On Thursday, cryptocurrency wallet provider MetaMask has disclosed an ongoing infrastructure security incident affecting some of its infrastructure.
The company is working to address the issue internally, with help from external partners and security advisors, and says there is “no immediate threat to MetaMask wallets.”
“As a precautionary measure, we are proactively exiting affected validators within our non-custodial staking operations, in coordination with clients and partners,” MetaMask noted. “As a reminder, our staking operations are non-custodial in nature and we do not manage withdrawal keys for stake on behalf of our clients.”
Validators are nodes on the Ethereum network that run software responsible for proposing blocks, verifying crypto transactions, and maintaining the security of the Ethereum blockchain.
A MetaMask spokesperson redirected BleepingComputer to the company’s public statement when asked what part of its infrastructure was affected and whether any systems or data were accessed or compromised.
While MetaMask hasn’t shared further details about the incident, the decentralized liquid staking platform Lido Finance said earlier today that MetaMask Staking (ex Consensys Staking) has taken precautionary measures to protect client assets related to Ethereum validators.
“These steps include exiting its Ethereum (ETH) validators in the Lido protocol, and will likely incur foregone rewards as well as possible downtime penalties should validators be taken offline in the near future to reduce risks related to potential network penalties,” Lido Finance said.
“Relevant validators have begun the exit process, with the final validators expected to be exited (but not fully withdrawn) by the end of October 7th, 2026.”
The MetaMask non-custodial crypto wallet, developed by blockchain software company Consensys, lets users store and manage assets on the Ethereum network and other compatible blockchains.

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Save your seat

