breach
Published 2026-09-30
Verified 2026-10-01

MetaMask: ongoing infrastructure security incident — precautionary Ethereum validator exits (Lido by 7 Oct); no immediate wallet threat claimed

MetaMask (Consensys) user update (30 September 2026; BleepingComputer and The Hacker News amplified 1 October) states the company is responding to an ongoing security incident affecting part of its infrastructure, remediating internally with external partners and advisors. MetaMask says it has identified no immediate threat to MetaMask wallets. As a precaution it is proactively exiting affected validators in its non-custodial staking operations with clients and partners; staking is non-custodial and MetaMask does not manage withdrawal keys for client stake. Lido Finance (forum disclosure) says MetaMask Staking (ex Consensys Staking) began exiting ETH validators in the Lido protocol to reduce network-penalty risk; final validators expected exited (not fully withdrawn) by end of 7 October 2026, with likely foregone rewards and possible downtime penalties. MetaMask has not publicly named the compromised subsystem or confirmed data access. Distinct from wallet-malware phishing campaigns. Primary: MetaMask user update; wire: BleepingComputer / THN 1 Oct.

Product
MetaMask infrastructure / MetaMask Staking (non-custodial Ethereum validators) — incident, not a product CVE
Versions
n/a — infrastructure incident / validator exit response (not a versioned product flaw)
Exploited in Australia?
unknown
Patch to
Wallet users: MetaMask states no immediate wallet threat; still prefer hardware wallets / avoid new approvals until MetaMask posts closure. Staking clients with MetaMask/Consensys-operated validators: expect exits through ~7 Oct per Lido; monitor rewards/penalties. Not a version patch.

Primary: MetaMask — User update (infrastructure security incident, 30 Sep 2026) · Vendor: MetaMask / Consensys — official user update · BleepingComputer — MetaMask infrastructure incident + Lido validator exits (1 Oct 2026)

breaches cloud