MetaMask security incident: separate your view of wallets and staking
At present, you should assess the already-disclosed infrastructure and staking incidents; you cannot directly conclude that all MetaMask wallet private keys have been leaked. Regular wallet users should first verify the official scope of impact; staking users should also pay attention to the exit progress and potential reward loss.
On September 30, MetaMask confirmed that some infrastructure experienced a security incident. It said it had not yet found any immediate threat to wallets and was proactively exiting the affected staking validator nodes that were being investigated. This is the official assessment during the investigation—not the final security conclusion.
Lido later disclosed that the related nodes have initiated exit and are expected to complete exit before October 7, but they may not have fully been able to withdraw back in full by then. The entire cycle—exit, withdrawal, and re-entering staking—may take up to about 45 days due to queueing effects. It is not an individual redeemer’s guaranteed time-to-receipt.
The key difference is this: MetaMask says it does not custody customers’ staking withdrawal keys, but node operations may still affect rewards. Lido warns that users may earn less rewards and, when nodes go offline, may be subject to downtime penalties—so “non-custodial” should not be understood as “zero loss.”
Lido currently says stETH holders do not need to take action. My advice is to verify updates only through the official website, and not to hand over seed phrases or signatures based on any unfamiliar “fix” page instructions. The disclosures that have been read so far have not explained the attack method or the full extent of losses, so you cannot use that information to assert that all wallets are affected.
Over the next 24 hours, watch whether the impact scope expands; by October 7, verify the actual exits, and don’t treat expectations as completed outcomes. If you confirm that wallet keys or the client are affected, the risk assessment should be upgraded immediately. Only once isolation measures, exit results, and loss accounting are verified will there be sufficient basis to lower the risk.
#MetaMask #以太坊 #asset security
At present, you should assess the already-disclosed infrastructure and staking incidents; you cannot directly conclude that all MetaMask wallet private keys have been leaked. Regular wallet users should first verify the official scope of impact; staking users should also pay attention to the exit progress and potential reward loss.
On September 30, MetaMask confirmed that some infrastructure experienced a security incident. It said it had not yet found any immediate threat to wallets and was proactively exiting the affected staking validator nodes that were being investigated. This is the official assessment during the investigation—not the final security conclusion.
Lido later disclosed that the related nodes have initiated exit and are expected to complete exit before October 7, but they may not have fully been able to withdraw back in full by then. The entire cycle—exit, withdrawal, and re-entering staking—may take up to about 45 days due to queueing effects. It is not an individual redeemer’s guaranteed time-to-receipt.
The key difference is this: MetaMask says it does not custody customers’ staking withdrawal keys, but node operations may still affect rewards. Lido warns that users may earn less rewards and, when nodes go offline, may be subject to downtime penalties—so “non-custodial” should not be understood as “zero loss.”
Lido currently says stETH holders do not need to take action. My advice is to verify updates only through the official website, and not to hand over seed phrases or signatures based on any unfamiliar “fix” page instructions. The disclosures that have been read so far have not explained the attack method or the full extent of losses, so you cannot use that information to assert that all wallets are affected.
Over the next 24 hours, watch whether the impact scope expands; by October 7, verify the actual exits, and don’t treat expectations as completed outcomes. If you confirm that wallet keys or the client are affected, the risk assessment should be upgraded immediately. Only once isolation measures, exit results, and loss accounting are verified will there be sufficient basis to lower the risk.
#MetaMask #以太坊 #asset security