MetaMask has begun removing Ethereum validators from its noncustodial staking service following a security breach of some of MetaMask’s infrastructure.
MetaMask Security Incident Triggers Ethereum Validator Exits as Lido Sets Oct. 7 Deadline
MetaMask has begun removing Ethereum validators from its noncustodial staking service following a security breach of some of MetaMask’s infrastructure.
Bitcoin Foundation
Publisher
Oct 1, 2026 at 8:51 AM UTC · 2 Min. Lesezeit

Entities
bitcoin, ethereum
Last Updated
vor 2 Stunden
The company disclosed the problem on Sept. 30 and reported that it was working with external security experts to address the issue. The company noted that it had not found any evidence of immediate risks to MetaMask wallets.
The company has not released information about how the hack was carried out, which infrastructure was attacked, or how many validators and ETH▲$2,518.27 were targeted.
It has not confirmed whether users’ or validators’ signing keys or other information were compromised. MetaMask officials said the withdrawals were a precautionary measure and noted that their staking business does not hold users’ withdrawal keys.
That separation is key to the noncustodial nature of the service. MetaMask has infrastructure and other resources to act as a validator, but users maintain control over the withdrawal keys for their staked ETH.
As a consequence, the infrastructure incident does not prove that client funds or withdrawal keys were lost. There have been no public reports of losses from slashing or withdrawals.
Lido shared more information about the incident, stating that MetaMask Staking began unstaking its validators participating in the Lido protocol following a breach of the validators’ infrastructure.
Market Context
Ethereum
ETH
$2,696
+0.07% (24H)
Market Cap
$328.6B
24H Volume
$11.7B
24H High
$2,738
Article Intelligence
Related Coverage
Sponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
