BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

MetaMask Reportedly Broadcasts ETH Addresses To Sites Visited By Users

- Advertisement -

The browser extension’s privacy mode is not enabled by default, something its lead developer says will be fixed sooner rather than later.

MetaMask, a browser extension that enables users to run Ethereum dApps, has been broadcasting individuals’ ETH addresses to websites and dApps visited by the user, according to a recently submitted GitHub issue outlining the extension’s default privacy settings. The apparent privacy concern allows third parties to see ETH addresses and potentially link a user’s “blockchain transactions to credit card payments, thereby [their] identity, and the identity of the last person [they] transacted with.”

In their GitHub post, the concerned user states that MetaMask’s privacy mode is not enabled by default, meaning the browser extension sends out “message broadcasts” about every 40 seconds. These broadcasts contain the client’s ETH address, which can then be relayed to any ads or trackers, such as Facebook and YouTube’s like button, and Twitter’s like and retweet buttons.

MetaMask unveiled its new privacy mode feature in November 2018. According to the announcement, MetaMask broadcasts users’ ETH addresses in order to let providers “propose Ethereum transactions, ask for your signature, query the blockchain,” and allow dApps to know your account balance. However, users can enable MetaMask’s privacy mode so that websites and dApps have to ask permission to see a user’s ETH address, which is supposed to help prevent malicious sites from collecting data to fingerprint, phish, or track unsuspecting users.

- Advertisement -

The GitHub poster says that enabling MetaMask’s privacy mode feature “doesn’t do very much at all” to prevent ETH addresses from being broadcast, and that the broadcasts themselves “serve no purpose.” Commenters were quick to point out that enabling privacy mode does indeed cause the message broadcast to be read as “undefined.” Further, MetaMask explained in its November 2018 announcement that privacy mode is not enabled by default because older dApps may not be compatible yet with the feature.

MetaMask’s lead developer, Dan Finlay, also found his way into the GitHub post’s comments, admitting that the browser extension’s team has been slow to enable the privacy mode feature by default. Finlay did assert that the switch would be coming sooner, rather than later, and that once the feature is enabled by default, users would still be able to manually turn it off.

The GitHub issue’s original poster continued to maintain that the browser extension has no technical reason to send out broadcast messages, calling the software team behind MetaMask “deceptive.” In response to the name-calling, Finlay stated: “We definitely reject all your claims that this is some weird malicious act on our part. That would be the craziest move we could ever make on a totally open source crypto project.”

Nicholas Ruggieri studied English with an emphasis in creative writing at the University of Nevada, Reno. When he’s not quoting Vines at anyone who’s willing to listen, you’ll find him listening to too many podcasts, reading too many books, and crocheting too many sweaters for his dogs, RT and Peterman.

Like what you read? Follow us on X @Bitnewsbot to receive the latest MetaMask, ETH address or other Ethereum dapps news.



Source: ETHNews

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Microsoft, Alphabet Surge on AI as OpenAI Stumbles

Google Cloud revenue surged 63% year-over-year to $20.03 billion in Q1 2026, with enterprise...

2 Major Hacks Among 68 Thefts Shake Crypto in 2026

Over $1.08 billion has been stolen in at least 68 crypto hacks so far...

Stable Sea Adds Tokenized Treasury Fund for Corporate Cash

Stable Sea integrated the WisdomTree Government Money Market Digital Fund (WTGXX) to help businesses...

Supply chain attack hits SAP npm packages with malware

A supply chain attack compromised four key SAP-related npm packages with credential-stealing malware on...

Sky Reports Record Q1 Revenue As Token Value Declines

Sky posted record Q1 2026 revenue of nearly $124 million, its highest since launching...

Must Read

Sushiswap vs Uniswap, What are the differences between these dex?

It's no secret that the world of decentralized exchanges has exploded in recent years. Many of you are probably wondering what the difference is...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading