Breaking
TRAttempted Hijacking of Plane from Dubai Over Jordanian AirspaceRUThe US Supreme Court overturned the stay of execution for Krista Pike of Tennessee.PLA Flydubai pilot attacked his co-pilot with a knife during a flight from Dubai to Tel AvivGLOBALTennessee death row inmate Christa Pike survives two lethal injections, taken to hospitalCNUS-Iran ceasefire talks stalled, US demands Iranian delegation to leave, Trump threatens to bomb IranGLOBALBank of England Governor Warns of AI Investment Risks and Market ShocksTRAzerbaijan International Defense Fair ADEX 2026 started, defense agreements were signed between Türkiye and AzerbaijanTRAn investigation has been launched due to Ferit Zengin's WhatsApp messagesTRDEM Party İmralı Delegation called on PKK to lay down arms after meeting with ÖcalanCNHong Kong's five-year plan emphasizes market economy and 'one country, two systems' principleTRAttempted Hijacking of Plane from Dubai Over Jordanian AirspaceRUThe US Supreme Court overturned the stay of execution for Krista Pike of Tennessee.PLA Flydubai pilot attacked his co-pilot with a knife during a flight from Dubai to Tel AvivGLOBALTennessee death row inmate Christa Pike survives two lethal injections, taken to hospitalCNUS-Iran ceasefire talks stalled, US demands Iranian delegation to leave, Trump threatens to bomb IranGLOBALBank of England Governor Warns of AI Investment Risks and Market ShocksTRAzerbaijan International Defense Fair ADEX 2026 started, defense agreements were signed between Türkiye and AzerbaijanTRAn investigation has been launched due to Ferit Zengin's WhatsApp messagesTRDEM Party İmralı Delegation called on PKK to lay down arms after meeting with ÖcalanCNHong Kong's five-year plan emphasizes market economy and 'one country, two systems' principle
BackMetaMask handles a security incident and removes its validators from Lido
MetaMask handles a security incident and removes its validators from Lido
Developing
Journal du Coin40 minutes agoTech2 min readView original

MetaMask handles a security incident and removes its validators from Lido

Quick Look

  • MetaMask announced that it was managing a security incident affecting part of its infrastructure during the night of September 30 to October 1, 2026, without disclosing the breach or its extent.
  • The publisher preemptively removed its validators operated within Lido, saying there is no immediate threat to users' wallets, while warning of potential scams exploiting the announcement.

AI-generated summary

Why It Matters

MetaMask is a non-custodial wallet developed by Consensys, allowing users to manage their private keys locally. Lido is a liquid staking protocol that entrusts deposited ETH to node operators to secure the Ethereum network in exchange for rewards in the form of stETH.

Font size

Rough night at MetaMask. The star wallet of the Ethereum ecosystem announced on the night of September 30 to October 1 that it was managing a security incident affecting “part of its infrastructure”. The publisher says nothing about the flaw or its extent. However, he has already taken a radical measure by releasing his validators operated within Lido.

Are your funds at risk? MetaMask swears not. Keep your hand on the brake though, because this kind of announcement attracts scammers like a lamppost attracts mosquitoes, and scams targeting MetaMask users have never waited for an excuse to multiply.

Security incident at MetaMask, a press release that says very little

The message is in two sentences. MetaMask explains that it is addressing an ongoing threat internally with the help of external security partners, and claims to have not identified any immediate threat to its users' wallets. Nothing about the compromised component. Nothing either on the date of the intrusion or on any data exposed.

Little useful reminder. MetaMask is a non-custodial wallet. Your private keys therefore remain stored on your computer or your phone, never on the servers of Consensys (the publisher of the extension). A hacker who enters the back end does not empty your wallet with a snap of his fingers. Depending on what it affects, it can however disrupt ancillary services such as swaps and bridges, or slip signature requests trapped in the interface.

“Security Update: We are currently responding to a security incident affecting part of our infrastructure. As of today, there are no immediate threats to MetaMask wallets. As a precautionary measure, we are proactively removing affected validators from our non-custodial staking operations, in coordination with our clients, partners and security advisors. We will keep you informed.”

The most concrete detail fell elsewhere, on the Lido governance forum. The principle of this liquid staking giant is simple. You deposit your ETH and receive in exchange stETH, a token which represents your deposit and its earnings. Lido then entrusts these ETH to node operators who run validators (the machines that secure Ethereum for rewards).

MetaMask Staking is one of these operators. His team published a disclosure message on September 30 at 11:40 p.m. UTC announcing the early release of its validators as a precaution. The process has already started. The last affected validators must have left the network by the end of the day on October 7, 2026, without being completely removed yet.

For stETH holders, the message is intended to be reassuring since no action is required. The message estimates that the released ETH will take up to 45 days to gradually return to the protocol, due to the validator entry queue. The bill will not be zero however. He also warns that the operation will likely result in lost rewards and possible downtime penalties.

Wallet MetaMask, good reflexes while waiting for the post-mortem

The scenario has recent precedent. In September 2025, the operator Kiln also released all of its Ethereum validators as a precaution, a few days after the theft of around forty million dollars in SOL from SwissBorg, via a compromised Kiln API.

MetaMask has not yet published any post-mortem (the report that details the causes of an incident). A few precautions until then are well worth their weight in ETH. Read each signature request completely before clicking. Postpone large swaps and new token approvals, those permissions that allow a contract to spend your tokens, for a few days. And ignore any “MetaMask support” who contacts you spontaneously, on X, Telegram or by email. No one at Consensys will ever ask you for your passphrase.

What to Watch

AI outlook — possibilities, not facts

  • MetaMask will publish a detailed postmortem of the incident within two weeks of the complete removal of validators.

    Likely · Within weeks

  • Scam attempts targeting MetaMask users will temporarily increase following the public announcement of the security incident.

    Very likely · Within days

Open Questions

  • What is the exact nature of the security flaw affecting MetaMask's infrastructure?
  • When did the intrusion begin and what data might have been exposed?
  • Which external security partners are involved in incident management?
  • What is the precise financial impact of the release of validators on MetaMask staking rewards?

Related Topics

This article was originally published by Journal du Coin.

Related Stories

More on this topicmetamask