MetaMask (more precisely, its staking division MetaMask Staking, formerly Consensys Staking) had a security incident on 9/30, and it’s still being handled. First, let’s make clear the parts most likely to be misleading in headlines:
1. The wallet is secure; in reality, theft is very rare.
Researchers estimate that only about 0.36 ETH of block rewards were transferred away — the direct loss is so small it can be ignored. MetaMask also said the wallet isn’t under immediate threat.
2. The real cost: 1.4 billion USD worth of staked ETH was "forced offline".
The issue was with the staking infrastructure (running ETH validators for customers and Lido). To protect assets, MetaMask proactively withdrew from validators — about 523,000 ETH (worth about $1.4 billion as of 10/1) were left idle and exited. Lido expects to finish withdrawing by 10/7. The entire "exit → withdraw → re-enter" cycle could take up to 45 days.
3. This is the key: staking infrastructure is a new layer of systemic risk.
This is the same kind of story as last week when Bitget was breached through a zero-day by a third-party security product — the issue isn’t “the coin itself,” it’s the infrastructure running beneath it. Validators, cross-chain bridges, staking services, security vendors… these “invisible pipelines” are becoming the most common weak points in 2026.
A reminder for you:
· When staking/re-staking, you need to factor in the “operator’s infrastructure risk,” not just look at the APR.
· In this 45-day exit period, stakers will earn fewer rewards, and liquidity will also be stuck — the risk isn’t always “getting stolen,” it could also be “getting frozen.”
One sentence: In 2026, the cybersecurity story is shifting — hackers aren’t just trying to steal your coins, they’re going after the pipeline underneath your coins.
(Not investment advice)
👉 Follow me to get the latest market viewpoints and news as soon as possible