Self-Custody

MetaMask's Incident: What Non-Custodial Doesn't Cover

MetaMask's September 30 infrastructure incident forced a validator exit while wallets stayed safe. What non-custodial promises, and what it doesn't.

Cover: WHERE THE ATTACK STOPPED SHORT OF THE KEYS. A gray path halts at a closed gate while a green path passes an open window; Tess reads a receipt, lower right.

On September 30, 2026, MetaMask disclosed a MetaMask security incident affecting part of its infrastructure, and its staking arm began exiting the Ethereum validators it runs in the Lido protocol as a precaution. An independent onchain researcher put the exit at about 17,000 validators holding some 523,000 ETH, worth around $1.4 billion; neither company has confirmed those figures. The story spread fast because MetaMask is the wallet millions of people point to when they say "self-custody." So if a self-custodial wallet company can have an incident at all, what does "non-custodial" protect you from? Take the questions one at a time.

Did the MetaMask Security Incident Touch My Wallet?

MetaMask says it has identified "no immediate threat to MetaMask wallets." The incident sits in infrastructure behind MetaMask Staking (formerly Consensys Staking), the business that operates validators for clients, and Decrypt's reporting on the exit quotes both MetaMask and Lido saying the same thing. The wallet on your phone holds your keys. The servers that run a company's staking business are a different system, even when both carry the same name.

If It's Non-Custodial, What Was There to Attack?

"Non-custodial" describes one fact: who holds the key that can move the asset. For a MetaMask wallet, you do. For MetaMask Staking, both firms say the company does not hold the withdrawal keys for client stake. A validator still runs on servers, signing software and monitoring that somebody hosts, and an attacker can go after all of that without ever reaching the stake.

The same onchain analysis shows what that looks like in practice. The researcher found that 18 block-reward payments from MetaMask validators went to an address funded through the Tornado Cash mixer instead of the correct fee recipient, roughly 0.36 ETH in total. In that reading, the attacker could touch where some rewards were sent, and "likely never had the ability" to withdraw the staked ETH itself. Neither company has confirmed it, so treat it as a strong hint, not a finding.

Why Exit Validators If Wallets Weren't Threatened?

A validator that may sit on compromised infrastructure is a liability whether or not any wallet was reached, and a key that can sign can also get a validator slashed. Exiting removes that risk. Lido expects the last of the validators to have exited by the end of October 7, and puts the full round trip of exit, withdrawal and re-entry at up to 45 days because of Ethereum's entry queue. Holders of stETH, Lido's liquid staking token, do not need to do anything. The delay comes from how Ethereum validators work.

It has happened before. Kiln, another large Lido node operator, exited all of its Ethereum validators in September 2025 after finding what its chief executive called a potential compromise of its infrastructure. Lido now points to its spread of node operators and a reserve of more than 6,750 stETH as buffers, and lending markets that take stETH as collateral reported no impact this time.

What Does Non-Custodial Actually Promise?

Less than "nothing can go wrong." A non-custodial design means no balance of yours sits in a company's wallet for that company to lose, freeze, misuse or have stolen. It says nothing about the rest of the company's infrastructure. The MetaMask case shows both halves: the stake stayed out of reach, while the reward routing around it appears to have been touched.

Mining has the same split. NexusPool's technology page describes the payout design: the block pays your address, and there is no balance for us to hold. With a 0% pool fee and a coinbase transaction written to the miner's own address, no pool wallet sits between a found block and the miner who found it, which is the failure that drained custodial pools and exchanges this year. That guarantee is real. It does not make a pool's servers immune to attack, any more than MetaMask's wallet design made its staking servers immune.

Where Would an Attack Show Up in Mining?

The MetaMask analysis points at the exact spot a miner should watch. In staking, the attacker went after the fee recipient, the field that says where rewards go. In mining, the equivalent field is the payout address inside the coinbase transaction, and the pool's server writes it into every block template. If someone compromised a pool's infrastructure, that output is what they would want to change.

So you check it. The Payout Preflight tool shows the coinbase transaction that would pay your address on the current block, before anyone finds it, so you can confirm the output names your address instead of taking our word for it. The Glass Ledger adds a signed receipt each hour for the shares the pool counted from your rig, the difficulty they were served at and the window they landed in, checkable against a key NexusPool publishes. Neither tool makes NexusPool's infrastructure attack-proof. They shrink what you have to trust.

What This Doesn't Claim

None of this is investment advice. A non-custodial design does not find blocks more often or pay better: your odds come from your hashrate against network difficulty, and they are the same at every pool. NexusPool's core software isn't public yet, so you cannot audit the pool's code the way you could audit open firmware. What non-custodial changes is narrow: a reward, whether a mining payout or a staked balance, never waits inside someone else's wallet for their decision.

So did non-custodial design fail at MetaMask? No. The part holding user keys stood apart from the part that had a problem, and the two did not share a failure.

Trust nothing. Verify what "non-custodial" covers before you assume it covers everything.