Software review — MetaMask
MetaMask review: essential, and a target
You will end up with MetaMask whether you planned to or not, because the Ethereum ecosystem is built around it. The software is solid. The industry of people trying to steal from its users is the largest in crypto, and that shapes how you should use it.
- 0.875% In-app swap fee, highest of the mainstream apps
- Open Largely open source, maintained by Consensys
- #1 Most impersonated brand in crypto phishing
- Pairable Works with Ledger and Trezor hardware
At a glance
The default key to the Ethereum ecosystem — and the single most impersonated brand in crypto phishing.
Best for: DeFi, dApps and anything EVM · Maker: Consensys
Why you will end up with it anyway
There is not much point pretending this is a free choice. If you want to use an Ethereum application — a decentralised exchange, a lending protocol, an NFT marketplace, a governance vote — the application was built and tested against MetaMask, its documentation assumes MetaMask, and its support channel will tell you to use MetaMask. Network effects in developer tooling are extremely durable, and this is one of the most durable in software.
Fortunately the software deserves its position reasonably well. It is largely open source, so the code handling your key can be reviewed. It is properly non-custodial — Consensys cannot move your funds. It supports hardware wallet accounts for both Ledger and Trezor, which is the single most valuable security feature it has. And it includes permission management, so you can see and revoke token allowances without installing a third-party tool that might itself be malicious.
What it does not have is any protection against the thing that actually costs its users money. MetaMask is the most impersonated brand in cryptocurrency, and that is not a figure of speech — the volume of fake support accounts, cloned wallet sites, malicious look-alike extensions and "validate your wallet" phishing pages built specifically around this brand is larger than for any other product in the space. Being the default makes you the target.
Specifications
| Maker | Consensys |
|---|---|
| Price | Free |
| Platforms | Browser extension, iOS, Android |
| Custody | Non-custodial — keys generated and stored on device |
| Source code | Largely open source |
| Asset support | EVM chains, plus Solana |
| Staking | Pooled and validator staking for ETH |
| Swap fee | Approximately 0.875% on top of the route |
| Hardware pairing | Ledger and Trezor supported |
| Backup | BIP39 12-word recovery phrase, portable to any compatible wallet |
| Last verified | September 2026 |
Browser extensions are the worst place for a key
This is worth understanding properly, because it changes how you should use MetaMask rather than whether you should.
A mobile wallet stores keys in the phone's hardware-backed keystore, inside an app sandbox that the operating system enforces strictly. A browser extension lives in the browser, which is a single process family shared with every page you have open and every other extension you have installed. Extensions run with broad permissions, they update automatically, and they change hands — there is a well-documented pattern of popular extensions being sold to new owners who then push a malicious update to an established install base.
None of that is MetaMask's fault and none of it means the extension is compromised. It means the environment is inherently more exposed than a phone, and the correct response is to limit what is at stake there. Keep a working balance in the extension. Keep your savings on a hardware wallet. And be genuinely ruthless about which other extensions you have installed — every one of them is running in the same neighbourhood as your keys.
The upgrade that solves most of this
Pair MetaMask with a Ledger or Trezor. The interface and every dApp connection work exactly as before, but the private key sits in the device's secure element and every transaction must be confirmed on the device's own screen. A malicious page can still ask you to sign something bad — that is your judgment call, not the device's — but a compromised browser can no longer take the key, and it cannot lie to you about the destination. NZ$99 from GROOV in Christchurch.
The 0.875% question
MetaMask charges approximately 0.875% on in-app swaps, layered on top of whatever the underlying route costs and the network fee. That makes it the most expensive of the mainstream wallets for swapping — Phantom takes 0.85%, Trust Wallet is cheaper still, and doing the trade on an exchange is usually cheaper than any of them.
Whether this matters is purely a function of size. Swapping NZ$150 of one token for another costs you about NZ$1.30 in MetaMask fees and it is not worth thinking about. Swapping NZ$10,000 costs nearly NZ$90 in wallet fees alone before the route spread and gas, and at that point the extra ten minutes of moving to an exchange and back is clearly worth it.
The reason people pay it anyway is that the fee is embedded in the quoted rate rather than shown as a line item, so it does not feel like a fee. The habit worth building is to check the pair's market rate before accepting any in-wallet swap quote, on any wallet. Our fees guide covers all three layers of cost — network, route and wallet — and how to separate them.
