In 2026 MetaMask already supports more than a dozen networks by default, TRON and BNB Smart Chain among them — there is no need to add them by hand. The network you want is already on the list of supported ones, and that list is visible right on the add-network screen.
The real extension in the Chrome Web Store has the identifier nkbihfbeogaeaoehlefnkodbefgpgknn and the publisher Consensys Software Inc. — you can check both against metamask.io/download. The real extension's rating is low, 2.7 out of 5 as of 19.09.2026: fakes usually show 4.9–5.0 off the back of padded reviews, so “look at the rating” is harmful advice.
If you do have to add a network by hand, MetaMask warns you outright: it does not check the data you enter, and a rogue RPC address can show a balance that does not exist or hold your transfer back. How to check a network before adding it, and why on 19.09.2026 a TRON transfer has to be looked up in a network explorer rather than in the wallet, is below.
The rating and the reviews are the worst way to spot a fake
The familiar advice to “look at the rating and the reviews” leads you, on this particular store page, straight to a fake. As of 19.09.2026 the real MetaMask extension has 2.7 out of 5 from 5.9k ratings. Fakes are usually rated 4.9–5.0, and that is no coincidence: review padding is described outright in security reports as part of the scheme.
One thing settles it — the identifier in the store page address: on the real extension it never changes. The publisher Consensys Software Inc. on the listing is a secondary sign: a fake will write anything at all in that line, this one included. What gives you something to lean on is not the listing but a check against metamask.io/download.
The check takes two steps. First open metamask.io/download — type the address by hand or take it from your bookmarks, rather than the first link in a search. The site itself has lookalikes too, and on a lookalike you will be checking one fake against another and putting your mind at rest.
Then look at where the install button leads: on 19.09.2026 it led to a Chrome store page with the identifier nkbihfbeogaeaoehlefnkodbefgpgknn and to the Firefox add-ons page. That is the identifier to check against the address of the page you are standing on.
What on the store listing stays put and what changes
This is an important dividing line: half the fields on the listing live a life of their own, and there is no point checking against them. The values were taken from the store page on 19.09.2026.
listing field | value on 19.09.2026 | does it change |
|---|---|---|
identifier in the page address |
| no |
publisher | Consensys Software Inc. | no |
rating | 2.7 out of 5 from 5.9k ratings | yes |
number of users | 12,000,000 | yes |
version and update date | 13.48.0 of 14.09.2026 | yes |
Further signs of a fake are named by MetaMask itself: typos, grammatical mistakes, outdated or sloppy images and logos, a badly put-together page in general. In the same place the vendor puts it bluntly: download the extension from nowhere except the button on metamask.io/download and the official browser extension stores.
Three fake campaigns: two from reports, one from news coverage
Wallet fakes are not a hypothesis but a phenomenon documented on a regular basis. The three campaigns below share one trick, and it matters more than the numbers.
“Superior”, a report by the firm Socket, August 2026. 19 extensions: 18 in Chrome, one in Edge. The largest picked up around 80,000 installs. The attacker created 14 of the extensions himself and bought another 5 from their previous owners, and the activity can be traced back to February 2024.
MetaMask is named outright among that campaign's targets. Researchers counted 16 modules in the code: wallet drainers, credential theft and phishing pages dressed up as Ledger and Trezor.
“GreedyBear”, a Koi Security report, August 2025. More than 150 malicious Firefox extensions, around 500 executables, more than $1 million stolen in five weeks. The fakes went out under the names MetaMask, TronLink, Exodus and Rabby Wallet. Researchers called the trick “extension hollowing”: first you assemble a portfolio of harmless extensions, and only then do you arm them.
2020, 49 Chrome extensions. According to reports from researchers, 49 extensions posing as wallets were pulled from the store at the time. The primary source would not open on 19.09.2026, so we give this as a report rather than a verified fact.
A caveat about the numbers for the first two campaigns: the direct pages of both reports would not open on 19.09.2026 either — one domain has moved, the other page returns an error. The numbers are taken from write-ups in trade publications, which agree with one another but are not the primary source.
The trick all three share: the extension gets into the store clean, builds up an audience and reviews, and is then updated to a malicious version automatically — by default the browser updates extensions by itself. Hence a conclusion that is rarely spelled out: “I installed it ages ago and everything was fine” protects you from nothing.
In practice two things follow from this. Keep only the extensions in your browser that you actually use, and do not hold sums in a browser wallet whose loss you would feel. These signs do not guarantee the outcome — they cut down the number of situations in which you sign blind.
Which networks are already built in, and when adding one by hand is unnecessary
The list of networks MetaMask supports by default as of 19.09.2026: Ethereum, Bitcoin, Linea, Base, Solana, Tron, Polygon, BNB Chain, Arbitrum, Monad, Robinhood Chain, OP, Sei, Avalanche, zkSync Era, MegaETH, HyperEVM, Arc, Tempo. The list was taken from the add-network screen the same day, and it keeps growing.
The practical conclusion: in 2026 an ordinary person has no need to add a network by hand at all. Both TRON and BNB Chain are already on the list. If a site offers to “add a network so you can see your coins”, that is almost certainly a scam — you cannot have coins of your own in a network that does not exist.
TRON in MetaMask: what works and what does not, as of 19.09.2026
TRON has been supported out of the box since 15.01.2026 — that is how the vendor described it in the announcement. Receiving and sending work, and the address for that network is created inside a multi-network account by itself.
Connecting to TRON apps did not work on 19.09.2026. The vendor's help page that day answered the question about dapp support word for word: “Not currently. Dapp connectivity will be available on Mobile and Extension soon.” A promise of “soon” is neither a fact nor a date, so check the status on the day you are reading.
