MetaMask pulls 17,000 Ethereum validators after security breach diverts staking rewards
MetaMask initiated the precautionary exit of roughly 17,000 Ethereum validators holding about 523,000 ETH after an infrastructure breach diverted 0.36 ETH in transaction fee rewards, while user wallets remained safe.

MetaMask initiated the precautionary exit of roughly 17,000 Ethereum staking validators—representing approximately 523,000 ETH—after discovering an ongoing security incident affecting part of its infrastructure. The company emphasized that its wallet software faces no immediate threat and pointed out that its staking service is non-custodial, meaning MetaMask does not manage withdrawal keys on behalf of users.[2][3][4][5][6][7]
According to on-chain security researcher Kaden, an attacker gained sufficient access to alter fee recipient parameters, diverting 18 block rewards from MetaMask validators to a Tornado Cash-funded address. The exploit captured only about 0.36 ETH, worth less than $1,000, though Kaden noted that any potential compromise of validator signing keys could introduce slashing risks. Taylor Monahan later praised MetaMask's quick reaction as a testament to its robust security for noticing the tiny 0.36 ETH diversion, while dismissing rumors that the infrastructure scare was connected to a post by Justin Drake.[2][3][7][8][10]
The mass exit triggered a steep surge across Ethereum's staking infrastructure, pushing the network's exit backlog to 773,447 ETH and driving withdrawal wait times to more than 13 days, the longest queue since December 2025. Liquid staking protocol Lido confirmed that MetaMask was pulling its operated validators, reassuring stETH holders that no action is required on their part but estimating that the full exit, withdrawal, and re-entry process could take up to 45 days.[1][2][6][7][9]
Key facts
- MetaMask proactively exited roughly 17,000 Ethereum staking validators holding approximately 523,000 ETH following an infrastructure security incident.
- MetaMask stated that user wallets face no immediate threat and noted its non-custodial staking service does not hold client withdrawal keys.
- On-chain researcher Kaden found that 18 block rewards were redirected to a Tornado Cash-funded address, netting the attacker around 0.36 ETH.
- Ethereum's validator exit backlog surged to 773,447 ETH, creating a wait time of over 13 days, the largest exit queue since December 2025.
- Lido stated that stETH holders need not take action, while estimating the full validator exit, withdrawal, and re-entry process could take up to 45 days.
- Taylor Monahan commended MetaMask's detection of the 0.36 ETH diversion as a testament to its security and denied rumors connecting the incident to a post by Justin Drake.
Sources · 8 sources
- CP
Crypto Patel@CryptoPatelPost on X ·
MetaMask Hack? Ethereum Validators Exit After Security Incident @MetaMask has started exiting affected Ethereum validators following an infrastructure security incident involving its non-custodial staking operations with Lido. All affected validators are expected to exit by October 7, while the full withdrawal process could take up to ~45 days. Lido says ethereum:0xae7ab96520de3a18e5e111b5eaab095312d7fe84 holders need no action, while Aave reports no market impact so far. The exact attack vector remains under investigation.
Open source - CR
CryptoSlateArticle ·
MetaMask security scare pushes Ethereum validator exits to a nine-month high MetaMask is pulling thousands of Ethereum validators after a security breach redirected rewards, creating a network-wide backlog for stakers trying to exit. Onchain security researcher Kaden said about 17,000 MetaMask-operated validators holding roughly 523,000 ETH were proactively exited after an analysis found that transaction-fee rewards from 18 of 19 validators that proposed blocks had been diverted to an address funded through Tornado Cash , an Ethereum-based privacy protocol that allows crypto transactions to be mixed and anonymized. The attacker appears to have captured only about 0.36 ETH, according to Kaden. The bigger concern is how the attacker gained enough access to alter fee recipients and whether that access extended to validator signing keys, which could trigger slashable behavior. MetaMask has not confirmed those figures or disclosed the cause of the incident. Instead, the company said that part of its infrastructure had been compromised and that it was exiting affected validators as a precaution while working with clients, partners and security advisers. It said it had identified no immediate threat to MetaMask wallets. The company also said its staking operation is non-custodial and that it does not control clients' withdrawal keys. That separation would prevent an attacker with only validator-level access from withdrawing the underlying stake, but it would not eliminate the possibility of penalties if signing keys were compromised and misused. Kaden said 821 potentially affected validators had not yet exited, including three among those whose fee rewards were allegedly diverted. It remains unclear why they are still active or whether the attacker retained access to change additional fee recipients. MetaMask has yet to disclose how many validators were affected, whether signing keys were exposed or whether any slashing has occurred. Ethereum’s withdrawal backlog spikes to 9-month high Meanwhile, the security incident and the exits are already rippling through Ethereum's staking infrastructure. About 773,447 ETH was waiting to leave the validator set on Wednesday, according to Validator Queue data, implying a 13-day, 10-hour wait before an exiting validator clears the queue. A further withdrawal sweep delay was estimated at 7.6 days. That is the largest exit backlog since December 2025 and above the roughly 476,000 ETH waiting during a previous surge in May, according to Validator Queue's historical data. Metamask's Security Issue Leads to a