#MetaMask has new handling milestones for the security incident, but this is not proof that the “incident has been resolved.” On September 30, MetaMask disclosed that part of its infrastructure was affected. It said that at the time, it did not find any immediate threat to wallets, and it described taking preventive steps to exit the affected validation nodes. On October 1, an official update moved the status forward a step: MetaMask said it had worked with its partners to take preventive measures to exit the affected validation nodes, while investigation and remediation were still ongoing.

What this update changes is the “progress on remediation,” not a root-cause conclusion. The official statement did not provide the number of affected nodes, the completion ratio for the exits, the on-chain completion times, or the list of partners. Therefore, it is not possible to expand “exit measures were taken” into “all nodes have been exited,” nor can it be used to determine that the incident has been fully contained.

The security boundary also needs to be understood as stated. MetaMask said that, as of now, its investigation has not shown that the wallet or customer funds were affected. That is the company’s interim investigation conclusion—not an independent audit. Its earlier clarification that the related staking operations were non-custodial and that withdrawal keys were not held by MetaMask can explain the boundary of asset control, but that alone cannot be used to infer that the infrastructure incident had no impact on validation services.

Node exit is a remediation action for validation infrastructure. It is not equivalent to users transferring ETH out or experiencing asset losses. The public update also did not provide the number of affected validators, any change in earnings, or data on service interruptions. To determine whether the staking service was impacted, it would be necessary to verify the status of Lido nodes and on-chain exit records.

I will continue to look for three verifiable signals: whether the official disclosures include the root cause and the scope of impact; whether exits by affected validators have been completed on-chain; and whether partners have added independent verification. Until this information appears, the most reliable phrasing is: “Remediation is ongoing; there are no official signs of user asset impact yet; the scope and completion status still need to be disclosed.”

This round’s新增 is the wording in the October 1 update: “has taken exit measures with partners.” Compared with the initial announcement on September 30, remediation has moved from preventive arrangements into the execution phase, but key numbers and on-chain status remain unpublished. This change is worth monitoring, but it is insufficient to conclude that all validation nodes have completed exiting or that customer funds are absolutely unaffected.