MetaMask is investigating a security incident affecting part of its infrastructure and has begun removing Ethereum validators from its staking operation as a precaution while the scope of the compromise is determined.

 

 

The crypto wallet provider disclosed the incident on September 30, saying it is working with external partners and security specialists to contain and remediate the problem. MetaMask has not revealed how attackers gained access, which specific systems were compromised, or when the incident began.

So far, the company says it has found no immediate threat to MetaMask wallets. There has been no announced compromise of wallet recovery phrases or private keys, and MetaMask has not reported losses from users’ self-custodial wallets connected to the incident.

The company’s response has instead focused on MetaMask Staking, its non-custodial Ethereum staking operation. MetaMask is proactively exiting affected validators in coordination with customers and partners while its investigation continues.

MetaMask stressed that it does not control the withdrawal keys for cryptocurrency staked on behalf of its clients. This distinction limits what the validator operator can do with the underlying ETH because the credentials required to withdraw those assets remain outside its control.

Some of the affected validators are operated through Lido, the Ethereum liquid staking protocol. Lido said MetaMask has begun exiting its Ethereum validators from the protocol and expects the final affected validators to complete the exit process by October 7.

Removing validators does not necessarily mean staked assets have been lost. However, Lido warned that the precautionary action could result in foregone staking rewards and possible downtime penalties while validators are taken offline and the situation is investigated.

The complete process of exiting validators, withdrawing the ETH, and eventually putting it back into staking could take considerably longer. Current estimates suggest the cycle could last around 45 days because of Ethereum’s validator queues.

Lido has told stETH holders that they do not need to take action because of the incident. The protocol itself has not reported a compromise, and the security problem disclosed so far concerns infrastructure operated by MetaMask.

There are early indications that the incident may have affected validator operations. An independent Ethereum security researcher reported that block-production payments from a small number of MetaMask-operated validators were sent to an unexpected address and estimated that roughly 0.36 ETH was diverted. MetaMask has not publicly confirmed that estimate or explained whether those transactions were directly caused by the security incident.

Estimates concerning the overall number of validators involved have also circulated, but the company has not confirmed them. MetaMask’s official disclosure only states that “affected validators” are being exited, without specifying their number or the total amount of ETH associated with them.

The cause and full consequences therefore remain unresolved. MetaMask continues to investigate with outside security advisers, while the precautionary validator exits are expected to continue through October 7, and the company says it will provide further information as appropriate.

Leave a Reply