Metamask Updates Privacy Policy: What You Need To Know | Biconomy (2024)

Consensys, the parent company of both Metamask and Infura, updated its privacy policy on 23rd November to inform its 30M+ users that their IP and Ethereum wallet addresses will be collected when they transact while using Infura as their default RPC provider on Metamask.

This was concerning for a lot of Metamask users who used to believe that their identity was completely hidden while using the wallet. However, the change in the policy should not come as a shock to those who are aware of how RPC works. Though, what’s concerning is if Metamask actually “stores” that data.

What’s RPC and why does it matter?

RPC stands for ‘remote procedure call’. This means that Infura takes requests from Metamask (or other software products that use it) and returns answers to those requests. For context, Infura is a set of APIs and on-chain services that act as a gateway to the Ethereum blockchain, allowing dApps to interact with decentralised networks without running a full node.

Let's say a user asks Metamask to get information on their wallet balance, this request is then passed to Infura who indexes that query and returns back the balance. To route back this information, the RPC provider (Infura) needs to know the IP address of the wallet to where the information has to be routed.

In an early Dec 2022 update, Metamask provided clarity on the situation.

  1. They do not store wallet account address information when a MetaMask user makes a “read” request through Infura. Like a request to check balance.
  2. They collect wallet and IP address information in connection with “write” requests, also known as transactions. The purpose of this collection is to ensure successful transaction propagation, execution, and other important service functionality such as load balancing and DDoS protection, as provided by Infura.
  3. IP addresses and wallet address data relating to a transaction are not stored together.
  4. They retain and delete user data such as IP address and wallet address. They are working on narrowing retention to 7 days.
  5. The company also clarified that it has never and will never sell any user data it collects.

Another important thing to note is that Metamask users have the option to change their RPC provider to a custom one ANYTIME. This means that if users don’t trust Infura then they can use Alchemy, Quicknode, or even connect their wallets to their own blockchain node.

What’s The Takeaway Here?

The concerning bit here is that currently, users cannot functionally "just use their own RPC" to avoid data leaking. This is because MetaMask doesn't allow setting the RPC until after the account setup is complete, and you cannot remove the default Infura endpoints which makes it very easy to accidentally leak data to Infura.

In response to this concern, Metamask has been prompt in introducing updates that will allow users to change the RPC provider before setting up their wallets. The update rolls out this week, and the information on the same can be found here: Github Metamast - Allow users to add custom RPC during onboarding #16696

The team has also opened an issue on GitHub, which when implemented, will prevent Metamask from making automatic RPC calls for balance updates. This would give users the option to opt-in for manual balance refreshing mode.


Don’t chuck that VPN subscription

The Metamask team understands that it caters to a wider audience and it acknowledges that even though most users desire better UX, some desire privacy over everything else. By giving user’s more flexibility and the option to opt out of their offerings, it suggests that the team supports maximum user agency.

While Metamask has proved its loyalty to the users, it is still always recommended to use VPN to make your identity untraceable. It is important to understand that true self-custody is achieved when no one can block your assets from any source possible, and that also includes location-based IP blockers.

Metamask Updates Privacy Policy: What You Need To Know | Biconomy (2024)

FAQs

What is the MetaMask privacy policy update? ›

The update provides users with greater transparency and control over their personal data, specifically concerning IP address processing. According to the new policy, Metamask may temporarily process a user's IP address only when required for certain services, depending on the user's Metamask settings.

Does MetaMask need to be updated? ›

MetaMask Extension automatically updates when you lock and then unlock the app.

What do you need to know about MetaMask? ›

MetaMask functions as an Ethereum wallet that allows storage for ETH, ERC-20 and ERC-721 tokens in one place. You can also create multiple wallet addresses and use them as you need. It gives users more control over their data by only generating a public and private key on their browser.

How to make sure your MetaMask is secure? ›

How can I secure my MetaMask wallet?
  1. Don't click suspicious links (especially if you don't know the sender)
  2. Use a strong, unique password and store it offline.
  3. Only ever download or update MetaMask from official sources.
  4. Always double check you're on the correct website before conducting transactions.

Does MetaMask report to government? ›

While Metamask transactions occur on the blockchain and are publicly visible, Metamask itself does not directly report to tax authorities.

Can MetaMask block your account? ›

MetaMask is a self-custodial wallet, which means we cannot control access to user accounts, nor intervene and rescue your account or funds for you.

Is MetaMask 100% safe? ›

MetaMask is safe and legit — it is trusted by more than 30 million users across the globe! When using any wallet, you should take steps to protect your cryptocurrency from hacks and malicious requests.

Is MetaMask asking for verification? ›

No legitimate MetaMask website will ever ask for your Secret Recovery Phrase. Non-malicious dapps will never do so either — so if any website does, don't enter it under any circ*mstances.

Is it safe to keep coins in MetaMask? ›

MetaMask provides a secure environment for storing your cryptocurrency assets; however, it's generally recommended to use hardware wallets for storing large amounts of cryptocurrency. Hardware wallets offer an extra layer of physical security by keeping your private keys offline.

