NewsLayer.com
NewsLayer PulseLIVEBTC$82,436+0.74%ETH$2,481+0.28%SOL$108.76-1.37%XRP$1.39+0.67%DOGE$0.0852+0.86%ADA$0.2402+2.34%Total Cap$2.91T+0.77%Layer Index40 Neutral

MetaMask Security Incident Triggers Ethereum Validator Exits as Lido Sets Oct. 7 Deadline

MetaMask has begun removing Ethereum validators from its noncustodial staking service following a security breach of some of MetaMask’s infrastructure.

Bitcoin Foundation

Publisher

Oct 1, 2026 at 8:51 AM UTC · 2 分钟阅读

MetaMask Security Incident Triggers Ethereum Validator Exits as Lido Sets Oct. 7 Deadline
Image via Bitcoin Foundation

Key Signal

Sept. 30 Breach disclosure date

Entities

bitcoin, ethereum

Last Updated

9 天前

翻译中…

MetaMask has begun removing Ethereum validators from its noncustodial staking service following a security breach of some of MetaMask’s infrastructure.

The company disclosed the problem on Sept. 30 and reported that it was working with external security experts to address the issue. The company noted that it had not found any evidence of immediate risks to MetaMask wallets.

The company has not released information about how the hack was carried out, which infrastructure was attacked, or how many validators and ETH▲$2,518.27 were targeted.

It has not confirmed whether users’ or validators’ signing keys or other information were compromised. MetaMask officials said the withdrawals were a precautionary measure and noted that their staking business does not hold users’ withdrawal keys.

That separation is key to the noncustodial nature of the service. MetaMask has infrastructure and other resources to act as a validator, but users maintain control over the withdrawal keys for their staked ETH.

As a consequence, the infrastructure incident does not prove that client funds or withdrawal keys were lost. There have been no public reports of losses from slashing or withdrawals.

Lido shared more information about the incident, stating that MetaMask Staking began unstaking its validators participating in the Lido protocol following a breach of the validators’ infrastructure.