MetaMask and Core Lightning incidents show crypto attacks moving down the stack
Key Takeaways
- •Core Lightning said attackers were targeting unpatched nodes and instructed users of version 26.06.7 or earlier to install the current release.
- •MetaMask exited validators operated through Lido after an infrastructure security incident, while reporting no evidence that customer wallets or funds were accessed.
- •Lido warned that affected stETH holders could face missed rewards or downtime penalties, with withdrawn ETH taking as long as 45 days to return.
- •Linea said validators connected to its MetaMask-linked Yield Boost vault were also being exited, but its funds and control remained unaffected.
- •The incidents affected software and staking infrastructure above the blockchain base layers, and neither Core Lightning nor MetaMask had reported stolen funds.

Attackers are probing unpatched Bitcoin nodes, Core Lightning has revealed, in the same week that MetaMask spent two days pulling staking validators offline following a breach of part of its infrastructure.
Both platforms said the incidents did not touch their respective base layers, the core protocol code on which Bitcoin and Ethereum run. Bitcoin kept producing blocks throughout, and MetaMask stated that no customer wallets or funds were affected. In both cases the exposure sat in the operational layer above: node software and staking infrastructure that connect users to the chains.
Core Lightning tells operators to stop running old builds
Core Lightning is open-source software that many businesses and individuals use to run nodes on the Bitcoin Lightning Network. On October 2, the team posted an urgent notice telling anyone running version 26.06.7 or earlier to install the current release immediately.
The project wrote on X, “We’ve received reports that attackers are targeting unpatched nodes.” It told users that upgrading to the current release was an important step in protecting their funds.
Core Lightning acknowledged flaws in the previous version but said nothing about stolen funds.
The alarm carries particular weight because Lightning nodes hold live balances in payment channels that sit off the main Bitcoin chain. A reachable node that has not been patched can be messaged directly by its peers, which turns a theoretical bug into an exposed attack surface.
A compressed two months of patches
The disclosure is the latest in a series of incidents Core Lightning has handled in the second half of 2026. In August, the project said it was working through a high volume of vulnerability reports, many of them machine-generated. It shipped version 26.06.7 on August 28, holding back the matching source code for roughly two weeks so operators could update before the fixes made the underlying bugs easier to reconstruct, a coordinated-disclosure window that gives defenders a head start on attackers.
A second scare followed in mid-September, when maintainers instructed operators to disable all experimental features immediately over a flaw that could put funds at risk. Version 26.06.8 was released on September 22, this time without an embargo.
MetaMask pulls validators out of Lido
MetaMask said on September 30 that it was responding to a security incident affecting part of its infrastructure. Over the following day, it began exiting the Ethereum validators it operates inside Lido, the largest liquid staking protocol on Ethereum, which lets users stake ETH and receive stETH, a token representing their staked coins. Validators earn rewards for helping run the network, so pulling them offline stops that income until they are back.
MetaMask Staking, formerly Consensys Staking, said its operations are non-custodial and that it does not hold withdrawal keys on clients’ behalf. In its October 1 update, the firm said it had found “no immediate threat to MetaMask wallets,” adding that there was no indication that customer funds had been accessed.
Lido, which disclosed the exits in a governance-forum notice, told stETH holders that no action was required, but warned that the move would likely mean foregone rewards and possibly downtime penalties. The precaution comes at a cost: withdrawn ETH could take up to 45 days to return, and the last affected validators are expected to have exited by the end of October 7.
Lido is not the only platform affected. Linea confirmed on X that validators supporting its MetaMask-linked Yield Boost vault were also being exited, though it stated that the vault’s funds and control were unaffected.
A pattern defenders have been flagging
Both events fit a trend the industry has been warning about. In August, BTCPay Server disclosed a critical flaw that attackers had already used to drain Lightning nodes belonging to merchants. The same flaw affected hardware wallet maker Foundation, which lost its own node in the attack.
Also that month, more than 30 firms, including Coinbase, Block, Blockstream, and ARK Invest, signed a letter organized by the Bitcoin Policy Institute noting that open-source security researchers are working with weaker AI tools than their attackers.
Across these cases, the target has not been a chain’s consensus rules but the software and infrastructure layered on top, leaving operators as the first line of defense. Neither Core Lightning nor MetaMask has reported stolen funds to date, and the signal to watch next is whether any losses emerge as operators finish upgrading and MetaMask’s exited ETH works through the withdrawal queue that can take up to 45 days to clear.