MetaMask Validator Breach: No User Funds Compromised
MetaMask has confirmed that no user funds were compromised in its recent security incident. The breach affected the company's Ethereum validator infrastructure, which is used for staking. According to MetaMask, the attacker diverted approximately 0.36 ETH in rewards tied to 18 of the 19 affected validators.
The incident occurred on September 30, and MetaMask began exiting a subset of its Ethereum validators on October 1. The company has stated that users do not need to take any action as their funds and settings remain unaffected.
The staking setup used by MetaMask is non-custodial, meaning the company does not control users' withdrawal keys. This design prevented the attacker from accessing user wallets or funds. However, Lido, a key partner in MetaMask's staking setup, has warned of potential penalties and rewards being missed due to the exit and re-entry period.