Surge in Ethereum Validator Queue Exit (Source: ValidatorQueue) The bottleneck reflects a safeguard built into Ethereum rather than an inability to process transactions. Ethereum limits how quickly stake can enter or leave its validator set to prevent abrupt changes from destabilizing its proof-of-stake consensus. The Validator Queue showed a churn rate of 256 ETH per epoch, with each epoch lasting about 6.4 minutes. At that rate, a large burst of exits must be processed gradually rather than simultaneously. The additional 7.6-day sweep period begins after validators clear the exit queue and become withdrawable. Ethereum then cycles through eligible validators and transfers balances to their designated withdrawal addresses. Related Reading Lido’s 1,500 ETH reserve target could slow stETH withdrawals in a crunch For MetaMask-linked stake, the disruption could last longer still. Lido, where MetaMask operates validators, estimates the full exit, withdrawal, and eventual re-entry process could take up to 45 days, partly because validators returning to Ethereum must also contend with a lengthy entry queue that is currently 27 days long. The post MetaMask security scare pushes Ethereum validator exits to a nine-month high appeared first on CryptoSlate .
Open source - WB
Wu Blockchain@WuBlockchainPost on X ·
Analysis: MetaMask Exits 17,000 Validators After Staking Security Incident MetaMask, one of the world’s most widely used self-custodial crypto wallets, has begun proactively exiting affected staking validators following a security incident. On-chain researcher Kaden said about 17,000 validators representing roughly 523,000 ETH have been exited, while around 821 potentially affected validators remain active. He identified 18 block rewards diverted from their intended fee recipients to a Tornado Cash-funded address, netting the attacker about 0.36 ETH. MetaMask said its staking service is non-custodial and that it does not control users’ withdrawal keys, while Kaden noted that compromised validator signing keys could still pose a slashing risk.
Open source - CB
Coin Bureau@coinbureauPost on X ·
⚠️ALERT: MetaMask says it is responding to a SECURITY INCIDENT affecting part of its infrastructure. The wallet provider says it has identified "no immediate threat to MetaMask wallets." As a precaution, it is exiting affected validators within its non-custodial staking operations. MetaMask says it does not manage the withdrawal keys for its clients' staked funds. The incident is ongoing, and MetaMask says it is working with external partners and security advisors to fix it.
Open source - WB
Wu Blockchain@WuBlockchainPost on X ·
MetaMask: Security Incident Affects Part of Infrastructure, No Immediate Threat to Wallets Identified MetaMask is responding to an ongoing security incident affecting part of its infrastructure, with no immediate threat to MetaMask wallets identified at this time. The company is working with external partners and security advisers to address and remediate the issue. As a precaution, MetaMask is proactively exiting affected validators from its non-custodial staking operations in coordination with clients and partners. Its staking operations are non-custodial, and MetaMask does not manage withdrawal keys on behalf of clients.
Open source - UN
UnchainedArticle ·
MetaMask Pulls Its Staking Validators After a Security Incident Hits Its Infrastructure MetaMask is taking the Ethereum validators run by its staking business offline after what it described on Wednesday as “an ongoing security incident affecting part of our infrastructure.” “At this time, we have identified no immediate threat to MetaMask wallets,” the company said, adding that it is working on a fix internally alongside outside partners and security advisors. As a precaution, MetaMask said, it has started exiting the validators affected by the incident, working with its staking clients and partners. The company stressed that the staking operation is non-custodial and that it does not hold withdrawal keys for clients’ stake. MetaMask was known as Consensys Software until earlier this month, when the company split in two and kept the wallet and consumer business under the MetaMask name. What It Means for Lido The validators being pulled include those MetaMask Staking runs as a node operator in the Lido protocol. A disclosure posted to Lido’s research forum late Wednesday, and shared by Lido on X, opened: “Following an investigation into an infrastructure compromise, MetaMask Staking (ex Consensys Staking) has taken precautionary steps to protect client assets related to its operated Ethereum validators.” The exits have already begun, and the final validators are expected to be out, though not fully withdrawn, by the end of Oct. 7 . The disclosure warned that the move will likely mean missed staking rewards, and that validators could face downtime penalties if they are taken offline in the near future. “No action is required from stETH holders,” the disclosure said. The ETH coming out of MetaMask Staking’s validators is expected to flow back into Lido gradually as it cycles through exit, withdrawal and re-entry, a process that could take “approximately up to 45 days due to the extended entry queue.” Lido pointed to its spread of node operators and an ad hoc reserve fund holding more than 6,750 stETH as backstops designed to contain disruptions like this one. Investigation Continues Neither MetaMask nor Lido has said what part of the infrastructure was compromised or how the breach was found. “A full investigation is underway, and further updates will be shared as they become available,” the Lido disclosure said. MetaMask said it will keep monitoring the situation and share more updates as appropriate. Related Listen: How the Bitget Hack Reopened Crypto’s Fight Over Neutral Infrastructure The post MetaMask Pulls Its Staking Validators After a Security Incident Hits Its Infrastructure appeared first on Unchained .