The balance sheet
What we like, and what we don't
What it does well
- Largely open source, so the key-handling claims can be independently reviewed
- Universal compatibility — effectively every Ethereum application is built and tested against it
- Hardware wallet support for Ledger and Trezor, which is the best available security upgrade for a dApp user
- Built-in permission and allowance management, so revoking approvals does not require a third-party tool
- Both pooled and validator ETH staking available
- Extension plus mobile app with the same wallet across both
- Enormous documentation and community troubleshooting base — every problem has been solved publicly
What we hold against it
- The most impersonated brand in crypto: fake support, cloned sites, malicious extensions and phishing at industrial scale
- A 0.875% swap fee, the highest of the mainstream wallets, on top of route cost and network fee
- A browser extension is the most exposed place a private key can live — same process space as every page and every other extension
- No transaction simulation showing what a signature will do to your balances before you approve
- EVM-first, so a poor choice for Bitcoin holders
- The interface has grown considerably in commercial surface, with buy, sell, swap, bridge and stake panels competing for attention
The phishing problem, specifically
We want to be concrete about this, because "be careful of scams" is useless advice. Here is what actually targets MetaMask users, in rough order of frequency.
Fake support. You post a problem in a public forum or Discord and within minutes receive a direct message from someone presenting as MetaMask support. They will ask you to "validate" or "sync" your wallet by entering your recovery phrase into a form, or to connect it to a diagnostic site. MetaMask does not have direct message support. Nobody legitimate will ever ask for your recovery phrase.
Cloned sites reached through search adverts. Searching for "metamask download" has repeatedly surfaced paid results pointing at convincing look-alike sites distributing modified extensions. Type metamask.io directly.
Malicious approvals dressed as a claim. An airdrop claim page, a mint, a "you have been selected" notification. The signature you are asked for grants a spending allowance rather than claiming anything. The wallet did what you asked.
Address poisoning. An attacker sends you a dust transaction from an address that looks like one you use often, with the same first and last characters, so that when you copy a recipient from your transaction history you copy theirs. Always get addresses from the source, never from history.
Full treatment, with the specific defences for each, in our scams and wallet drains guide.
Audit your approvals — today, if you have not
If you have used MetaMask for more than a few months, you almost certainly have active token allowances granted to contracts you cannot name. Some of them are probably unlimited. Each is a standing permission for that contract to move that token out of your wallet at any point in the future.
MetaMask has permission management built in, under connected sites and token allowances. Go through it. Remove anything you do not recognise. Remove every unlimited approval for something you are not actively using. It takes five minutes and it closes doors that have been standing open, in some cases for years.
If you use a third-party revocation tool instead, verify it carefully — fake revocation sites exist specifically to catch people in the act of trying to be careful, which is about as cynical as this industry gets.
Our view
The most useful mental model for MetaMask is that it is a browser for a hostile internet, not a bank. You would not keep your life savings inside a browser tab, and the same instinct should apply here. Install it, use it, keep the balance at the level of "annoying to lose", and put the savings behind a device that makes you press a physical button while reading a screen a website cannot control.
MetaMask FAQ
MetaMask — questions New Zealanders ask
Is MetaMask safe?
The software is largely open source, non-custodial and maintained by Consensys, and its key handling has not been broken. What makes MetaMask users lose money is the environment around it: it is the single most impersonated brand in crypto, so fake support accounts, cloned websites, malicious browser extensions and "wallet validation" pages targeting MetaMask exist in enormous volume. The app is fine. The ecosystem hunting its users is not, which is why we pair it with a hardware wallet the moment balances get serious.
What are MetaMask swap fees?
MetaMask charges roughly 0.875% on swaps, on top of whatever the underlying route costs and the network fee. That makes it the most expensive of the mainstream wallets for in-app swapping — Phantom is 0.85% and Trust Wallet is cheaper again. On small trades it is irrelevant. On a NZ$10,000 swap it is nearly NZ$90 in wallet fees alone, and doing the trade elsewhere is worth the extra step.
Can I use MetaMask with a Ledger or Trezor?
Yes, and you should once you hold a meaningful amount. MetaMask supports hardware wallet accounts, so the interface and dApp connectivity stay the same while the private key sits in the device's secure element and every transaction is confirmed on the device's own screen. This is the single best security upgrade available to a MetaMask user, and it costs about NZ$99 for a Ledger Nano S Plus from a New Zealand reseller.
Does MetaMask support Bitcoin?
MetaMask is built for EVM chains and has expanded to Solana, but it is not a Bitcoin wallet in any serious sense. If you hold Bitcoin, use a wallet designed for it — BlueWallet on mobile, or a Bitcoin-focused hardware device like Coldcard or Blockstream Jade. Using an EVM-first wallet for Bitcoin means accepting a smart-contract wallet's risk surface for an asset that does not need it.
How do I revoke MetaMask token approvals?
MetaMask has permission management built into the settings for connected sites and token allowances, and there are also well-known third-party revocation tools — use only ones you can verify, since fake revocation sites exist specifically to catch people trying to be careful. Go through your allowances, remove anything you cannot identify, and remove any unlimited approval you are not actively using. This is a five-minute task with a very high return. See our drains guide.
Next in this cluster