MetaMask Exits Ethereum Validators After Security Incident
MetaMask disclosed an ongoing infrastructure security incident on Thursday and is pulling affected Ethereum validators out of staking as a precaution, with the final validators due to exit by the end of 7 October 2026.

The disclosure came in a company statement reported by BleepingComputer on Thursday. MetaMask said it is "actively addressing and remediating the issue internally, in coordination with external partners and security advisors" and that it had identified "no immediate threat to MetaMask wallets" at that time.
MetaMask did not say which part of its infrastructure was affected. A spokesperson redirected BleepingComputer to the public statement when asked whether systems or data had been accessed. The wallet, developed by Consensys, handles assets on Ethereum and other compatible chains.
According to Lido Finance, MetaMask Staking, formerly Consensys Staking, is exiting its Ethereum validators in the Lido protocol. Lido warned the move will "likely incur foregone rewards as well as possible downtime penalties should validators be taken offline in the near future to reduce risks related to potential network penalties", and said the final validators should be exited, though not fully withdrawn, by the end of 7 October 2026. Both MetaMask and Lido stress that staking operations are non-custodial and that withdrawal keys are not managed on behalf of clients. The Hacker News reported on 1 October that MetaMask said it had worked with partners to exit the affected validators and saw no evidence that wallets or customer funds were affected.
Undersea cables, satellites and the trust problem underneath
The MetaMask episode is one of several this autumn in which the weak point sits below the application layer. On the same day the wallet incident surfaced, the CNBC AI Forum in Dallas on Thursday put autonomous agents and cyber risk at the centre of its agenda, with Credo AI founder Navrina Singh arguing there has been "much less focus on how do you actually put in place the right governance infrastructure".
The physical layer has its own version of that problem. On 1 October, BAE Systems published a piece on turning the seabed into a sensor to protect critical undersea infrastructure, and the US Department of War said Marines would support a NATO security initiative in the Baltic Sea.
Reports across stripes.com, Defence Industry Europe and Fierce Sensors described the same deployment, with drones and coastal sensors supporting Finnish forces. Ireland and Britain ran their first subsea telecoms cable security exercise, the Irish Examiner reported on 1 October, while the EEAS said the EU and Singapore discussed strengthening security of critical maritime and underwater infrastructure the same day. On 29 September, Defence24.com reported that Poland had joined all five major EU defence projects, with the Eastern Flank Watch potentially reaching EUR 100 billion.
Where the software risk meets the wire
Security researchers keep finding the same pattern in different stacks. Security startup Glow Security found more than 13,000 internal company screenshots that AI agents had uploaded publicly to GitHub repos, belonging to 343 organisations including Fortune 500 companies and AI labs, according to The Decoder on 1 October. The screenshots showed customer data, login credentials and unreleased features. Because the images were not stored in company accounts, security teams never noticed.
Epic, the US medical records giant behind MyChart, has paused most of its product development for what founder and CEO Judy Faulkner told Modern Healthcare would likely be six weeks, after a deployment of Anthropic's frontier cybersecurity model Mythos unearthed flaws. Epic chief security officer Stirling Martin told The New York Times that some customer configurations of MyChart could let outsiders access patient records without logging an intrusion. MyChart holds over 320 million patient records, TechCrunch reported on 2 October.
On the open source side, Envoy Gateway shipped v1.9.1 on August 28 with AES-256-GCM for OAuth2/OIDC session-cookie encryption and removal of the legacy AES-256-CBC decryption path, addressing CVE-2026-47775, InfoQ reported on 2 October. The same release restored a 15-second initial fetch timeout after v1.9.0 set it to zero, a change a GitHub issue linked to a production outage in which proxies lost downstream TLS certificates.
DigitalOcean launched Managed Agents in public preview, with isolated microVM runtimes, a Harness Runtime for coding agents such as Claude Code and Codex CLI, and an Action Gateway exposing more than 16,000 tools behind centralised permissions and human approval for sensitive operations, InfoQ reported on 2 October. Gecko Robotics, meanwhile, said on 28 September that it is working with NVIDIA to add AI agent security and control, The Robot Report wrote.
Grid, chips and money behind European infrastructure
Europe's own infrastructure build-out keeps running into constraints that are not purely technical. Transport and Environment, writing in CleanTechnica on 1 October, noted that 375 GW of clean energy projects and 455 GW of battery storage projects are waiting in queues for grid connection, while demand-side sites such as factories, data centres, ports and airports face the same congestion. Ports and airports have been told by law to electrify, but the grid has to follow.
At the Pretzl Connect 2026 event in Budapest, ESA future space transportation propulsion architect Kate Underhill told EE Times that space systems typically operate "at least 10 years behind consumer electronics" and that European satellite builders often face US export rules: "If there is any U.S. component on your satellite, then you have to comply with U.S. regulations."
Money is moving into the layer below the application. DIG Ventures closed its third fund at $120 million to back pre-seed and seed AI-native enterprise and cloud infrastructure companies, Tech.eu and Sifted reported on 1 October. Headline closed a $400 million European fund focused on Seed and Series A, Tech.eu reported the same day, citing its early bet on Mistral. Orange Business was selected as trusted network partner for TESTA-EIRIIS, the EU's private backbone for public administrations, Light Reading reported on 29 September, promising 99.999% availability across at least 12 points of presence.
None of that settles the MetaMask question. As of the company's 1 October update, teams were still working through containment and verification, and MetaMask reiterated that it will never ask users for their Secret Recovery Phrase.
Sources
14- 01Metamask discloses security incident affecting its infrastructureEN
- 02MetaMask Security Incident Prompts Exit of Affected Ethereum ValidatorsEN
- 03CNBC AI Forum 2026 takeaways: AI costs, security and scale in focusEN
- 04Security startup finds more than 13,000 internal company screenshots that AI agents uploaded publiclyEN
- 05Medical records giant Epic pauses product development to fix security bugs that risk patients' dataEN
- 06Envoy Gateway 1.9.1 Tightens Security and Addresses a Difficult Upgrade PathEN
- 07DigitalOcean Managed Agents Brings Managed Cloud Infrastructure to AI AgentsEN
- 08Grid Connection at European Ports & Airports: Solutions to Accelerate Transport ElectrificationEN
- 09Europe's Space Industry Seeks Greater Supply Chain ControlEN
- 10DIG Ventures closes $120M Fund III to back Europe's AI infrastructure startupsEN
- 11Exclusive: Dig Ventures raises $120m to back Europe's AI infrastructure startupsEN
- 12Mistral and Black Forest Labs backer Headline closes $400M European fundEN
- 13Orange Business to provide European Union's backbone network for trusted data exchangeEN
- 14Gecko Robotics works with NVIDIA to add AI agent security and controlEN
All figures and quotations in this text come from the sources listed below.
Content prepared by the editorial team with AI assistance.
Comments
0- No comments yet — be the first.