The story is always told the same way. Someone closes their MacBook at night, the wallet balance is fine, and in the morning it’s gone. The transactions went out at 3 a.m. while the laptop was asleep. It feels impossible, because the Mac was off.

It isn’t impossible, and understanding why is the most useful thing you can learn about keeping a hot wallet on a Mac. The Mac being asleep doesn’t protect you, because the attacker was never using your Mac to take the money.

Why sleep doesn’t matter

A browser wallet like MetaMask stores your keys in an encrypted vault on your disk, unlocked by your wallet password. A thief needs two things: a copy of that vault, and the password, or the recovery phrase that recreates everything.

Once they have those, they don’t need your Mac at all. They open the wallet on their own computer and sign the transactions there. The drain can happen minutes after the theft or weeks later, often at night in your timezone, because nobody is watching.

So the real moment of loss was earlier: when something copied your vault and captured your password, or when you typed your recovery phrase somewhere you shouldn’t have.

How they get the vault and the password

  • Stealers. MacSync and similar malware copy browser wallet extension data, saved browser passwords, your keychain file and your Mac password, which they ask for directly with a fake prompt. If your wallet password is the same as, or similar to, any of those, the vault opens.
  • Trojanized wallet extensions. Security researchers documented a campaign aimed at crypto and Web3 developers that modified the MetaMask extension to send the wallet password and encrypted vault straight to the attacker. MacSync’s backdoor has a command for installing browser extensions, too.
  • Lookalike extensions and sites. Fake MetaMask extensions and download pages, promoted with search ads or fake reviews, work like the real thing until you’ve funded them.
  • Phishing for the phrase. Emails and pages impersonating MetaMask with a “mandatory 2026 upgrade” or fake two-factor setup drained hundreds of wallets this year. They end with a request for your recovery phrase.
  • Approvals you already signed. A malicious site can get you to approve unlimited spending of a token. Nothing happens until the attacker uses that approval, which can be any time later, while your Mac sleeps.

What macOS does and doesn’t protect

  • Gatekeeper and notarization stop many malicious apps, but not ones you approve by entering your password, and not commands you paste into Terminal.
  • FileVault protects your data if the Mac is stolen and switched off. It does nothing against malware running while you’re logged in.
  • Privacy permissions limit what apps can read, but a browser extension runs inside your browser and already has access to the wallet.

In other words: on a Mac, as on any computer, a hot wallet is exactly as safe as everything else running on that computer and in that browser.

A threat model that works

  • Split your money. Keep only spending money in a hot wallet. Savings belong on a hardware wallet, where every transaction has to be confirmed on the device’s own screen.
  • Give the wallet its own browser profile, or better, its own macOS user account. Install the wallet extension and nothing else there, and use it only for crypto.
  • Use a unique wallet password that isn’t your Mac password, isn’t saved in the browser, and isn’t reused anywhere.
  • Lock the wallet automatically after a few minutes in its settings.
  • Review and revoke token approvals regularly with a trusted approval checker, especially unlimited ones.
  • Install wallet extensions only from the link on the wallet’s official site, and check the publisher in the extension store.
  • Treat any request for your recovery phrase as an attack. MetaMask, Ledger and Trezor never ask for it by email, in a pop-up or in a browser tab.
  • Keep macOS and your browser updated. This week that means 27.0.1, 26.7.1 or 15.8.1.

If it already happened

  1. From a different, clean device, create a new wallet with a new recovery phrase, and move anything left in the old wallet and any wallet that shared its phrase or password.
  2. Revoke outstanding token approvals from the old address.
  3. Check the Mac for the signs in our MacSync guide. If you find any, erase it and reinstall macOS before using it for crypto again.
  4. Change passwords for email, exchanges and your Apple Account from the clean device.
  5. Be wary of anyone offering to recover the funds for a fee. Recovery scams target people right after a loss.

The short version

A hot wallet drained while your MacBook slept wasn’t drained through the Mac. Something earlier copied your wallet vault and password, or you entered your recovery phrase somewhere, and the thief signed the transactions on their own machine. Keep only small amounts in a hot wallet, isolate it in its own browser profile or user account, use a unique password, revoke approvals, and keep savings on a hardware wallet.