Common fake-wallet forms
- A same-name mobile app distributed through an ad, chat file or APK link.
- A cloned browser extension claiming the real wallet is outdated.
- A web page that imitates a full-screen extension and asks for a seed phrase.
- Fake support that requests remote control, screen sharing or a “repair” app.
- A pre-created wallet whose seller kept the same recovery phrase.
Verify before installing
- Independently find the wallet developer's verified website.
- Follow the store link from that site and inspect the publisher.
- Check the full domain, permissions, update history and official support route.
- Reject requests for accessibility control, remote access or routine seed entry.
- Test unfamiliar Web3 activity with a separate empty or low-balance wallet.
MetaMask's official guidance says its real wallet is a browser extension or mobile app and that a seed phrase should never be entered on a conventional website. See How to verify the real MetaMask wallet.
If you installed a fake wallet
If no seed or signature was entered, preserve evidence, remove the software and inspect the device. If a seed or private key was entered, assume every derived account is compromised: create a new wallet on a clean device, move remaining assets and permanently retire the old phrase. If funds moved, preserve TxIDs and report through independently verified official and local channels.
Use the wallet scam risk checker or read the signature phishing guide.