What MetaMask Has Disclosed
MetaMask disclosed on October 1, 2026, that it is responding to a security incident affecting part of its infrastructure. The company confirmed no direct threat to user wallets. The crypto wallet provider is working with external partners and security advisers but has not disclosed the nature of the incident.
The company's statement points at MetaMask's own backend services rather than the self-custodial keys stored in users' browser extensions and mobile apps. MetaMask is a non-custodial wallet, meaning seed phrases and private keys are stored locally, not on a MetaMask server. The company has stressed that the incident involves infrastructure and does not represent a current security risk to MetaMask wallets.
Validators Exited, Lido Involved
MetaMask is exiting Ethereum validators operated through Lido as a precaution while it investigates the security incident. A validator caught signing conflicting messages can be slashed, meaning the network destroys part of its stake and forcibly removes it. Exiting validators before their keys can be misused closes off that exposure, at the cost of the rewards those validators would otherwise earn.
No action is required from stETH holders, according to the disclosure, though there may be some cost to staking rewards during the process. Exited ETH will return to Lido gradually as validators complete the exit, withdrawal, and re-entry cycle, which is estimated to take up to 45 days because of the long validator entry queue.
Aave founder Stani posted on X that his team is monitoring the incident in collaboration with Lido, noting that the Aave market is not affected and all operations are running normally.
MetaMask says it will provide further updates as appropriate as a full investigation continues.
Sources:
CoinTelegraph: MetaMask Exits Validators Amid Security Incident
Blockhead: MetaMask Exits Lido Validators After Infrastructure Compromise
Cyber Kendra: MetaMask Security Incident, Staking Validators Exited