Can I transfer money from MetaMask to my bank account? ›

At this time (May 2023), MetaMask does not support fiat withdrawals. So, in order to cash out your crypto to fiat money, like USD or EUR, you'll have to first transfer it to a platform that allows for fiat withdrawals, like ZenGo.

Who owns MetaMask? ›

MetaMask is developed by Consensys, a blockchain software company focusing on Ethereum-based tools and infrastructure.

What information does MetaMask collect? ›

They collect wallet and IP address information in connection with “write” requests, also known as transactions.

How do you know if your MetaMask wallet is compromised? ›

If you notice that unauthorized outgoing transactions are occurring from your wallet, your wallet has likely been compromised. This may have occurred through a variety of means including, but not limited to: Downloading malicious software. Inputting personal information on a phishing website.

How to clear privacy data on MetaMask? ›

Click the three dots in the upper right corner of your MetaMask interface, and click 'Settings'. Then, click 'Security & Privacy'. Scroll down until you see the 'Delete MetaMetrics data' button. Clicking this button will delete MetaMetrics data associated with your use on that specific device.

How do I check if my wallet is safe? ›

Check if the wallet has strong encryption, multi-factor authentication, and a good reputation. Also, look for open-source code and regular security updates.

What is the security warning on MetaMask? ›

How does it work? ​ Together, Blockaid and MetaMask have developed a security alert system using a privacy-preserving system that simulates transactions locally, providing warnings in your MetaMask wallet if a transaction is suspected as fraudulent.

How do I turn off privacy mode in MetaMask? ›

On MetaMask Mobile, you can adjust your privacy settings by clicking the cogwheel icon in the lower left corner of the app, then clicking 'Security & Privacy'.

What is the security policy of MetaMask? ›

Don't share your Secret Recovery Phrase and private keys

Never share them with anyone, including the MetaMask team or anyone claiming to represent us. We will never ask you to provide your Secret Recovery Phrase. If someone claims that we do, insist on not sharing.

What is the vulnerability of MetaMask wallet? ›

Description and Overview. CVE-2022-32969: Insecure permissions vulnerability in MetaMask and other browser extension cryptocurrency wallets allows an attacker to access a user's secret recovery phrase on disk via remote or physical access.

Top Articles
7 Legal and Financial Steps to Closing Your Small Business
Airbnb Taxes|7 Deductions to Maximize your Profit
Parke County Chatter
DPhil Research - List of thesis titles
Enrique Espinosa Melendez Obituary
Myexperience Login Northwell
Sandrail Options and Accessories
From Algeria to Uzbekistan-These Are the Top Baby Names Around the World
Find All Subdomains
Gameplay Clarkston
World of White Sturgeon Caviar: Origins, Taste & Culinary Uses
Hair Love Salon Bradley Beach
6813472639
Truck Trader Pennsylvania
Trac Cbna
Milspec Mojo Bio
Welcome to GradeBook
Full Standard Operating Guideline Manual | Springfield, MO
Www.publicsurplus.com Motor Pool
Days Until Oct 8
eHerkenning (eID) | KPN Zakelijk
Walgreens 8 Mile Dequindre
Accuradio Unblocked
Catchvideo Chrome Extension
Farm Equipment Innovations
Usa Massage Reviews
Buhl Park Summer Concert Series 2023 Schedule
Pronóstico del tiempo de 10 días para San Josecito, Provincia de San José, Costa Rica - The Weather Channel | weather.com
Robotization Deviantart
Log in to your MyChart account
Our Leadership
R/Sandiego
Restaurants Near Calvary Cemetery
El agente nocturno, actores y personajes: quién es quién en la serie de Netflix The Night Agent | MAG | EL COMERCIO PERÚ
Ni Hao Kai Lan Rule 34
Goodwill Thrift Store & Donation Center Marietta Photos
The Bold And The Beautiful Recaps Soap Central
20+ Best Things To Do In Oceanside California
Giantess Feet Deviantart
Nearest Ups Office To Me
877-292-0545
Convenient Care Palmer Ma
Craigslist Odessa Midland Texas
Clausen's Car Wash
Weather In Allentown-Bethlehem-Easton Metropolitan Area 10 Days
Rocky Bfb Asset
Rush Copley Swim Lessons
Dyi Urban Dictionary
26 Best & Fun Things to Do in Saginaw (MI)
St Anthony Hospital Crown Point Visiting Hours
Greg Steube Height
Bumgarner Funeral Home Troy Nc Obituaries
Latest Posts
Article information

Author: Reed Wilderman

Last Updated:

Views: 5822

Rating: 4.1 / 5 (72 voted)

Reviews: 95% of readers found this page helpful

Author information

Name: Reed Wilderman

Birthday: 1992-06-14

Address: 998 Estell Village, Lake Oscarberg, SD 48713-6877

Phone: +21813267449721

Job: Technology Engineer

Hobby: Swimming, Do it yourself, Beekeeping, Lapidary, Cosplaying, Hiking, Graffiti

Introduction: My name is Reed Wilderman, I am a faithful, bright, lucky, adventurous, lively, rich, vast person who loves writing and wants to share my knowledge and understanding with you.