Mastodon Skip to content
LIVE - NYSE/-/- CRYPTO/OPEN/24/7
BTC$86,479▲ 2.02%ETH$2,731▲ 1.66%SOL$121.67▲ 1.67%TOTAL CRYPTO$2.92T▼ 1.95%S&P 5007,722.72▲ 0.73%NASDAQ27,190.86▲ 1.19%DOW51,176.96▲ 0.49%GOLD4,176.20▲ 0.33%WTI91.04▼ 0.08%BRENT102.59▲ 0.33%EUR/USD1.1260▲ 0.09%USD/JPY157.76▼ 0.10%DXY101.87▼ 0.06%
Crypto

MetaMask Pulls $1.4 Billion in ETH From Staking After Reward Diversion

MetaMask exited about 17,000 validators after block rewards were diverted to a Tornado Cash-funded wallet. The attacker netted 0.36 ETH. The exit queue hit 773,000 ETH.

Pexels – Jonathan Borba

MetaMask has pulled roughly 17,000 validators holding about 523,000 ETH, close to $1.4 billion, out of Ethereum staking after an attacker redirected block rewards from its infrastructure to an outside wallet. The stolen amount traces to about 0.36 ETH, less than $1,500. The defensive move around it is one of the largest precautionary validator exits Ethereum has seen this year. The exit queue swelled past 773,000 ETH, a level not recorded since December 2025, and Lido expects the last affected validators to leave active duty by October 7. Withdrawal of that ETH from the queue, and return to staking, runs on a timeline Lido puts at up to 45 days. MetaMask, a wallet with tens of millions of users, confirmed a security incident in “part of its infrastructure” but has not explained how the attacker got in, whether signing keys were exposed, or how many customers were running the affected validators.

How the divert was caught

The disclosure came on September 30, when MetaMask posted on X that it was responding to a security incident and had “identified no immediate threat to MetaMask wallets.” The detail arrived from outside the company. Kaden, an on-chain security researcher who works with audit firms Spearbit and Cantina, analyzed validator fee flows in MetaMask’s non-custodial staking operation and found something odd: of 19 MetaMask-operated validators that had proposed blocks and earned fee rewards, 18 had sent those payments to an address that should not have received them.

The receiving address was funded through Tornado Cash, the Ethereum privacy protocol that was removed from the US sanctions list in 2025 after sanctions related to money laundering and sanctions evasion were lifted. Money that enters a Tornado Cash pool is hard to trace onward.

What the attacker actually captured was small. Kaden’s estimate of the diverted rewards came to about 0.36 ETH. The mismatch, an intrusion capable of changing fee recipient settings across most of a fleet of validators, against a theft measured in fractions of a single coin, is the thread that runs through everything that followed.

“Security Update: We are responding to a security incident affecting part of our infrastructure. At this time, we have identified no immediate threat to MetaMask wallets. As a precaution, we are proactively exiting affected validators within our non-custodial staking operations,” MetaMask said on X on September 30, 2026.

Half a billion of opacity

MetaMask did not publish its own count. The 17,000 validators and 523,000 ETH figure is Kaden’s estimate, and the company had neither confirmed nor denied it as of October 1. Consensus reported by CoinDesk and Protos landed on the same range. At the ether price in early October, that stake value sits around $1.4 billion.

What the company has not said matters as much as what it has. Two facts are missing. First, how the attacker got enough access to alter fee recipients. Second, whether that access touched validator signing keys. Fee recipient addresses are configuration, not secrets. Signing keys are the actual credentials that make a validator a validator. If signing keys leaked, the attacker could do more than skim fees. Slashable behavior, actions that destroy a validator’s own stake as a penalty, becomes possible. CryptoSlate noted that MetaMask has not resolved that question, and no slashing has been recorded so far.

Consensys founder Joseph Lubin, whose firm operates MetaMask, said publicly on October 1 that wallets, keys and self-custodied assets were not part of the incident. That statement addresses the worst-case reading for MetaMask’s user base, though the company itself has kept its disclosure to the shorter formulation of no immediate threat to wallets.

