
MetaMask is responding to a security incident affecting part of its infrastructure and has begun exiting affected staking validators as a precaution.
The company says it has identified no immediate threat to MetaMask wallets.
MetaMask disclosed the incident in a September 30 announcement, saying its internal teams are working with external partners and security advisors to address and remediate the issue.
CyberInsider contacted MetaMask for additional details about the incident, but the company directed us to its published information without providing further answers.
MetaMask provides a self-custodial cryptocurrency wallet and services for interacting with blockchain applications. Its validator staking service lets users earn Ethereum staking rewards while MetaMask runs the underlying hardware and software on their behalf. Validators help verify transactions and propose new blocks on the Ethereum network.
MetaMask emphasized that its staking operations are non-custodial and that it does not manage clients’ withdrawal keys. Operating validator infrastructure therefore does not give the company custody of clients’ staked assets. However, that distinction does not eliminate the potential operational impact of the incident, including interruptions to staking rewards.
Lido outlines staking impact
A separate disclosure on Lido’s governance forum provided more detail on the response, describing an investigation into an infrastructure compromise involving MetaMask Staking, formerly Consensys Staking.
According to the disclosure, MetaMask is exiting Ethereum validators it operates within the Lido protocol to protect client assets. The relevant validators have already begun the exit process, with the final exits expected by the end of October 7, 2026. That deadline covers validators leaving active service, not completing the withdrawal process.
Lido warned that the precautionary measures will likely result in missed staking rewards. Validators could also incur downtime penalties if they are taken offline before completing their exits to reduce exposure to potential network penalties.
The affected ETH is expected to return to the protocol gradually as the validators complete the exit, withdrawal, and re-entry cycle. Lido estimates that this process could take approximately 45 days because of Ethereum’s extended validator entry queue. It stated that holders of stETH, its liquid staking token, need to take no action.
MetaMask’s announcement does not identify the affected infrastructure components, the cause of the incident, when it was discovered, or whether anyone accessed any information. It also does not specify how many validators or how much staked cryptocurrency is affected.
The company has promised further updates as appropriate. For now, its wallet security assessment remains limited to finding no immediate threat, while Lido’s guidance to stETH holders is to take no action.







Leave a Reply