Consensys MetaMask privacy policy: four myths vs facts
Consensys updated its MetaMask Privacy Notice on September 30, 2026, revealing that social login users cannot opt out of basic functionality data collection. While private keys remain local, a security incident involving 17,000 validators and IP exposure via NFT images pose risks.
The Infura connection
Consensys Software Inc. revised the MetaMask Privacy Notice on September 30, 2026. While the company claims it does not sell personal information, Infura, the blockchain infrastructure provider owned by Consensys, collects the IP addresses and Ethereum wallet addresses of users who use the default remote procedure call settings. These users rely on Infura to connect to the blockchain. I find the Infura connection deceptive for privacy-conscious users who assume non-custodial status guarantees anonymity. Infura provides a free tier with 3 million credits per day and 5 requests per second, or a $50 per month plan that provides 15 million credits per day. You can change your RPC provider to a custom endpoint from a third-party provider to avoid this. QuickNode, for instance, provides 10 million credits per month with 15 requests per second, while Alchemy offers 30 million credits per month with 25 requests per second. Ankr provides 200 million API credits per month with approximately 30 requests per second. Chainstack provides 3 million RU per month with 25 requests per second. Infura’s architecture distributes requests across multiple underlying providers, adding another layer of redundancy.
The social login trap
Users often believe they can opt out of all data collection through the privacy settings. While Secret Recovery Phrase users can toggle "Basic Functionality" to limit data, social login users who use Google, Apple, or Telegram accounts cannot disable these settings. The "Basic Functionality" includes several features like token and NFT detection, transaction simulations, phishing detection, and network details checks. It also handles proposed nicknames, smart contract decoding, and account balance batch requests. The setting also manages ENS domains in the address bar to resolve names and check for IPFS content. I call this the "social login trap" because it forces data sharing for those seeking easier onboarding. The company also processes non-sensitive user events through MetaMetrics using Segment and Mixpanel to help improve the software for MetaMask users. If you onboarded to MetaMask using the Secret Recovery Phrase method, you can disable or opt-out of these settings at any time in the privacy menu, but social login users through Google, Apple, or Telegram are stuck with mandatory data sharing.
| User Type | Basic Functionality Toggle | Analytics (MetaMetrics) |
|---|---|---|
| Secret Recovery Phrase | Available | Opt-in / Opt-out |
| Social Login (Google/Apple/Telegram) | Always enabled | Opt-in / Opt-out |
Security realities
The claim that MetaMask collects private keys is false. The company maintains that private keys and Secret Recovery Phrases stay on your device. However, the September 30, 2026, security incident involving 17,000 validators shows that even non-custodial operations face risks. This incident specifically affected the infrastructure used for Ethereum staking validators rather than ordinary wallets. MetaMask is exiting affected validators to mitigate the impact after Lido confirmed that MetaMask Staking began exiting the affected Ethereum validators. The last affected validators are expected to exit by October 7, 2026, though the full withdrawal cycle could take up to 45 days. Additionally, cryptographer Alexandru Lupascu found a vulnerability where the mobile app fetches NFT images from remote servers, which exposes the user’s IP address to the server owner. A malicious actor can mint an NFT with a URL pointing to a private server and transfer it to an Ethereum address. When the mobile app fetches the image, the server receives the user’s IP, which allows for targeted attacks based on blockchain addresses alone. The investigation into the validator infrastructure remains active, and users should expect opportunistic phishing campaigns claiming that a wallet must be verified by entering a Secret Recovery Phrase. Will Consensys ever resolve the mobile IP vulnerability permanently?
Join the discussion