There is a direct consequence for checking a transfer. The status, the number of confirmations and the resources spent are shown by a network explorer — for TRON that is Tronscan — and you search there by the transaction hash, not by the address. The wallet gives you the hash after you send, in the TxID or Transaction ID field.
Three more TRON quirks that show up in the wallet itself, all as of 19.09.2026:
- TRX staking is only available in the mobile app. The extension cannot stake, but it can use resources obtained by staking in the app.
- The network does not hand out free energy. The only thing granted free is bandwidth, and only to accounts that hold TRX — about 600 units a day. What you spend is restored over 24 hours, and it is credited linearly, from the moment it was spent, rather than all at once at the end.
- Sending USDT does not activate a new account. TRX has to arrive at the address first — the vendor's help page says so in plain words.
How to add a network by hand and what to look at
If you do end up adding a network manually, the form asks for five fields. Only two of them merely set labels on the screen — Network Name and Currency Symbol. The other three are what decide things: RPC URL, Chain ID and Block Explorer URL.
form field | what it actually is |
|---|---|
Network Name | the network's label in the interface, nothing more |
Network URL (RPC) | the address of the node through which the wallet sees the blockchain and sends transactions. The wallet has no copy of the blockchain of its own: whoever runs that server decides what you see |
Chain ID | a number mixed into the transaction signature that stops it being replayed in another network. Ethereum is 1, BNB Smart Chain is 56 (a direct query to the nodes on 19.09.2026) |
Currency Symbol | the label under the figure on the screen. Nothing checks it: BNB can be labelled “ETH” |
Block Explorer URL | where the “view transaction” button leads. This is exactly where Tronscan, Etherscan and BscScan get plugged in |
A separate word about the explorer address. The field is optional, but filled in it works: an address put there sends the “view transaction” button to a fake explorer. Explorer lookalikes sit in search results next to the real thing and call themselves official — and checking a transfer with that button means checking yourself against the very people who gave you the network.
Next, three warnings from MetaMask itself. First: the vendor does not verify custom networks, and even when its own checks have been passed, a network may turn out to be malicious or wrongly described by the site that offered it. Checking the network is the job of whoever adds it, exactly like checking the wallet address before you send.
Second: the vendor does not maintain third-party network directories and takes no responsibility for what is in them — Chainlist gets a line of its own on that. Third: a rogue node can lie about the state of the blockchain, hold a transaction back and record your network activity and IP address.
Lying about the state means showing a balance that is not there. A person sees “USDT credited” while nothing at all has happened in the network. There is exactly one way to check: open that same address in an explorer whose address you typed by hand. A wallet can be fooled through a substituted node; a public explorer on its own domain cannot.
A separate scenario the vendor describes outright: a rogue network is there to slip you a counterfeit token. It works through a different RPC endpoint and is therefore a different token with no real value, even though it goes by the same name.
And a technical detail that is easy to miss: replacing the default RPC address in Ethereum, Linea, Base, Arbitrum or BNB Smart Chain switches off the built-in mechanisms, MEV protection among them. So even an honest node belonging to someone else deprives you of what was switched on by default.
What MetaMask never asks for
This list consists entirely of the vendor's own wording — and in practical terms it is the most useful part of the subject.
- The wallet never asks for your recovery phrase — not to check anything, not “for an update”: the vendor writes that there is no need to enter it regularly. You enter it yourself when you are restoring a wallet on a new device. How to store it is covered separately: recovery phrase.
- Support never writes first — not in direct messages, not by email.
- Support has no phone number, and nobody there will speak to you by voice.
- Support is not on messengers: groups and channels on WhatsApp, Telegram, Discord and the like that offer help are a scam.
- The extension window does not open by itself. It appears in response to something you did. If it popped up on its own and is asking for 12 words, it is a fake or a malicious extension sitting on top of the real one.
The same rule works on the explorer side: neither Tronscan nor Etherscan nor BscScan needs your private key, recovery phrase or password to show you a transaction. A site that looks like an explorer and asks you to enter 12 or 24 words is not an explorer.
A word about our own interest: we are an exchanger, not a wallet and not a vault. We issue an address for a one-off deposit, there is no need to keep funds on it, so checking the network and the extension is your side of the deal, not ours. If the next step is an exchange, we have a separate direction for USDT on the TRON network with the transfer network stated explicitly.
Short answers
How do I check that a MetaMask extension is the real one?
What settles it is the identifier in the store page address: it has to be nkbihfbeogaeaoehlefnkodbefgpgknn. The publisher Consensys Software Inc. is a secondary sign — a fake will write anything at all in that line of the listing. What you compare it against is where the install button leads on metamask.io/download, typed by hand. The rest of the fields on the listing change.
Is a high rating in the store a sign that it is genuine?
No. The rating is not a sign at all — neither a high one nor a low one. As of 19.09.2026 the real extension has 2.7 out of 5, the fakes usually 4.9–5.0: reviews get padded, and security reports describe this as part of the scheme. Tomorrow the numbers will be different, which is why people check the identifier rather than the scores.
Do I need to add the TRON or BNB Chain network by hand?
No. As of 19.09.2026 both networks are built into MetaMask by default and appear in the list of supported ones on the add-network screen. An offer on a third-party site to “add a network so you can see your coins” is almost always a scam, and a network added by hand is not checked by the vendor.
Can I check a TRON transfer right inside MetaMask?
The transfer's details — status, confirmations, resources spent — are shown by a network explorer, not by the wallet. On top of that, connecting to TRON apps did not work in MetaMask on 19.09.2026, and the vendor promised it “soon”, with no date. Look up the transfer by the hash the wallet gave you after sending.



