MetaMask Security Incident Leaves Validator Infrastructure Compromised
MetaMask, a leading Ethereum wallet provider, has confirmed that a recent security incident affecting its validator infrastructure did not compromise user funds. The company reported the incident on September 30, 2026, and confirmed that no user accounts or assets were compromised on October 1, 2026.
The incident impacted 18 of the 19 affected validators, with an attacker diverting approximately 0.36 ETH in rewards. As a result, around 17,000 validators are now exiting the system, holding approximately 523,000 ETH. MetaMask began exiting a subset of its Ethereum validators, working with its associated partners.
MetaMask's staking setup is non-custodial, meaning users control their withdrawal keys, and MetaMask does not hold the second key that determines where staked funds go. The company warned users to remain vigilant for phishing attempts as the situation unfolds.
Lido, a key partner in MetaMask's staking setup, has flagged a potential cost for participants. Stakers may miss out on rewards during the exit and re-entry period, which could last up to 45 days, and may face penalties during that cycle.