MetaMask has disclosed an ongoing infrastructure security incident affecting part of its operations and is proactively exiting affected Ethereum validators. The company said on September 30, 2026, that it has identified no immediate threat to MetaMask wallets.
The incident affects infrastructure connected to MetaMask’s non-custodial staking operations. MetaMask is working with external partners and security advisers while it investigates and remediates the issue.
What happened in the MetaMask security incident
MetaMask said part of its infrastructure is affected by an ongoing security incident. As a precaution, the company is exiting affected validators that it operates for non-custodial staking clients.
Lido Finance separately described the event as an infrastructure compromise. It said MetaMask Staking, formerly Consensys Staking, has started exiting Ethereum validators from the Lido protocol to protect client assets and reduce the risk of network penalties.
Lido expects the final affected validators to enter the exit process by the end of October 7, 2026. The complete exit, withdrawal, and re-entry cycle could take up to approximately 45 days because of the Ethereum validator queue.
What is confirmed
- An infrastructure security incident is ongoing. MetaMask has publicly confirmed that part of its infrastructure is affected.
- Affected Ethereum validators are being exited. MetaMask says this is a precautionary action coordinated with clients and partners.
- MetaMask does not hold withdrawal keys for staking clients. The staking operation is non-custodial.
- No immediate wallet threat has been identified. MetaMask has not advised ordinary wallet users to move funds or take emergency action.
- Lido says stETH holders do not need to act. Exited ETH is expected to return gradually after validators complete the exit and re-entry process.
What remains unverified
MetaMask has not disclosed how the incident began, which systems were accessed, who was responsible, or whether data was taken. It has also not reported theft of customer funds or compromise of wallet seed phrases.
Those unanswered questions are important. Reports or social media posts claiming widespread wallet theft, exposed recovery phrases, or a confirmed attacker should be treated as unverified unless MetaMask or another authoritative source provides supporting evidence.
Who may be affected
The confirmed operational impact involves Ethereum validators operated by MetaMask Staking. Those validators may experience downtime, foregone staking rewards, or network penalties while they are exited.
MetaMask wallet users are not currently identified as directly affected. Businesses using MetaMask for treasury management, decentralized finance, payments, or other on-chain operations should still monitor the investigation because the scope may change as more evidence becomes available.
Why the incident matters
MetaMask is one of the most widely used self-custodial crypto wallets. A security incident involving its infrastructure can attract phishing campaigns that impersonate support staff or exploit uncertainty among users.
The validator exits also show that the response extends beyond a routine website outage. MetaMask and Lido are taking steps intended to protect staking assets while investigators determine the scope of the incident.
Practical defensive actions
Use only official MetaMask updates
Check MetaMask’s official website and support channels for new information. Avoid links sent through unsolicited email, text messages, social media replies, or direct messages.
Do not share a recovery phrase
MetaMask support will not need a secret recovery phrase or private key to investigate this incident. Any person or website requesting those credentials should be treated as malicious.
Watch for incident-themed phishing
Attackers may send fake security alerts that claim a wallet must be upgraded, migrated, synchronized, or revalidated. Do not enter a recovery phrase into a website and do not approve an unexpected transaction.
Review wallet activity and permissions
Businesses should review recent transactions, connected applications, token approvals, and authorized devices. Revoke permissions that are no longer needed and investigate any unfamiliar activity.
Protect business crypto accounts
Use a hardware wallet or properly configured multisignature wallet for significant business funds. Require independent review for high-value transfers and keep day-to-day balances separate from long-term holdings.
Confirm staking status through trusted channels
Organizations using MetaMask Staking or Lido should consult their normal account contacts and official dashboards. Lido says no action is required from stETH holders, but affected operators may experience temporary reward or availability changes.
What to monitor next
MetaMask says it will provide additional updates as appropriate. The most important unanswered issues are the initial access method, the systems involved, whether information was accessed, and the final impact on validator operations.
Until those details are available, businesses should maintain normal wallet security controls, remain alert for phishing, and avoid making decisions based on unverified claims.