TL;DR
- MetaMask, Phantom, and other major wallets launch a real-time phishing defense network with the Security Alliance (SEAL).
- The move follows over $400 million in crypto phishing losses in the first half of 2025.
- SEAL calls it a "decentralized immune system for crypto security," open for anyone to report or stop active scams.
- WalletConnect's new integration will warn users of known scam sites, expanding cross-platform protection.
- The initiative marks a shift toward collective, proactive wallet security in Web3.
For years, crypto users have faced a silent but deadly threat-phishing drainers. They've drained hundreds of millions by tricking users into signing malicious transactions that look safe on the surface. Now, some of the industry's biggest wallet providers are coming together to stop it.
MetaMask, Phantom, WalletConnect, and Backpack have teamed up with the Security Alliance (SEAL) to create a real-time phishing defense network-an open system where anyone can help identify and shut down scams before they spread. In a statement shared Wednesday, the MetaMask team said:

The timing couldn't be more urgent. According to SEAL, crypto phishers stole over $400 million in the first half of 2025 alone, using increasingly advanced tactics to outsmart traditional security tools.
Inside the "Decentralized Immune System"
SEAL describes the new system as a "decentralized immune system for crypto security," where anyone-from wallet developers to everyday users-can contribute verified phishing reports.
The backbone of the system is SEAL's verifiable phishing report tool, released last week. It lets researchers cryptographically prove that a website actually contains phishing content, preventing false flags and boosting community trust.
Together, the initiative forms a living defense grid-constantly scanning, verifying, and sharing threat data across wallets and dApps in real time.
Crypto Drainers: A Game of Cat and Mouse
Phishing in crypto has evolved beyond fake websites or DM scams. The real danger now lies in drainer scripts, which can empty wallets within seconds once a user interacts with a malicious link.
SEAL's report highlights how these drainers constantly adapt:
- Rotating landing pages to dodge updated blocklists.
- Offshore hosting to stay out of reach of regulators.
- Cloaking tactics to fool automated scanners.
MetaMask security researcher Ohm Shah likened the situation to a never-ending chase:
WalletConnect's Layer of Protection
WalletConnect, one of the most widely integrated crypto connection protocols, is also upgrading its security stack as part of the initiative. Its new WalletConnect Certified system now alerts users when they try to access a known phishing domain. With the SEAL partnership, these warnings will get even smarter.
Derek Rein, CTO of WalletConnect, explained:
A Shift Toward Collective Security

For years, crypto wallet security has been siloed-each company defending its own users, each blocklist fighting the same battle separately.
This initiative changes that model. The phishing defense network operates as an open, shared layer of intelligence, letting wallet providers sync data and respond faster. The move mirrors traditional cybersecurity alliances seen in Web2, where data-sharing frameworks helped turn isolated defenses into global warning systems.
In the words of SEAL's announcement, the network aims to become "a collaborative security protocol that learns and evolves as threats change."
Why It Matters
The $400 million figure highlights a bigger truth: phishing is the new frontier of crypto crime. Unlike protocol exploits that rely on smart contract bugs, phishing attacks target human behavior-and that makes them harder to fix with code alone.
As Web3 adoption grows, wallet providers now face the challenge of balancing usability with safety. The SEAL partnership could be a first step toward industry-wide security standards-where wallets work together instead of in silos. And for users, the impact will be simple but powerful: fewer scams, faster warnings, and a greater sense of safety in everyday transactions.
The Road Ahead
The decentralized phishing network is still in its early phase, but SEAL plans to expand participation beyond wallets to DeFi protocols, exchanges, and blockchain explorers. The long-term goal is to make verified phishing data openly accessible, creating a transparent, community-driven layer of protection that evolves as threats do.
If successful, it could become a model for how crypto handles shared risk-through open collaboration instead of closed competition. For now, wallet developers like MetaMask and Phantom hope the project sends a message to scammers: the ecosystem is finally uniting against them.