MetaMask, one of the most widely used self-custody crypto wallets, has disclosed that it is responding to a security incident affecting part of its infrastructure. In an update published on September 30, the company said its security team identified no immediate threat to MetaMask wallets and is working with external partners and advisers to contain and remediate the issue.
As a precautionary measure, MetaMask said it has begun proactively exiting affected validators connected to its non-custodial staking operations, while coordinating with clients and partners. Exiting validators removes them from active duty on Ethereum's proof-of-stake network. In practice, that reduces the infrastructure's exposure while an investigation is ongoing and gives the company time to address any components that may be compromised or potentially vulnerable.
As of the company's disclosure, MetaMask had not reported any stolen user funds or a compromise of wallet keys, and had not described the exact nature of the incident or which specific part of its infrastructure was involved. That lack of technical detail makes it difficult to independently assess the severity of the event beyond the precautionary steps the company has described.
The knock-on effect has been visible on-chain. Coverage of the incident reported that roughly 523,000 ETH is leaving MetaMask-operated validators, pushing Ethereum validator exits to a nine-month high, with Ethereum's total exit queue surging above 773,000 ETH. CoinDesk reported that precautionary exits cover validators holding roughly 523,000 ETH and cited an Ethereum security researcher's estimate that about 0.36 ETH in rewards was diverted.
It is worth separating two different things that are often conflated when a wallet provider reports an incident. The first is the wallet software itself, which in MetaMask's case is non-custodial, meaning private keys are generated and held on the user's device rather than by the company. The second is the staking infrastructure that MetaMask operates or coordinates for users who choose to stake ETH, which involves servers, validator keys and operational systems that sit outside a user's own wallet. MetaMask's statement addressed the infrastructure side and said it had not identified an immediate danger to ordinary wallet users.
Validator exit queues on Ethereum are designed to throttle how quickly stake can leave the network, so a large batch of exits does not happen instantly. A spike in the exit queue therefore shows up as a measurable, publicly observable signal, and in this case the volume of exits attributed to MetaMask-operated validators was large enough to move the network-wide queue to levels not seen in months. Elevated queues mean those staking through affected validators may wait longer than usual for withdrawals to process.
Liquid staking protocol Lido indicated that no action is needed for stETH holders, according to coverage of the incident.
The episode lands during a period of heightened attention to security across the industry, with CoinDesk separately reporting a $3.8 million exploit involving NEAR Intents. For users, the practical takeaway is to rely on official MetaMask channels for updates rather than unverified social media accounts, which commonly impersonate wallet providers during incidents, and to be wary of unsolicited messages asking for seed phrases or wallet approvals.
Until MetaMask publishes a fuller technical post-mortem, key questions remain open, including how the infrastructure was accessed, how long the exposure lasted, and whether any further validator sets are affected. This article is informational only and is not investment advice.
This is a news summary for general information only — not financial advice, and nothing here is a recommendation to buy, sell, or hold any asset. Always verify against the original source and do your own research before making a financial decision.
Source: CaptainAltcoin · 2026-10-02