MetaMask pulls 17,000 validators offline after staking infrastructure breach
Security & Exploits ·
The self-custodial wallet provider moved to withdraw roughly 523,000 ETH from staking after discovering tampered validator operations, even as hundreds of validators remain unresolved.
MetaMask has begun unwinding a large share of its staking validators following what it describes as a security incident tied to its infrastructure, according to wublockchain.xyz. On-chain researcher Kaden put the scale of the response at about 17,000 validators withdrawn, corresponding to close to 523,000 ETH, with roughly 821 validators that may still be affected yet to be removed from active duty.
Kaden's review also surfaced a smaller but more pointed problem: 18 block rewards were rerouted away from their designated fee recipients and funneled toward an address funded through Tornado Cash, yielding the party behind the redirection about 0.36 ETH. The sum is modest, but the mechanism — rewards being redirected mid-process — points to interference at the validator signing layer rather than a flaw in user-facing wallet software.
MetaMask has maintained that its staking offering is non-custodial and that it never holds users' withdrawal keys, a distinction the company has repeated in addressing the episode, as noted in its own statement on x.com. Kaden's analysis complicates that reassurance somewhat, flagging that validator signing keys appear to have been compromised, which could expose stakers to slashing penalties even without withdrawal funds being at risk.
The validator exits specifically touched MetaMask's Lido-connected staking positions, and separate reporting notes that withdrawals from that pathway are subject to a 45-day queue, meaning affected stakers may face an extended wait before funds are fully settled, per decrypt.co. Multiple accounts of the incident converge on the same baseline reassurance — that user wallets themselves were not directly compromised — while describing the validator exits as a precautionary measure rather than confirmation that all risk has been cleared.
What remains unclear is the root cause of how validator signing keys were compromised in the first place, whether the 821 still-active validators face ongoing exposure, and whether any additional rewards beyond the 18 identified instances were diverted. The resolution of the 45-day Lido withdrawal queue, along with any further disclosures from MetaMask on the scope of the breach, will likely determine how the incident is ultimately assessed.