MetaMask Removes 17k Validators After Ethereum Security Incident
MetaMask is taking a precautionary measure by removing nearly 17,000 Ethereum validators from active staking after a security incident exposed part of its infrastructure. This move affects over half a million ETH and creates weeks of operational disruption.
The incident occurred on September 30, and MetaMask disclosed it while coordinating validator exits with clients and partners. Onchain analysis by Bitquery indicates that an unauthorized wallet received block tips from 18 MetaMask-operated validators, totaling just 0.36 ETH. The timing suggests that MetaMask had already started containment before the suspicious reward activity became visible on-chain.
The large validator exit is better understood as a security response rather than a measure of funds lost. Bitquery's evidence points to the fee-recipient layer, where an attacker could alter the destination and capture certain validator earnings without obtaining withdrawal credentials. MetaMask's decision to exit validators addresses the more serious residual risk: potentially compromised signing infrastructure.
The affected infrastructure extends beyond one staking pool, with several groups among the validators MetaMask is removing, including Lido, MetaMask's own pooled staking product, and validators whose block tips normally flow to a Coinbase-labeled address. The distribution shows why the incident is primarily an infrastructure problem rather than a failure isolated to Lido.
Exiting compromised validators is not instantaneous due to Ethereum's limits on validator exits per period. This process will occupy much of the exit capacity, with MetaMask's non-Lido clients expected to continue moving through the queue after Lido's validators leave. Lido estimates that this full cycle could take up to 45 days.