MetaMask began pulling its Ethereum validators offline on Sept. 30 after an infrastructure security incident. A security researcher estimates about 17,000 validators holding roughly 523,000 ETH are exiting, and that 18 of 19 validators sent block rewards to an unexpected address. MetaMask says wallets are not affected and hasn’t confirmed those figures.
Staking exposure puts rewards under pressure
The MetaMask security incident is also creating a secondary issue for investors: the potential loss of staking income while affected validators leave the network.
Ethereum security researcher Kaden separately reported that 18 of 19 MetaMask-operated validators that had received block-production payments sent those payments to an unexpected address.
The researcher estimated that approximately 0.36 ETH in rewards had been diverted. MetaMask has not confirmed Kaden’s estimate or publicly explained how the infrastructure was compromised.
Kaden estimated that roughly 17,000 validators holding about 523,000 ETH were being exited as a precaution. MetaMask had not confirmed those figures at the time of the report, so they should be treated as an external estimate rather than an official count.
Ethereum’s protocol processes validator exits through a rate-limited queue, meaning large groups of validators cannot simply leave the network at once. Once a validator has exited, its ETH becomes eligible for withdrawal under the network’s withdrawal rules.
Validators that stop performing their duties after completing the exit process no longer earn normal staking rewards.
The economic impact could therefore extend beyond the estimated 0.36 ETH in redirected block-production payments. If affected validators remain outside the staking system for an extended period, their operators can lose additional rewards during the interruption.
MetaMask security incident raises Lido reward concerns
Lido said MetaMask-operated validators in its system had started the exit process, with the remaining affected validators expected to stop staking by October 7.
The MetaMask security incident consequently has implications for users who gain exposure to Ethereum staking through Lido’s infrastructure.
Lido warned that moving validators out and subsequently bringing them back into staking could take up to approximately 45 days because of Ethereum’s entry queue.
During that period, affected validators could miss staking rewards and potentially face penalties if they are taken offline before completing the required exit process.
The statement is significant because stETH holders are not being asked to manually withdraw or alter their positions in response to the incident. Lido’s position indicates that the operational disruption is being handled at the validator and infrastructure level.
Ethereum’s own documentation confirms that validator exits are processed through a queue and that timing depends on network demand. That design means a security-driven exit can become a longer operational event rather than an instant transfer of staked ETH.
The MetaMask security incident therefore presents a distinction between asset safety and income disruption. Even where principal funds remain protected, periods outside active validation can reduce the rewards generated by those assets.
Broader crypto market watches infrastructure risks
The MetaMask security incident also coincided with several notable on-chain movements, although the reported transactions were not established as being directly connected to the security event.
Blockchain tracker Lookonchain reported that a wallet associated with Ethereum co-founder Joseph Lubin transferred 133,298 ETH, valued at roughly $356 million, to a new address. The report did not establish a connection between that transfer and MetaMask’s response.
Ethena also withdrew funds from Morpho amid the security disclosures. The reported movements included about $75 million from a vault holding Ripple’s RLUSD and approximately $60 million from another vault holding PayPal’s PYUSD.
A source close to Ethena described those withdrawals as precautionary, and on-chain data later showed the funds had been redeployed after the company gained more clarity.
The MetaMask security incident shows the difference between smart-contract, custody and infrastructure risks. A staking provider can protect the underlying principal while still experiencing operational interruptions that affect validator rewards.
At the same time, several details remain unresolved. MetaMask has not publicly disclosed how its infrastructure was compromised, has not confirmed the researcher’s estimate of affected validators, and has said it will provide further updates as the response continues.
Until more information is released, the central questions for the market are the final number of affected validators, the amount of rewards actually diverted, how the infrastructure was accessed and how quickly the affected validators can safely return to active staking.
The MetaMask security incident is therefore primarily an infrastructure and staking-operations story at this stage, with the company reporting no immediate threat to MetaMask wallets while affected validators are removed from service as a precaution.