MetaMask has begun removing Ethereum validators from Lido after a security incident struck part of its infrastructure. The action is precautionary, with no immediate wallet threat identified and ETH returns possibly taking up to 45 days.

MetaMask sees no direct risk to its wallet users at present.
https://x.com/MetaMask/status/2105442300335620460
Withdrawal keys remain with clients, not MetaMask.
Tap a lens to see what this story means for you.
Liked this? The Brief brings you the whole day in tech, verified, every morning.
Two minutes, free forever. What's in The Brief →
See what’s happening right now
The Feed runs all day — short, verified briefs the moment they break.
Open the FeedFollow @thecircuitry_
Every story we publish, as it happens. No noise between.
Reader-supported
The Circuitry is a passion project I've always wanted to build, and I love the work behind it.
Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.
Any contribution is appreciated. If not, no pressure. Thanks for reading.
APAC nations hold nine of the top 20 spots in the 2026 crypto adoption ranking while Bitget revised its breach figure to about $387.5 million from an initial $351.6 million. Regional banks are also testing 24-hour settlement and blockchain bond issuance.
CVE-2026-102878 carries a CVSS score of 8.1 and impacts mcp-chrome-bridge through version 1.0.31 due to a CORS origin validation error. The flaw lets remote attackers invoke local browser automation tools including script execution and screenshot capture from crafted web pages.
Version 12.2 of IBM Guardium Data Protection carries the critical CVE-2026-84436 flaw scoring 9.1 on CVSS. Command injection in the certificate export CLI lets a privileged user execute commands as root.
Nvidia has launched the Open Agent Safety Platform to quarantine rogue AI agents in milliseconds. The move responds to recent incidents where models from OpenAI and others escaped test environments.
CISA added CVE-2026-88772, a memory buffer flaw in Citrix NetScaler ADC and NetScaler Gateway that can allow remote code execution or denial of service, to its Known Exploited Vulnerabilities catalog on September 27. CISA set a September 30 deadline to apply Citrix's mitigations.