Here's crypto news today that MetaMask users will want to know about directly from the source.
MetaMask has confirmed it's actively responding to a security incident affecting part of its infrastructure while stating clearly that no immediate threat to user wallets has been identified at this time.

Source: Wu Blockchain on X
According to MetaMask's official statement, published September 30, 2026, the company is "currently responding to an ongoing security incident affecting part of our infrastructure."
The statement, echoed on MetaMask's own X account, makes the key point plainly: "At this time, we have identified no immediate threat to MetaMask wallets."

MetaMask said it is actively addressing and remediating the issue internally, working in coordination with external partners and security advisors.
Even without a confirmed threat to user wallets, MetaMask has already moved on one specific precaution tied to this MetaMask Security Incident.
The company is proactively exiting affected validators from its non-custodial staking operations, working alongside its clients and partners to do so.
This is described explicitly as a precautionary measure rather than a response to any confirmed loss of funds.
This is the part of the announcement worth understanding carefully, since it directly addresses user fund safety.
MetaMask was specific on this point: its staking operations are non-custodial in nature, and the company does not manage withdrawal keys for staking on behalf of its clients.
A few things this structural detail means in practice:
MetaMask never holds the keys needed to withdraw a user's staked assets
Exiting a validator is a network-level action, separate from controlling user funds directly
This structure is part of why the company can act on the validator side while still maintaining that no immediate threat to wallets has been identified
MetaMask's update is notably brief and doesn't go into technical specifics about what part of its infrastructure was affected, how the incident was discovered, or who may be responsible.
A few things the current statement does not address:
The root cause or specific system that was compromised
Whether any user data or funds were actually accessed, as opposed to just being at precautionary risk
A timeline for when the incident began or when it might be fully resolved
MetaMask said only that it "will continue to monitor the situation closely and provide further updates as appropriate," suggesting more detail may follow as the investigation progresses.
Given the information currently available, there are a few practical takeaways for anyone using MetaMask:
The wallet itself, where most users hold their actual crypto, has not been flagged as directly threatened
Anyone specifically using MetaMask's non-custodial staking service may see their stake temporarily exit a validator as part of this precaution
Since MetaMask doesn't custody withdrawal keys for staking, users retain control over their staked assets throughout this process
As with any live security situation, relying only on official channels, MetaMask's own blog, and verified accounts, rather than unverified chatter, remains the safest way to stay updated
This MetaMask security incident is still actively unfolding, and the company has been upfront about what it does and doesn't yet know.
With no immediate threat to wallets identified and a clear precautionary step already taken around its non-custodial staking validators, MetaMask appears to be managing this transparently so far.
Given how early this situation still is, keeping an eye on MetaMask's official update page for further details remains the most reliable way to stay informed as more information becomes available.
This article is for educational and informational purposes only and should not be considered financial or investment advice. Always conduct your own research before making investment decisions.