MetaMask users are being targeted by a new scam that impersonates two-factor authentication (2FA) security verification, according to SlowMist's Chief Information Security Officer, 23pds (Shan Ge). The scam involves a fraudulent page with a domain name similar to MetaMask, which redirects users to a fake security alert and 2FA process. This page uses elements like countdowns and "authenticity verification" to appear credible, ultimately tricking users into entering their mnemonic phrases. This results in the theft of their assets. Users are reminded that mnemonic phrases should only be used for initial wallet import or recovery, and any website requesting them poses a high risk.