DIGITAL ASSET RISK

Crypto products can result in total loss. A rating is not proof of solvency, safety or local availability.

Read the safety standard
M

Self-custody wallet · Evidence assessment

MetaMask

Self-custody software wallet and Web3 gateway

MetaMask is a self-custody browser and mobile wallet whose value lies in broad Web3 access. Its main risks move from exchange counterparty exposure to recovery, signing, permissions, endpoint security and privacy choices.

Custody model

Self-custody

Users control wallet access and bear recovery responsibility.

Evidence state

Public sources reviewed

Assessment reflects the cited public record and product documents.

Decision focus

Recovery, signing and privacy

Exchange liquidity metrics do not apply to this wallet.

Editorial assessment

The decision in plain language.

MetaMask remains a capable default for users who need broad EVM application access, but it rewards careful operational habits. It is strongest when paired with a hardware wallet, deliberate permission review and an offline recovery plan; convenience features should not obscure transaction or telemetry trade-offs.

Best suited to

Experienced or learning Web3 users who need EVM dapp access and will actively manage keys, permissions and recovery.

Primary trade-off

Broad compatibility and convenience expose users to complex signing, phishing and recovery decisions that no support desk can reverse.

Evidence-backed strengths

  • Well-documented self-custody and recovery concepts.
  • Broad browser/mobile dapp integration and hardware-wallet workflows.
  • Public repositories and a visible security programme provide inspectable evidence.

"Limitations to resolve"

  • Self-custody makes seed-phrase and signing mistakes potentially irreversible.
  • Built-in swaps carry a MetaMask fee in addition to network and route costs.
  • Telemetry and third-party RPC or security-service data paths require an explicit privacy decision.

Evidence review

What the public record currently supports.

Each conclusion is bounded by its product, jurisdiction and source type.

01

Key control and recovery

MetaMask describes itself as self-custodial: the provider cannot recover a traditional Secret Recovery Phrase for the user. Newer social-login recovery uses encrypted key shares and creates a different dependency model, so the setup path must be documented rather than collapsed into one label.

S01S02

Evidence reviewed
02

Onchain safety is behavioural

Transaction simulations, alerts and hardware-wallet support can reduce risk, but users still authorise contracts and bear phishing exposure. No legitimate support request should require a Secret Recovery Phrase or private key.

S02S07

Evidence reviewed
03

Swap cost is layered

MetaMask's swap guide currently discloses a 0.875% MetaMask fee in addition to network and route costs. Gasless flows can change how gas is collected, but do not make an onchain transaction economically free.

S03

Evidence reviewed
04

Privacy requires configuration

MetaMetrics settings, RPC providers and security simulations can involve wallet addresses, transaction hashes and device or usage data. Users should review the current notice and settings rather than assuming self-custody equals anonymity.

S04

Evidence reviewed
05

Code and audit scope

The extension and mobile repositories are public, but licences and coverage differ; public code is not synonymous with a fully permissive open-source product. Security reviews are scoped, and the 2023 support-ticket data incident remains relevant even though it was not described as a private-key breach.

S05S06S07S08

Evidence reviewed

Decision dossier

From evidence to an accountable decision.

Ten separate modules prevent product scope, legal status, cost, control and remedy from collapsing into one brand impression. Sources were retrieved on .

01

Answer first

MetaMask is a strong EVM access tool for users prepared to own recovery, inspect every signature and manage permissions. It is safer as a deliberately configured signing interface—ideally with hardware-backed keys—than as an invisible browser convenience.

Source register · retrieved 17 Aug 2026
02

Who should not choose it

It is unsuitable for anyone expecting a provider to reverse a bad signature, recover a traditional Secret Recovery Phrase, guarantee dapp safety or make self-custody anonymous by default.

Source register · retrieved 17 Aug 2026
03

Product and legal-entity scope

Browser extension and mobile builds are distinct software surfaces. The dossier covers the self-custody wallet, not MetaMask Portfolio as a custodial exchange, and distinguishes traditional SRP recovery from newer login/key-share paths.

Source register · retrieved 17 Aug 2026
04

Custody and security controls

The user controls the SRP/private keys and authorises transactions. Hardware-wallet integration can isolate key material, but the screen and browser still mediate intent; simulation, alerts and permissions reduce risk without making malicious approvals reversible.

Source register · retrieved 17 Aug 2026
05

Regulation and customer protection

A self-custody wallet is not an exchange account and does not provide deposit insurance, an ombudsman or platform custody. Regulation of integrated fiat, swap or third-party services must be assessed at the provider and route level.

Source register · retrieved 17 Aug 2026
06

Fees and total-cost recipe

For the same token swap, record MetaMask’s quoted route, 0.875% provider fee where currently disclosed, gas, price impact, slippage setting and minimum received, then compare one direct DEX route. No cheaper-path conclusion is claimed until both executable quotes share a block/time window.

Source register · retrieved 17 Aug 2026
07

Funding, withdrawal and exit

Receiving and sending are onchain actions; built-in purchase or bridge flows may introduce third parties. A safe exit test uses disposable funds, verifies network and address, checks simulation and confirms finality without exposing the SRP.

Source register · retrieved 17 Aug 2026
08

Execution, API or wallet permissions

The decisive wallet metric is not exchange latency but what the user is asked to sign. Tests should cover token approvals, permit signatures, chain switching, spending caps, connected-site revocation and hardware-device confirmation.

