MetaMask discloses ongoing infrastructure security incident
Cryptocurrency wallet provider MetaMask has disclosed a security incident affecting part of its infrastructure. The company says the incident is still ongoing but that there is "no immediate threat to MetaMask wallets."
MetaMask made the announcement on Thursday. It said it is handling the incident internally, with support from external partners and security advisors. It has not said which systems were involved or what the attackers may have reached.
MetaMask is a non-custodial crypto wallet developed by Consensys, a blockchain software company. Non-custodial means that users hold their own keys, not the provider. The wallet lets people store and manage assets on Ethereum and on other blockchains compatible with it.
Validators taken offline as a precaution
The main visible step so far concerns MetaMask's staking business. In staking, users lock up cryptocurrency to help secure a blockchain and earn rewards in return.
"As a precautionary measure, we are proactively exiting affected validators within our non-custodial staking operations, in coordination with clients and partners," MetaMask said.
The company also noted that its staking operations are non-custodial and that it does not manage withdrawal keys for stake on behalf of its clients.
Validators are nodes on the Ethereum network. They run software that proposes new blocks, verifies transactions and helps keep the blockchain secure. Exiting a validator removes it from these duties. This process is slow and cannot be done instantly.
BleepingComputer asked MetaMask which part of its infrastructure was affected and whether any systems or data were accessed or compromised. A spokesperson pointed back to the company's public statement and gave no further answers.
Lido Finance confirms the exit process
More detail came from Lido Finance, a decentralized liquid staking platform. Lido said earlier the same day that MetaMask Staking, formerly known as Consensys Staking, had taken precautionary steps to protect client assets tied to Ethereum validators.
According to Lido, those steps include exiting MetaMask's ETH validators in the Lido protocol. This comes at a cost. Lido said the move will likely mean lost rewards. There may also be downtime penalties if validators are taken offline in the near future to reduce the risk of wider network penalties.
"Relevant validators have begun the exit process, with the final validators expected to be exited (but not fully withdrawn) by the end of October 7th, 2026," Lido Finance said.
The wording matters. Being exited and being fully withdrawn are two separate stages on Ethereum. That means the funds involved will not move right away once the exits are complete.
What is still unknown
Several key questions remain open:
- which part of MetaMask's infrastructure was affected
- whether attackers accessed any systems or data
- how the incident was discovered and when it started
- why the affected validators were judged to be at risk
Until MetaMask shares more, wallet users have only the company's statement that their wallets face no immediate threat.
Our Take
For everyday MetaMask users, the message so far is reassuring. The company says wallets are not at immediate risk, and its non-custodial design means it does not hold users' keys. The decision to pull validators offline, however, suggests MetaMask sees enough risk in its staking setup to accept lost rewards and possible penalties rather than wait.
That is a sensible trade-off, but the lack of detail is a problem. Crypto platforms remain a top target, as the recent Bitget hack showed, and vague "infrastructure" incidents often turn out to be more serious once full reports appear.
It is worth watching whether MetaMask explains what was accessed and how the attackers got in. Another point to follow is whether the validator exits finish on schedule by October 7. Staking clients should also keep an eye on any messages from Lido and MetaMask about penalties or delayed withdrawals.
