On June 22, a message mocking Jaredfromsubway.eth—a well-known MEV bot operator—appeared on X, seemingly sent from the ENS name 'MetaMask.eth'. The close resemblance to MetaMask’s official ENS domain sparked confusion. MetaMask’s official account quickly replied: 'FYI, we did not send this message. The message was sent from MetaMask.eth (capitalized version), which is owned by an unaffiliated third party. We own metamask.eth. It is unfortunate that both uncapitalized and capitalized versions of ENS names are able to be created, and most (if not all) platforms default to displaying an uncapitalized ENS name.'
This incident underscores a fundamental aspect of the Ethereum Name Service (ENS): different capitalizations of the same name are distinct NFTs. For example, 'MetaMask.eth' and 'metamask.eth' are separate tokens, each registrable by anyone. MetaMask holds the lowercase version, while a third party registered the capitalized one. As most wallets and social platforms display ENS names in lowercase by default, users cannot easily tell them apart, making it a vector for impersonation.
The vulnerability has been exploited before—attackers register 'capitalized' or 'mixed-case' versions of high-profile ENS names to forge official announcements, phishing links, or defamatory content. MetaMask’s case is a textbook example.
MetaMask urges users to verify the exact capitalization of ENS names before trusting communications. Tools like ENS domain resolvers can show the actual owner address. Official channels (MetaMask’s website, verified social media) should also be cross-checked. Platforms displaying ENS names could improve by flagging case variants or adding verification badges for official domains.
It remains unknown why the third party registered 'MetaMask.eth', but MetaMask has thoroughly disassociated itself. The community is calling for ENS or security bodies to implement protection for brand names, preventing similar spoofing events in the future.