Source register · retrieved 17 Aug 2026
09

Privacy and telemetry

MetaMetrics is configurable, while RPC, phishing/simulation and third-party transaction services can receive addresses, hashes or device/usage data. The right question is which data path each enabled feature creates, not whether self-custody equals privacy.

Source register · retrieved 17 Aug 2026
10

Support and dispute route

MetaMask support cannot reverse a confirmed onchain transaction or safely request an SRP. A valid support test should verify anti-impersonation guidance, official channels and escalation for software or data issues, while distinguishing those from unrecoverable key loss.

Source register · retrieved 17 Aug 2026

Fit boundary

Four situations, before a brand preference.

Fits

You need broad EVM dapp access and understand signing authority.

MetaMask is a mature interface for EVM account and permission workflows.

Fits

You can pair daily use with hardware-backed keys and permission review.

That configuration reduces key exposure while preserving access.

Does not fit

You need provider-assisted recovery of a lost SRP.

The traditional recovery model leaves the secret with the user.

Does not fit

You approve opaque prompts without inspecting spender, amount and chain.

Self-custody cannot reverse a valid harmful signature.

Reproducible scenarios

The next evidence, already specified.

These are protocols, not claimed results. Inputs remain fixed so later observations can be repeated or challenged.

S1

Fresh-device recovery

Fixed inputs: Disposable wallet, no valuable assets, documented SRP storage and clean device.

Capture: Prompts, account derivation, imported-account boundary, warnings and post-recovery security settings.

S2

Approval comprehension

Fixed inputs: Test token, controlled contract, standard approval plus permit-style message and hardware wallet where supported.

Capture: Human-readable fields, spender, amount, simulation, device display, rejection and revocation path.

S3

Swap total cost and telemetry map

Fixed inputs: Same wallet, chain, pair, amount and block window with MetaMetrics states recorded.

Capture: Route, fee, gas, minimum received, price impact and network requests visible to configured providers.

S4

Support impersonation drill

Fixed inputs: No-value wallet and a benign recovery/help question submitted only through an official channel.

Capture: Identity prompts, anti-SRP warning, channel hand-offs, resolution boundary and escalation for a software issue.

Incident and change timeline

What changed the risk picture.

  1. Consensys disclosed a support-ticket data incident.

    A wallet can preserve private keys yet still expose identity/support data and phishing opportunities.

  2. The public extension repository showed a current release trail during review.

    Version and official distribution provenance belong in every wallet assessment.

  3. Recovery, swap, telemetry, repository and security sources re-retrieved.

    Controlled signing and recovery scenarios are specified alongside the documentary review.

Alternatives

Choose by responsibility, not fame.

Trust Wallet

Broader multi-chain coverage matters more than MetaMask’s EVM-centred dapp convention.

Hardware wallet with a minimal companion

Key isolation and a narrower attack surface matter more than seamless browser integration.

Evidence confidence

Medium confidence, with a visible stop gate.

Supported
Official recovery, swap and telemetry documents plus public repositories support the control-model assessment.
Unresolved
Current signing comprehension, hardware behaviour, runtime data flows, recovery UX and third-party route costs are the primary variables in the account-level review.
What would change the conclusion
Material changes to recovery architecture, default telemetry, signature presentation or independently evidenced security outcomes would alter the recommendation.

Method applied

How this file is challenged.

  1. Fix app surface, version, operating system and recovery mode.
  2. Use disposable accounts and no valuable assets for signing/recovery tests.
  3. Record every party receiving data or transaction authority.
  4. Separate provider fee, route economics and network gas.

Dossier change log

Material editorial changes.

Added an integrated key-to-signature decision chain, privacy map and reproducible recovery, approval and swap protocols.

FAQ

Questions that decide whether the product fits.

Can MetaMask recover my SRP?

Not for the traditional SRP path. Anyone asking you to send it is a threat, not legitimate support.

Does a hardware wallet remove phishing risk?

No. It can isolate keys, but a user can still authorise a harmful transaction if the intent is misunderstood.

Are MetaMask swaps free?

No. Provider fee, route economics and network gas can all apply.

Does self-custody mean anonymous?

No. RPC, simulation, analytics and transaction providers may process addresses, hashes, device or usage data depending on configuration.

Applicable scorecard

Self-custody wallet scoring framework.

Weights are published in advance. An evidence gate can still block the final calculation.

Key & transaction security30%

Key control, signing clarity, permissions, phishing defenses and incidents.

Code & audit transparency15%

Source availability, audit scope, release provenance and governance.

Recovery & backup15%

Recovery models, backup choices, failure states and user responsibility.

Network & dapp coverage15%

Chains, assets, hardware support and onchain application access.

Privacy10%

Telemetry, data collection, account requirements and third parties.

Usability & support10%

Platforms, accessibility, transaction comprehension and help channels.

Built-in transaction cost5%

Wallet fees, provider markups and separation from network gas.

Source register

Documents behind the assessment.

Primary records establish legal and regulatory facts. Product documents establish current contractual or functional claims; they do not prove solvency or future performance.

Change control

Assessment history.

Material changes remain visible. A log entry records editorial work and the evidence behind each change.

C01

· Editorial assessment updated from cited primary records and product documentation.