MetaMask , one of the world’s most popular software crypto wallets , has announced that it is experiencing an “ongoing security incident” affecting part of its infrastructure. The MetaMask security incident has already caused concern in the Ethereum and DeFi communities , as the wallet is used by millions of users worldwide. Although the company has not disclosed full details, the precautionary measures taken suggest that the situation is being taken very seriously.

According to the company’s official statement , MetaMask is actively working to address and remediate the issue, working with external partners and security consultants. The company emphasized that “no immediate threat to MetaMask wallets has been identified,” which is a positive sign for ordinary users. However, the lack of detailed information about the nature of the incident has raised concerns in the community.
As a precautionary measure, MetaMask announced that it is moving forward with the exit of affected validators from its non-custodial staking operations, in coordination with customers and partners. The company recalled that staking operations are non-custodial in nature, meaning that the service does not manage withdrawal keys for stakes on behalf of its customers. This is a significant difference compared to custodial systems, where the provider controls the funds.
See also: SAP Security Patch Day September 2026: New security fixes
MetaMask security incident: What we know so far
MetaMask has not revealed any further details about the security issue, leaving many questions unanswered. We do not yet know if this is a cyberattack, an internal bug, a software vulnerability, or some other type of incident. Transparency in the Web3 and cryptocurrency is critical, as users trust these platforms with significant amounts of digital assets. The community awaits further updates from the company.
Lido , a decentralized liquid staking solution for Ethereum , has confirmed that MetaMask has taken steps to protect customer assets associated with the Ethereum validators it operates. These measures include the exit of ETH validators from the Lido protocol . According to The Hacker News, the process of exiting the validators has already begun, with the last validators expected to exit (but not be fully retired) by the end of October 7, 2026 .

MetaMask security and the importance of non-custodial staking
One of the key points that MetaMask is the non-custodial nature of its staking functions. In a non-custodial system, the user maintains full control over their private keys and, by extension, their funds. This means that even if the provider’s infrastructure is compromised, users’ funds are not directly at risk, as long as the private keys are not exposed. This architecture is a fundamental principle of the DeFi ecosystem.
See also: AWS Security Incident Response: A service for responding to cyberattacks
This incident is a reminder of the risks associated with participating in DeFi protocols and staking operations, even when they are non-custodial. The infrastructure supporting these operations can be the target of attacks or experience technical issues, with consequences for users. Diversifying investments and using multiple platforms can reduce this risk.
How to Protect Yourself: Tips for MetaMask Users
In times of uncertainty like this, it is important for MetaMask users to take proactive steps to protect their digital assets . First, make sure your seed phrase is stored securely offline and not shared with anyone. Second, enable two-factor authentication ( 2FA ) on all connected platforms. Third, regularly monitor MetaMask ’s official announcements through official communication channels.
Additionally, it is important to avoid phishing sites and scams that often exploit such incidents to trick users. Malicious actors often create fake websites or send phishing emailsthat mimic official announcements, asking users to enter their private keys or seed phrase . Remember, no legitimate provider will ever ask you for this information. Vigilance is the best defense during times like these.
See also: Oracle: 800+ vulnerabilities in the September 2026 Security Update
The MetaMask security incident is a reminder that even the most trusted Web3 platforms are not immune to security incidents. The community eagerly awaits further updates from MetaMask regarding the nature of the incident, the extent of its impact, and the measures being taken to prevent similar incidents in the future. Transparency and timely communication are critical to maintaining user trust in this critical ecosystem.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