Open source - PR
ProtosArticle ·
MetaMask unstakes $1.4B of ETH after validator rewards stolen Crypto wallet giant MetaMask has “proactively” initiated the exit of 17,000 affected Ethereum validators, representing a total of over 523,000 staked ETH ($1.4 billion), following a security incident. It stressed that its wallets faced “no immediate threat,” and that the issue was confined to its “non-custodial staking operations.” The firm has so far provided no further details, but the worrying news prompted others to investigate the scope of the breach. Security Update: We are responding to a security incident affecting part of our infrastructure. At this time, we have identified no immediate threat to MetaMask wallets. As a precaution, we are proactively exiting affected validators within our non-custodial staking operations,… — MetaMask (@MetaMask) September 30, 2026 Read more: Bitget’s eighth birthday ends with a $352M hack Spearbit and Cantina security researcher 0xKaden posted an analysis of the incident to X, noting that block rewards from 18 MetaMask validators were “not paid to the correct fee recipient but instead to this tornado [Cash] funded account .” The suspicious address has made no transactions and holds 0.46 ETH, including its funding of 0.1 ETH from crypto mixer Tornado Cash. It has received 18 incoming ETH transfers (block rewards) from Titan Relay: Forwarder, worth less than $1,000 in total. On-chain analyst Emmett Gallic spotted a sizable 133,300 ETH transfer coming from wallets labelled “Lubin/ConSensys,” worth $360 million a few hours before MetaMask’s statement, though there’s no suggestion this is a suspicious transfer. after some onchain sleuthing, i think this is what happened: 19 metamask validators had won block rewards, and 18 of the rewards were not paid to the correct fee recipient but instead to this tornado funded account: 0x98B9231de84334c1d48BA0b72CF13f92484924A3 ~17k validators… https://t.co/qAlfkVNUW1 — kaden.eth (@0xKaden) October 1, 2026 Read more: SwissBorg CEO blames $41M loss on staking partner Kiln The incident bears a striking resemblance to last September’s $41 million loss from Kiln’s SOL staking operations. In that case, the firm also exited all active ETH validators and rotated their signing keys, treating all related operations as “potentially compromised.” UnMasked In July, Drop Site News reported that ConsenSys (MetaMask’s developer, which rebranded as both MetaMask and ConsenSys in early September) “accidentally hired a software developer linked to North Korea… as a consultant.” However, the report doesn’t suggest that the consultant ’s role, which lasted around a month, was related to the affected staking operations. Read more: Staked ETH exit queue reaches 45 days, highest in over two years Unstaked MetaMask’s response has led to a spike in the ETH staking exit queue, which has hit its highest level so far this year. MetaMask pulling the plug on 17,000 validators has seen a sharp spike in the Ethereum staking queue , which leapt to over 700,000 ETH. The queue leapt from around 200,000 ETH on Wednesday to over 700,000 ETH on Thursday, bumping the withdrawal wait time from three and a half days to almost two weeks. Liquid staking provider Lido expects MetaMask ETH to be re-deposited following the validators’ “exit, withdrawal, and re-entry cycle, which is estimated to take approximately up to 45 days due to the extended entry queue.” Got a tip? Send us an email securely via Protos Leaks . For more informed news and investigations, follow us on X , Bluesky , and Google News , or subscribe to our YouTube channel. The post MetaMask unstakes $1.4B of ETH after validator rewards stolen appeared first on Protos .
Open source - LS
Laura Shin@laurashinPost on X ·
"No ... not what happened," @tayvano_ on rumors that MetaMask's infrastructure scare is related to Justin Drake's post https://t.co/gTtZyQDawI
Open source - CR
CryptoSlate@CryptoSlatePost on X ·
Ethereum’s exit queue reached 773,447 ETH after MetaMask began precautionary validator exits following an infrastructure breach. Signing-key exposure remains undisclosed. MetaMask says it found no immediate threat to wallets. https://t.co/2oWqUzUEkn
Open source - LS
Laura Shin@laurashinPost on X ·
"I can't believe they noticed 0.36 ETH was diverted," @tayvano_ says MetaMask reaction to staking infrastructure scare is a testament to its robust security https://t.co/gTtZyQCCHa
Open source

