asset recorded and transferred on a blockchain.

Frequently asked questions

Can MetaMask reset my password or recover my Secret Recovery Phrase?

No. The password exists only on your device, and a written Secret Recovery Phrase is never sent to Consensys. The help centre states that if the phrase is lost, the funds cannot be recovered. The only way to regain access on a new device is to restore the wallet from the phrase.

Does MetaMask have a phone number?

No. The help centre states that MetaMask Support does not have a phone number and will never speak to you on the phone. A phone call, or a request to make one, is a sign of an impostor.

What is the difference between a seed phrase and a Secret Recovery Phrase?

They are the same thing. MetaMask adopted the name Secret Recovery Phrase in 2021 to make its role clearer and to reduce confusion exploited by scammers. In Japanese, both シークレットリカバリーフレーズ and シードフレーズ are in use.

What does MetaMask say about a Secret Recovery Phrase that has been typed into a website?

MetaMask's position is that such a phrase can no longer be treated as secret. The practice it describes is to create a new wallet with a new phrase on a trusted device and to send any remaining funds to it, because anyone who holds the old phrase can use it at any time. The same guidance states that transactions cannot be reversed and that MetaMask cannot intervene. This guide cannot examine your situation; it describes the published guidance only.

Is it dangerous to connect MetaMask to a website?

Connecting reveals your selected addresses and lets the site suggest transactions, but nothing moves without your approval. The risk lies in what you approve or sign afterwards. MetaMask describes reviewing each request, limiting spending caps, and disconnecting from unused sites as the ways that risk is kept small.

Do I need a hardware wallet to use MetaMask safely?

No. A hardware wallet keeps keys offline and is described by the help centre as the safest option for larger holdings, but the habits in this guide apply with or without one. Whether a device is worthwhile is a personal decision based on how much is held and how comfortable someone is managing hardware.

Why is MetaMask security mostly about habits?

Because the cryptography that protects keys is rarely the weak point. In the cases the help centre describes, losses follow from a person being persuaded to reveal the phrase, sign something unread, or approve an unlimited allowance. Good habits remove those opportunities; no software setting can remove them on its own.

Sources

  • MetaMask Help Centre, "User guide: Secret Recovery Phrase, password, and private keys", accessed August 2026.
  • MetaMask Help Centre, basic safety and security guidance for MetaMask, accessed August 2026.
  • MetaMask Help Centre, "How do I recognize the real MetaMask?", accessed August 2026.
  • MetaMask Help Centre, What are MetaMask's official support channels?, and Will MetaMask ever ask me to verify my account?, accessed August 2026.
  • MetaMask Help Centre, Signature phishing, Address poisoning scams, and Scammers and phishers: rug pulls and airdrop scams, accessed August 2026.
  • MetaMask Help Centre, Connecting to a dapp, and How to customize token approvals with a spending cap, accessed August 2026.
  • MetaMask Help Centre, Verifying custom network information, and The risks of connecting to an unknown network, accessed August 2026.
  • MetaMask Help Centre, Hardware wallet hub, and User guide: How to use a hardware wallet, accessed August 2026.
  • Consensys Software Inc., MetaMask Terms of Use, 2026.
  • Financial Services Agency of Japan, information page on crypto-assets, 2026.

If some of the terms in this guide were new, our article What Is Blockchain and How Does It Work? explains the ledger, blocks, hashes, and consensus that every wallet relies on.