MetaMask Exits Lido Validators After Infrastructure Security Incident
Key Takeaways
- •MetaMask began precautionarily exiting the Ethereum validators it operates through Lido after a security incident in its infrastructure, with about 17,000 validators holding roughly 523,000 ETH, valued around $1.4 billion, being exited.
- •MetaMask said it identified no immediate threat to MetaMask wallets, and both companies stressed the staking setup is non-custodial, with MetaMask not holding clients' withdrawal keysThe exits, expected to complete by the end of October 7, will likely result in foregone rewards and possible downtime penalties, and returned stake could take up to 45 days to cycle through Ethereum's entry queue.
- •Unconfirmed on-chain analysis by researcher Kaden indicated 18 block reward payments totaling roughly 0.36 ETH, worth under $1,000, were routed to a Tornado Cash-funded address, though the attacker likely never had the ability to withdraw staked ETH.
- •Aave and Ethena reported no impact from the incident, which marks the second compromise involving a major Lido operator in just over a year, following Kiln's validator exits in September 2025.

MetaMask is responding to an “ongoing security incident” affecting part of its infrastructure and has begun exiting the Ethereum validators it operates through Lido as a precaution, the companies said Wednesday.
The wallet developer said it had identified “no immediate threat to MetaMask wallets.” It is investigating and remediating the issue internally with external partners and security advisers while exiting affected validators within its non-custodial staking operations and coordinating with clients and partners.
Security Update: We are responding to a security incident affecting part of our infrastructure. At this time, we have identified no immediate threat to MetaMask wallets. As a precaution, we are proactively exiting affected validators within our non-custodial staking operations,… — MetaMask 🦊 (@MetaMask) September 30, 2026
https://x.com/MetaMask/status/2105442300335620460?ref_src=twsrc%5Etfw
MetaMask Staking, formerly Consensys Staking, operates validators on Lido, Ethereum’s largest liquid staking protocol. Liquid staking lets users stake ETH without running their own validators and receive a token in return — in Lido’s case stETH — a structure that ties the security of individual node operators directly to assets used across decentralized finance. Lido disclosed the exits in a security notice posted to its governance forum, describing the cause as an infrastructure compromise under investigation.
Following an investigation into an infrastructure compromise, MetaMask Staking (ex Consensys Staking) has taken precautionary steps to protect client assets related to its operated Ethereum validators. These steps include exiting its Ethereum (ETH) validators in the Lido… — Lido (@LidoFinance) September 30, 2026
Lido said the move would likely result in foregone rewards and could lead to downtime penalties if validators go offline in the coming days to reduce the risk of network penalties. That is because an exit removes validators from Ethereum’s active set, where they stop performing duties and earning rewards until they re-enter. The relevant validators have started the exit process, and the last are expected to have exited—though not fully withdrawn—by the end of October 7.
Neither MetaMask nor Lido said whether validators operated by MetaMask elsewhere are involved. Lido described the exits as one of several precautionary measures taken after the infrastructure compromise.
Returning the ETH will take considerably longer. Lido said the exited stake should gradually return to the protocol as validators complete the exit, withdrawal and re-entry cycle. The round trip could take up to 45 days because of Ethereum’s extended entry queue.
Both companies stressed that the staking arrangement is non-custodial and that MetaMask does not hold withdrawal keys for clients’ staked assets. Lido said holders of its liquid staking token, stETH, do not need to take any action. It also pointed to its distributed network of node operators and an ad hoc reserve fund containing more than 6,750 stETH as buffers against disruption.
Independent on-chain analysis, which neither company has confirmed, offered an indication of the amount that may have been taken. Researcher Kaden said 19 MetaMask validators had earned block rewards and that 18 of those payments were routed to an address funded through the Tornado Cash mixer instead of the correct fee recipient. The payments amounted to roughly 0.36 ETH, worth less than $1,000 at current prices.
According to the same analysis, about 17,000 validators holding approximately 523,000 ETH, valued at around $1.4 billion, are being exited as a precaution. Ethereum caps validators at 32 ETH each, which is why a mass exit of this scale spans thousands of individual validator accounts. The researcher said 821 potentially affected validators had yet to leave. It remained unclear whether the attacker could alter fee recipients across the entire set.
Kaden said the attacker “likely never had the ability” to withdraw staked ETH. However, the validators could in principle be deliberately slashed — Ethereum’s protocol penalty, which burns part of a validator’s stake when it provably breaks network rules — depending on how signing access was obtained.
Aave founder Stani Kulechov said the lending protocol was monitoring the situation alongside Lido and that there had been no impact on Aave markets. stETH is among the most widely used forms of collateral on the platform, a measure of how deeply the token is embedded in decentralized lending and of why protocols beyond Lido moved quickly to check their own exposure.
Ethena founder Guy Young said the backing assets for the USDe synthetic dollar did not currently include direct exposure to stETH or any other liquid staking token, and that he expected no impact.
The incident is the second similar episode involving a major Lido operator in just over a year. Kiln exited all of its Ethereum validators in September 2025 after identifying what its chief executive described as a potential compromise of its infrastructure. That followed a Solana incident involving SwissBorg several days earlier.
Neither company has disclosed what was compromised, how the compromise occurred or who was responsible. A full investigation is under way, and both companies have promised further updates. The next visible milestones are the completion of exits by Oct. 7 and the gradual return of exited stake over the following weeks.
Source: Decrypt