MetaMask Tackles Security Incident with Validator Removal
MetaMask is dealing with its first major security incident since becoming an independent company just three weeks ago. The incident, which began on October 1, involves a security compromise that has prompted MetaMask to remove its Ethereum validators from the Lido staking protocol. Despite initial concerns about user wallets and customer funds, MetaMask claims to have found no indications of imminent threats.
The company's non-custodial staking model means it does not hold withdrawal keys for client assets, but it is still focusing on 'containment and verification' steps. Affected validators are being pulled offline, with the last expected to be out by October 7. It may take another 27 days and 18 hours to fully withdraw Ethereum from validator positions.
The incident has raised questions about MetaMask's security measures, particularly given its position as the world's largest self-custodial financial platform. The company has urged users to exercise caution and not share their Secret Recovery Phrase or private keys with anyone. It also reminded users that any communications not coming from official channels should be ignored.