MetaMask Confirms Security Incident Affecting Part Of Its Infrastructure, No Immediate Threat To Wallets Identified
In Brief
MetaMask confirms a security incident affecting part of its infrastructure and is proactively exiting affected validators from Lido, with no immediate threat to wallets identified.

MetaMask has confirmed it is responding to a security incident affecting part of its infrastructure, stating that no immediate threat to MetaMask wallets has been identified at this time. The company disclosed the situation in a public security update, noting that the response is being conducted in coordination with clients, external partners, and security advisers.
The original announcement read: “We are responding to a security incident affecting part of our infrastructure. At this time, we have identified no immediate threat to MetaMask wallets. As a precaution, we are proactively exiting affected validators within our non-custodial staking operations, in coordination with clients, partners and security advisors. We’ll share further updates as appropriate.”
As a precautionary measure, MetaMask is exiting affected validators involved in its non-custodial staking operations. The company emphasized that its staking services are non-custodial in nature and that MetaMask does not manage withdrawal keys on behalf of clients.
According to on-chain reports, the timeline of events began at approximately 10:27, when a freshly created externally owned account funded through a 0.1 ETH withdrawal via Tornado Cash received the funds. Validator exits associated with MetaMask and Consensys began around 11:00. Between 12:12 and 16:46, the address collected block rewards totaling roughly 0.36 ETH from 18 blocks proposed by MetaMask-run validators — a group consisting of 11 Consensys-operated Lido validators, five client validators, and two validators linked to EthFoxVault. At 12:42, Consensys removed 400 unused Lido keys, and after 16:46 rewards reportedly returned to their correct recipients. Separately, lending protocol Aave was reportedly preparing to freeze its V3 markets as a contingency, though it ultimately did not proceed.
Lido Exit Process Underway, Community Speculation Persists
Lido confirmed that MetaMask Staking — formerly Consensys Staking — has begun exiting its Ethereum validators from the protocol as a precaution following an infrastructure compromise. The exit process has started, with the final validators expected to have exited, though not yet fully withdrawn, by October 7, 2026. Lido noted that the move will likely result in foregone rewards and possible downtime penalties if validators are taken offline to reduce risks related to network penalties.
No action is required from stETH holders. ETH withdrawn from MetaMask-operated validators is expected to return to the protocol gradually as validators complete the exit, withdrawal, and re-entry cycle — a process estimated to take up to 45 days due to extended entry queue times. Lido also pointed to the protocol’s diversified node operator set and its reserve fund of more than 6,750 stETH as safeguards designed to contain and mitigate disruptions.
The limited details disclosed so far have fueled speculation within the crypto community. A podcaster known as Andy suggested — without providing evidence — that the incident could be more severe than publicly known, claiming that a small percentage of the Ethereum supply might be effectively locked on-chain through a single liquid staking provider. Community member Nick O’Neil similarly hypothesized that MetaMask may have disclosed the incident preemptively, though he offered no proof of this either.
Former MetaMask employee and security specialist Taylor Monahan pushed back against such interpretations, describing the company’s actions as a standard incident response sequence: detecting suspicious activity, remediating the potential threat, and proactively rotating affected infrastructure. She argued that organizations that detect, disclose, and mitigate threats should be viewed as less risky than those unaware of compromises affecting their systems.
In a development that added to community discussion, on-chain analysts observed that a wallet linked to Ethereum co-founder and Consensys CEO Joseph Lubin transferred 133,298 ETH — valued at roughly $356.2 million — to a new address several hours before the incident was made public.
However, there is no confirmed connection between this transfer and the MetaMask security incident. Notably, Consensys announced in September that it would split its consumer and institutional businesses into two independently managed companies. A full investigation into the incident is underway, with further updates expected from MetaMask as they become available.
Disclaimer
In line with the Trust Project guidelines, please note that the information provided on this page is not intended to be and should not be interpreted as legal, tax, investment, financial, or any other form of advice. It is important to only invest what you can afford to lose and to seek independent financial advice if you have any doubts. For further information, we suggest referring to the terms and conditions as well as the help and support pages provided by the issuer or advertiser. MetaversePost is committed to accurate, unbiased reporting, but market conditions are subject to change without notice.
About The Author
Alisa, a dedicated journalist at the MPost, specializes in crypto, AI, investments, and the expansive realm of Web3. With a keen eye for emerging trends and technologies, she delivers comprehensive coverage to inform and engage readers in the ever-evolving landscape of digital finance.
More articles
Alisa, a dedicated journalist at the MPost, specializes in crypto, AI, investments, and the expansive realm of Web3. With a keen eye for emerging trends and technologies, she delivers comprehensive coverage to inform and engage readers in the ever-evolving landscape of digital finance.



