
MetaMask now allows users to create, back up, and restore their wallets using their Google or Apple accounts combined with a unique password. Instead of manually managing a 12-word Secret Recovery Phrase (SRP) upfront, MetaMask generates the SRP securely and encrypts it locally on the user’s device. Access to the wallet is granted only when the user logs in through their social account and provides their password, which decrypts the SRP locally, ensuring MetaMask never has access to user keys.
Two-step Setup: Sign in with Google or Apple ID, then create a strong password.
Self-Custodial Security: No single party, including MetaMask or Google/Apple, can retrieve your recovery phrase without your credentials.
SRP Management: The Secret Recovery Phrase is generated and stored securely, accessible only by the authenticated user.
Dual Access Options: Users can still use traditional recovery phrases alongside social login for flexibility.
Cross-Device Sync: Enables seamless access and synchronization of wallets across devices while safeguarding keys.
The social login reduces entry barriers for newcomers who find recovery phrases intimidating, merging familiar Web2 login methods with Web3 security principles. It provides a faster, less error-prone path to wallet management, encouraging wider adoption of decentralized technologies.
MetaMask stresses the importance of creating and remembering a strong password for social login since losing it means wallet recovery is impossible without the original credentials. Users are encouraged to continue prudent security practices, including optional use of hardware wallets and secured backups.