Oct. 2 (CandyPulse) — MetaMask, one of the world's most popular crypto wallets, is responding to a security incident affecting part of its infrastructure. As a precaution, it has started exiting affected Ethereum validators in its staking operations. The company says there is no immediate threat to MetaMask wallets.
Key takeaways
MetaMask said it is dealing with an "ongoing security incident" affecting part of its infrastructure. It hasn't said which systems were affected or whether any data was exposed.
The step it has taken is focused on staking. Working with clients and partners, MetaMask began exiting affected Ethereum validators, the machines that stake ETH and help secure the network. Reports say this includes validators running within the Lido protocol.
When a validator exits, it stops securing the network and its staked ETH goes through a process to become withdrawable. It's a cautious move: if there's any risk that the systems running those validators were compromised, shutting them down limits the potential damage.
It does come with costs. Exiting means missed staking rewards, and there may be small downtime penalties. Reports suggest the full cycle of exiting, withdrawing and re-entering could take about 45 days.
| Group | Impact |
|---|---|
| Everyday MetaMask wallet users | No immediate threat, according to MetaMask |
| Clients of MetaMask's staking operations | Affected validators being exited; rewards paused |
| Lido-linked validators run by MetaMask | Included in the exits |
MetaMask stressed that its staking is non-custodial. It doesn't hold the withdrawal keys for clients' stake, which means it can't move their ETH. That design limits what an attacker could do with access to MetaMask's systems.
The exits should be complete by Oct. 7. Watch for a fuller explanation from MetaMask about what happened, which systems were involved and when staking operations will resume.
This article is for information only and is not financial or security advice.