MetaMask discloses infrastructure breach, exits Ethereum staking validators
MetaMask says a security incident hit part of its infrastructure and is exiting affected Ethereum validators in its non-custodial staking operations, while stating wallets face no immediate threat.
At a glance
- MetaMask disclosed an ongoing security incident affecting part of its infrastructure and said it found no immediate threat to MetaMask wallets.
- MetaMask Staking, formerly Consensys Staking, is exiting affected validators, including roughly 17,000 validators in the Lido protocol, according to Decrypt.
- An independent researcher estimated about 0.36 ETH in block rewards was diverted; MetaMask has not confirmed the cause or scope.
- Lido says stETH holders need take no action, but exits will likely mean missed rewards and possible downtime penalties.
MetaMask, the cryptocurrency wallet developed by blockchain software company Consensys, has disclosed a security incident affecting part of its infrastructure and has begun exiting affected Ethereum validators run by its staking business. The company said it has identified no immediate threat to MetaMask wallets. Decrypt and CyberInsider report that the disclosure was made on September 30, 2026, while BleepingComputer covered it on October 1. The incident matters because MetaMask Staking operates a large number of validators for clients and for Lido, the largest liquid staking protocol on Ethereum.
What happened
"We are responding to a security incident affecting part of our infrastructure," MetaMask said in its statement, adding that its internal teams are working with external partners and security advisors to address and remediate the issue. According to BleepingComputer, the company is proactively exiting affected validators within its non-custodial staking operations in coordination with clients and partners.
MetaMask stressed that its staking operations are non-custodial and that it does not manage withdrawal keys for stake on behalf of its clients. When BleepingComputer asked which systems or data were accessed, a spokesperson pointed back to the public statement and provided no further details. CyberInsider notes that the company has not said when the incident was discovered or what caused it.
Technical details
The affected business is MetaMask Staking, formerly known as Consensys Staking. Lido said in its own disclosure that, following an investigation into an infrastructure compromise, MetaMask Staking took precautionary steps to protect client assets, including exiting its Ethereum validators in the Lido protocol. Decrypt reports that roughly 17,000 validators holding about 523,000 ETH were sent toward the exit, with the last ones expected to leave by October 7, 2026.
Independent on-chain analysis offers some indication of what the attacker did. According to Ethereum security researcher Kaden, cited by Decrypt and Coinpaprika, 18 of 19 MetaMask validators that earned block-production payments sent those payments to an unexpected address funded through Tornado Cash. Kaden estimated that about 0.36 ETH, worth under $1,000, was diverted. Decrypt reports that the researcher believes the attackers likely never had the ability to withdraw staked ETH directly, but could potentially have slashed validators depending on how signing keys were accessed. MetaMask has not publicly confirmed these findings or the attack method.
Who is affected
MetaMask wallet users are not affected according to the company, which said wallet assets face no immediate threat. The impact falls mainly on staking clients and on Lido. Lido warned that the precautionary measures will likely result in missed staking rewards and that validators could incur downtime penalties if they go offline in the coming days. According to CyberInsider and Decrypt, the exited stake is expected to return to the protocol gradually, and the full exit, withdrawal and re-entry cycle could take up to about 45 days because of Ethereum's extended validator entry queue.
Lido said that no action is required from stETH holders and pointed to its distributed validator model and a 6,750 stETH reserve fund as protective measures, Decrypt reports.
What to do
MetaMask wallet users do not need to take action based on current information, but should rely only on official MetaMask and Consensys channels, as high-profile incidents are often followed by phishing campaigns impersonating the affected company. Institutional staking clients of MetaMask Staking should follow coordination instructions from the company and review where their stake is delegated. Lido stETH holders were told no action is required. Further details on the root cause and scope have not yet been disclosed.
Sources
- MetaMask discloses security incident affecting its infrastructure — BleepingComputer
- MetaMask Exits Lido Validators Amid Infrastructure 'Security Incident' — Decrypt
- MetaMask exits Ethereum validators after infrastructure compromise — CyberInsider
- MetaMask Pulls Ethereum Validators Over a Sub-$1,000 Staking Breach — Coinpaprika
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



