metamaskio-auth.tem3[.]io
Category: Phishing And Fraud
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Quttera Web Malware Removal is a paid subscription service. Pricing, plans, and trial availability are set by Quttera. Quttera is operated by Quttera Ltd, an independent third-party company unrelated to RCS LT. PCRisk.com may earn a referral commission when users sign up through this link.
Description of metamaskio-auth.tem3[.]io
The domain metamaskio-auth.tem3[.]io appears to host a cryptocurrency-themed landing page that imitates the branding and messaging of MetaMask, a widely known Web3 wallet platform. The page title and visible content promote installing a browser extension wallet, and the screenshot shows MetaMask-style logos, navigation labels, and wallet interface imagery. At the same time, the page is served from a subdomain of tem3.io rather than an official MetaMask-owned domain, which is a notable mismatch.
Based on the screenshot and linked assets, the page also appears to be built using a third-party landing-page platform associated with Tem3/Teko infrastructure. The visible footer and header references suggest the operator may be using a generic site builder rather than an official product site. This combination of copied wallet branding, third-party hosting, and non-official domain naming is commonly associated with credential harvesting or deceptive crypto download pages.
Safety Assessment for metamaskio-auth.tem3[.]io
Multiple scan signals indicate elevated risk at the time of this scan. The domain was flagged by 18 out of 91 security engines, categorized by multiple web-classification providers as phishing/fraud, and listed in at least one major blacklist database for social-engineering activity. A malware scan also reported a malicious threat level and identified one flagged object, with an additional flagged external endpoint referenced by the page.
The domain name itself raises further concern. Although the page visually presents itself as MetaMask, it is hosted on metamaskio-auth.tem3[.]io rather than an official MetaMask domain. In addition, the domain closely resembles temu.com in structure and may be a look-alike, while the page content imitates a different well-known brand, MetaMask. That mismatch between domain identity and on-page branding is a common warning sign for deceptive campaigns.
The screenshot shows a polished crypto-wallet landing page, but the surrounding indicators do not support it as an authentic brand property. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid TLS certificate issued by a mainstream certificate authority and is fronted by Cloudflare infrastructure, with the server IP resolving to Cloudflare-hosted space in Canada. Nameservers also point to Cloudflare, suggesting CDN or reverse-proxy protection is in use. DNSSEC appears to be unsigned, which is not uncommon but does remove one layer of DNS integrity protection.
From a security perspective, the more important concerns are reputational and behavioral rather than transport encryption. The domain is not ranked in major popularity lists, reportedly lacks MX records, and references a flagged external ingestion endpoint. The page appears to be delivered through a landing-page builder on a subdomain rather than a dedicated official brand domain, which may be consistent with short-lived phishing infrastructure.
Share your experience with this website. Was it safe? Did you encounter any issues?