The exodus hits Ethereum itself

Precautions at this scale are not free, and the bill is landing on the network, not on MetaMask alone. When thousands of validators exit at once, they queue. The Ethereum validator exit queue jumped from roughly 200,000 ETH to over 700,000 ETH within a day, according to the queue tracker cited by Protos, and CryptoSlate put the total at 773,447 ETH, the largest backlog since December 2025. Anyone exiting a validator behind them in the queue waits longer for their ETH.

Lido, the staking service that pools user ETH, operates some of the redirected validators. Pooled operators are the dominant way retail holders stake, and a 17,000-validator exit is a measurable slice of Lido’s fleet. Lido’s early October disclosure said MetaMask-operated validators had begun leaving its system, expects the last of them to stop by October 7, and puts the full exit, withdrawal and re-entry cycle at up to about 45 days because of the queue. As The Defiant noted in covering the disclosure, rewards are lost while validators sit in that cycle, and those losses land on whoever stakes through the service, not on the operator.

The reaction spread past staking. Ethena withdrew funds from Morpho lending vaults as a precaution on October 1 and 2, according to CoinDesk, a migration-risk response in the same week. Separately, Consensys had already run this playbook once. A September incident affecting staking operator Kiln saw the firm exit all active ETH validators under its control and rotate their signing keys, treating related operations as potentially compromised. That exit also jammed the queue. MetaMask’s response mirrors the Kiln approach: pull everything, assume compromise, rotate, return later.

Figure Value Source
Validators exited (precaution) About 17,000 Researcher 0xKaden, CoinDesk
ETH left the exit queue About 523,000, roughly $1.4 billion 0xKaden, Protos, CryptoSlate
ETH actually diverted to attacker About 0.36 ETH, under $1,500 0xKaden
Validators emitting diverted rewards 18 of 19 block proposers in the fleet 0xKaden
Exit queue peak 773,447 ETH CryptoSlate
Full exit and re-entry cycle Up to about 45 days Lido disclosure

The price of assuming the worst

There is an argument that MetaMask overreacted. The attacker took less than one ETH. Exiting 17,000 validators cost stakers weeks of rewards and jammed a queue for the whole network. A slower response, raising fee recipients, rotating keys on the affected subset, would have limited the collateral damage.

The counterargument is the Kiln precedent. When an operator treats an intrusion as an unknown until proven otherwise, it exits and rotates first. Signing keys at risk of compromise are the reason. The fee recipient diversion proves the attacker had control over validator configuration. Whether that control extended deeper, into the signing infrastructure itself, had not been established publicly when the exits began. Waiting to find out means potentially permitting slashable actions on half a billion dollars of ETH.Operators in this market do not carry that risk once a breach is confirmed. The cost lands on stakers instead. It is a trade every large operator now makes without discussion at the first sign of compromise.

It also says something about how deposits are held. Non-custodial staking leaves infrastructure in the hands of a relatively small number of large operators, MetaMask, Lido nodes, Kiln, platforms such as Binance and exchanges. Fee recipients are changed at a fleet level, which turns hundreds of thousands of ETH into a single deployment unit. Precaution at fleet scale then propagates onto the queue globally.

What happens next

MetaMask has said it is working with third-party security investigators on the incident. The pending questions are the root cause, whether signing keys were in scope, and how many customers were exposed to reward losses rather than capital losses. No slashed funds are recorded. Re-entry will be staggered by the queue.

Holders staking through MetaMask or Lido can check whether their stake sits on affected validators and track queue timelines on public trackers. Developers weighing operator concentration have a fresh data point: when one wallet provider’s staking fleet is compromised, the queue, not the operator, absorbs the cost of the shakeout. Agency in staking security continues to be driven by precaution. Anyone reading the exit timeline as de-risking has that number wrong. The queue, not the headline theft, is the story to watch.

SourcesCoinDesk; Protos; CryptoSlate; The Defiant; Lido research forum; MetaMask statements on X.
Share: X