MetaMask Staking Exits Validators After Reward Payments Were Diverted

Brendan Smith
Brendan Smith - Cybersecurity Analyst
6 Min Read
Ethereum reward coins pass through an exit gate beside a separate staking vault
Validator exits and withdrawal custody involve separate controls

MetaMask is withdrawing affected Ethereum validators after a security incident in its staking infrastructure. An independent on-chain investigation found a striking mismatch: thousands of validators were heading for the exit, while the diverted block payments it measured totalled just 0.36 ETH. The difference matters because operating a validator, receiving its rewards and withdrawing its stake involve separate controls.

In its October 1 update, MetaMask said its investigation had found no indication that wallets or customer funds were affected. That is the company’s current finding, not a completed explanation of the intrusion. Its September 30 notice said it does not hold clients’ staking withdrawal keys.[1]

The payment address changed between two blocks

Bitquery’s October 1 reconstruction follows September 30 payments. One MetaMask-operated validator sent its block tips to Lido’s rewards vault at 12:11 UTC. Forty-eight seconds later, another paid a different wallet. Across the interval it studied, Bitquery counted 18 blocks whose tips were diverted, totalling 0.36 ETH. These are transaction tips from block production, not a measurement of stolen staking deposits.[2]

The surprising timing is that the first validator exit preceded the first diverted payment by 85 minutes. That does not establish when MetaMask discovered the problem: blockchain records reveal the transactions, not the company’s internal response.

Three controls explain the much larger exit

Ethereum’s staking-as-a-service model lets a provider operate the validator while withdrawal control remains separate. A validator’s signing key authorizes its network duties; withdrawal credentials determine where withdrawn stake goes. Keeping those controls apart limits what an operator compromise can do, but it does not make the operator’s infrastructure irrelevant.[4]

Bitquery diagram separates the staking deposit, validator signing key and fee-recipient address
Bitquery’s original diagram separates the deposit, validator signing key and fee-recipient setting. Its snapshot reports redirected tips and no slashing; access to signing keys remains unproven. Source: Bitquery Research.

The fee-recipient address is another setting: it determines where execution-layer block tips are paid. Changing it can redirect those payments without changing the stake’s withdrawal destination. A compromised signing system also raises a different concern: conflicting signatures can trigger slashing, a protocol penalty against the validator’s stake. Bitquery reported no slashed validators in its snapshot. Its investigation cannot establish whether the intruder obtained signing keys or accessed the machinery around them.

This is why the small diverted amount does not measure the whole disruption. Bitquery counted 16,965 validators holding 565,056 ETH that had exited or entered the queue as of 05:29 UTC on October 1. That ETH figure describes the stake associated with exiting validators; it is not a theft total. Non-Lido attribution uses matching validator messages, so the count is a dated analytical estimate rather than MetaMask’s confirmed scope.

An exit is not the end of the waiting period

Lido’s September 30 disclosure expected its final affected validators to exit by October 7, while explicitly distinguishing that from full withdrawal. It estimated the exit, withdrawal and re-entry cycle could take up to 45 days because of the extended entry queue. Foregone rewards and possible downtime penalties are the operational consequences it identified.[3]

Lido said no action was required from stETH holders. That statement has a defined audience; it does not describe every staking product or every MetaMask user. Readers checking an individual staking position should use their existing provider’s official account and notices to identify the product and its current status.

A message offering an emergency wallet “repair” is a separate trust decision. MetaMask says it will never ask for a Secret Recovery Phrase. Do not submit that phrase or a private key to a purported incident-response form. Our Ill Bloom wallet case explains another reason to distinguish the specific affected control from a request to reveal a seed phrase.

The useful lesson is the separation of controls: preserved withdrawal custody can coexist with disrupted validator operations and redirected rewards. Follow the scope of the verified incident, rather than treating a large exit total as proof of a wallet-wide loss.

References

  1. MetaMask. “User update.” September 30 and October 1, 2026; accessed October 3, 2026. Infrastructure incident and precautionary validator exits.
  2. Gaurav Agarwal. “MetaMask Staking pulled 17,000 validators. The intruder took 0.36 ETH.” Bitquery Research, October 1, 2026. On-chain reconstruction and measurement limits.
  3. Lido Governance. “[Security Disclosure] MetaMask Staking Precautionary Out of Order Exits.” September 30, 2026; accessed October 3, 2026. Affected validators and exit-cycle estimate.
  4. Ethereum.org. “Delegated staking (staking as a service).” Accessed October 3, 2026. Signing keys and withdrawal controls.
Share This Article
Cybersecurity Analyst
Follow:
Brendan Smith has spent over 15 years knee-deep in cybersecurity, chasing down malware from the gritty reverse-engineering of old-school trojans all the way to wrangling full-blown incident responses for small-to-medium businesses that couldn’t afford a full-blown breach. Over at Gridinsoft, he’s the guy piecing together those double-checked guides on nasty stuff like AsyncRAT, a remote access tool used in malware campaigns—helping readers make sense of the threat and work through cleanup without the extra headache.
Leave a Comment

AI Assistant

Hello! 👋 How can I help you today?