Public-evidence reviewsSeven beginner guides reviewedRead the safety note
plainblockclear questions before crypto decisions
Beginner wallet review

MetaMask

A recovery-first MetaMask guide covering self-custody, social recovery, swap cost, telemetry and the limits of visible source code.

Editorial statusPublished review
Public evidenceReviewed
Hands-on checksPublished
ComparisonSame-category only
Reviewed
Confidencemedium
What this page covers:

Public evidence refreshed on 16 August 2026. Wallet setup, recovery, signature and asset-transfer scenarios are specified as fixed protocol runs.

Our view

Editorial verdict

MetaMask gives users key control and broad dapp access, but beginners should not translate ‘self-custody’ into ‘no server, no data collection or no service fee’. Recovery choice is the first safety decision.

Who it may suit

Best for

People ready to protect recovery material, review every signature and choose privacy and recovery settings consciously.

The big decision

Main trade-off

Flexible access to dapps and recovery options can improve convenience while increasing what the user must understand and protect.

Before you sign

Five questions about keys, recovery, cost and software.

Answers come from public records. Where real use is needed, the page specifies the scenario as a fixed protocol run.

1

Who can sign?

MetaMask is self-custodial: the user controls signing credentials.

Why it matters: No support agent can safely ask for the recovery phrase.
answered from public evidence
2

Which recovery path did you choose?

A Secret Recovery Phrase and Google/Apple/Telegram recovery use different designs, including encrypted online shards for the latter.

Why it matters: Account compromise and phrase loss create different failure risks.
answered from public evidence
3

Are MetaMask swaps free?

No. The guide reviewed states a 0.875% MetaMask fee plus network and route-dependent costs.

Why it matters: Gasless does not mean costless.
answered from public evidence
4

Does self-custody mean no data leaves the device?

No. MetaMetrics and security simulation can involve addresses, transaction hashes or service requests depending on settings and actions.

Why it matters: Key control and data privacy are separate questions.
answered from public evidence
5

Is everything fully open source and audited?

Public repositories and scoped assessments exist, but current licences are restrictive and coverage is limited.

Why it matters: A visible repository does not prove every distributed component.
answered from public evidence
See how we check this category
Evidence-backed

Strengths

  • Clear self-custody and recovery guides
  • Public repositories and security assessments
  • Visible MetaMetrics controls
Keep in view

Limitations

  • Social recovery has online service dependencies
  • Swaps add a 0.875% MetaMask fee plus route costs
  • Public code does not prove every binary and service is permissively open source or fully audited
Plain-language analysis

The important decisions, without the jargon.

Each section keeps its primary sources close by. A company statement is not upgraded into a guarantee.

1

1. Write down the recovery method on day one

Traditional MetaMask recovery uses a Secret Recovery Phrase that can restore all associated accounts. Newer social sign-in options use encrypted online shards. A beginner needs to know which path they selected before a device is lost or an online account is compromised.

Sources: MetaMask Support · MetaMask Support
Reviewed
2

2. Self-custody still involves services

The user remains the signer, but swaps, telemetry and security simulation can communicate with MetaMask or other providers. This does not remove self-custody; it means ‘who signs’ and ‘which data or routing service is used’ are different questions.

Sources: MetaMask Support · MetaMask Support
Reviewed
3

3. Count the service fee and the route

The Swaps guide re-retrieved on 16 August 2026 states a 0.875% MetaMask fee. Network cost, route pricing and price impact can add more. When a flow says gasless, compare the final amount rather than assuming the whole transaction is free.

Sources: MetaMask Support
Reviewed
4

4. Privacy settings deserve a real decision

MetaMetrics can collect product events, and selected events may be associated with a wallet address or transaction hash. Security simulation can send requests to MetaMask or Blockaid. Review settings before connecting a valuable wallet.

Sources: MetaMask Support · MetaMask
Reviewed
5

5. Source code and audits have edges

The extension and mobile repositories can be inspected, but their current licences are not universally permissive. Security reports cover named scopes and versions rather than every feature forever. Download only from a verified channel and keep the app updated.

Sources: GitHub / MetaMask · GitHub / MetaMask · MetaMask
Reviewed
Deep decision guide

Ten decisions, each tied to a common mistake and a safer next step.

Public sources were retrieved on . Any step needing a real account, funds, signing or support is specified as a fixed protocol run.

May suit

You need EVM dapps and will read every signature.

MetaMask is a widely documented self-custody signing tool.

May suit

You can protect recovery material and consider hardware-backed keys.

The user keeps authority rather than a support desk.

Probably not

You need a provider to undo mistakes or restore a lost SRP.

Self-custody cannot do that.

Probably not

You assume self-custody means anonymous and service-free.

Telemetry, RPC, swaps and security services can participate.

1

1. Which app and version?

Extension and mobile are separate builds.

Common mistake
Downloading from a link in a message.
Who is responsible
You verify the official channel; MetaMask publishes releases.
Safer next step
Record store/publisher/version before creating a wallet.

Sources: GitHub / MetaMask · GitHub / MetaMask

2

2. Who can sign?

You control the wallet credentials and approve actions.

Common mistake
Thinking self-custody means no service ever sees data.
Who is responsible
You own signing decisions; providers/RPCs handle enabled services.
Safer next step
Map authority and data paths separately.

Sources: MetaMask Support · MetaMask Support

3

3. Which recovery route?

Traditional SRP and login/key-share options have different failure paths.

