MetaMask on Thursday said it's responding to what it described as an "ongoing security incident" impacting part of its infrastructure.
"We are actively addressing and remediating the issue internally, in coordination with external partners and security advisors," the software cryptocurrency wallet maker said. "At this time, we have identified no immediate threat to MetaMask wallets."
MetaMask did not disclose any additional details related to the security issue. As a precautionary measure, MetaMask said it's proactively exiting affected validators within its non-custodial staking operations, in coordination with clients and partners.
"As a reminder, our staking operations are non-custodial in nature, and we do not manage withdrawal keys for stake on behalf of our clients," it added.
Lido, a decentralized liquid staking solution for Ethereum, said MetaMask has taken steps to protect client assets related to its operated Ethereum validators.
"These steps include exiting its Ethereum (ETH) validators in the Lido protocol, and will likely incur foregone rewards as well as possible downtime penalties should validators be taken offline in the near future to reduce risks related to potential network penalties," it said.
"Relevant validators have begun the exit process, with the final validators expected to be exited (but not fully withdrawn) by the end of October 7, 2026."
Update
In an update shared on October 1, 2026, MetaMask said it worked with its partners to exit affected validators and that there is no evidence that MetaMask wallets or customer funds have been affected.
"Our teams continue to work through containment and verification, and we’ll share further verified information as appropriate," it said.
"As always, please remain vigilant: be cautious of unsolicited messages, never share your Secret Recovery Phrase or private keys, and rely on official MetaMask channels for updates. MetaMask will never ask you for your Secret Recovery Phrase."




