MetaMask Exits Lido Validators Over Infrastructure Compromise
MetaMask has taken precautions to secure its Ethereum validator operations in Lido protocol following an infrastructure compromise. The company's staking arm, formerly known as Consensys Staking, is proactively exiting the validators as a precautionary measure. In a statement on September 30, MetaMask disclosed that it was responding to the security incident and had identified no immediate threat to its wallets.
The company emphasized that its staking operations are non-custodial, meaning they do not manage withdrawal keys for client stakes. This distinction is crucial because an Ethereum validator runs on two keys: a signing key that votes on blocks, and withdrawal credentials that decide where staked $ETH can go. Since MetaMask does not hold withdrawal keys, an attacker who reached the signing side could not move the underlying $ETH.
The validators are expected to be exited by October 7, although not fully withdrawn. According to Lido, the final validators will be removed, and the exited $ETH is expected to flow back into the protocol gradually over roughly 45 days as validators complete the exit, withdrawal and re-entry cycle.
No action is required from stETH holders, but they may forgo some rewards during the exit window. Lido's node operator set and security systems are designed to contain disruptions to protocol operations.