Common mistake
Following one recovery guide for another setup.
Who is responsible
You protect factors; MetaMask explains but cannot safely receive your SRP.
Safer next step
Write down the chosen recovery architecture.

Sources: MetaMask Support · MetaMask Support

4

4. What are you really signing?

Connection, token approval, permit and transfer grant different authority.

Common mistake
Clicking confirm because the dapp name looks familiar.
Who is responsible
You authorise; dapp/wallet must present fields clearly.
Safer next step
Check spender, amount, chain and consequences; use hardware display where possible.

Sources: MetaMask

5

5. Does public code prove the installed app?

No; repository, licence, release and binary are separate evidence.

Common mistake
Assuming GitHub visibility guarantees store-binary identity.
Who is responsible
MetaMask publishes code/releases; you verify channel/version.
Safer next step
Match installed build to official release evidence.

Sources: GitHub / MetaMask · GitHub / MetaMask · MetaMask

6

6. What does a swap cost?

Provider fee, route economics and network gas can all apply.

Common mistake
Calling a gasless flow free.
Who is responsible
MetaMask shows the quote; you compare final received amount.
Safer next step
Save route, fee, price impact, minimum and gas.

Sources: MetaMask Support

7

7. Who is involved in buy/bridge routes?

Integrated third parties and networks may add terms, fees and remedy limits.

Common mistake
Thinking every built-in button is provided solely by MetaMask.
Who is responsible
Each provider handles its step; you verify parties.
Safer next step
Open provider/terms before authorising.

Sources: MetaMask Support · MetaMask Support

8

8. How do you remove permissions?

Disconnecting a site may not revoke onchain token approval.

Common mistake
Closing the tab and assuming authority ended.
Who is responsible
You revoke approvals; contracts enforce remaining authority.
Safer next step
Check and revoke onchain permissions after use.

Sources: MetaMask

9

9. What data leaves the device?

Depending on settings, metrics/RPC/simulation can process usage, addresses or hashes.

Common mistake
Treating self-custody as automatic anonymity.
Who is responsible
Providers process enabled features; you choose available settings.
Safer next step
Compare network flows with MetaMetrics on/off.

Sources: MetaMask Support · MetaMask

10

10. What can support do?

It can help with software but cannot reverse chain actions or safely ask for an SRP.

Common mistake
Giving secrets to a convincing ‘agent’.
Who is responsible
You protect secrets; official support states the boundary.
Safer next step
Use only official channels and never send the phrase.

Sources: MetaMask Support · Consensys

Safe decision journeys

Fixed checklists and defined records.

J1

First wallet

Starting point: Disposable extension wallet.

  1. Verify build.
  2. Choose recovery mode.
  3. Store recovery safely.
  4. Record privacy settings.

Evidence still needed: Fresh-device recovery result.

Published
J2

Dapp approval

Starting point: Controlled test token/contract.

  1. Connect.
  2. Read approval/permit.
  3. Reject/approve controlled case.
  4. Revoke onchain.

Evidence still needed: Prompt comprehension.

Published
J3

Swap

Starting point: Same chain/pair/amount/block.

  1. Save MetaMask quote.
  2. Save direct route quote.
  3. Record fee/gas/minimum.
  4. Compare final.

Evidence still needed: Executable cost output.

Published
J4

Lost-device/support

Starting point: No-value wallet.

  1. Use official recovery.
  2. Confirm no SRP request.
  3. Open benign software case.
  4. Record escalation.

Evidence still needed: Recovery/support output.

Published
What changed

Timeline for beginners.

  1. Support-ticket data incident.

    Private keys can stay safe while support data still helps scammers.

  2. Current extension release visible during review.

    Version checking is part of wallet safety.

  3. Recovery, fee, telemetry and code sources rechecked.

    Real signing/recovery tests are specified as fixed protocol runs.

Alternatives

Change product when the responsibility changes.

Trust Wallet

You need broader multi-chain coverage.

Hardware wallet with narrow companion

Key isolation matters more than seamless browser access.

Confidence and change gate

Medium evidence confidence.

What we know
Official recovery, swap and telemetry guides plus repositories explain the model.
What we do not know
Current prompt quality, recovery UX, runtime data and route cost.
What would change our view
Recovery/default telemetry/signature changes or material security results.
Method

How the guide stays honest.

  1. Fix build/recovery mode.
  2. Use disposable wallets.
  3. Follow authority and data separately.
  4. Reconcile onchain receipts.
Change log

What changed in this guide.

Added ten beginner signing/recovery responsibilities and four safe journeys.

FAQ

Short answers before you act.

Can MetaMask recover my SRP?

No.

Does hardware stop phishing?

No.

Are swaps free?

No.

Is self-custody anonymous?

Not automatically.

S

Primary-source list

Reviewed on 16 August 2026 by Plainblock Review Editorial Team; independent review by Plainblock Review Review Team.

  1. Recovery phrase, password and keys guideMetaMask Support · retrieved 16 August 2026
  2. Self-custodial wallet guideMetaMask Support · retrieved 16 August 2026
  3. Swaps user guideMetaMask Support · retrieved 16 August 2026
  4. MetaMetrics settingsMetaMask Support · retrieved 16 August 2026
  5. Browser extension repositoryGitHub / MetaMask · retrieved 16 August 2026
  6. Mobile repositoryGitHub / MetaMask · retrieved 16 August 2026
  7. Security programmeMetaMask · retrieved 16 August 2026
  8. Support data incident FAQConsensys · retrieved 16 August 2026