MetaMask Pulls Ethereum Validators After Security Incident – User Wallets Not Affected So Far

MetaMask has disclosed a security incident affecting part of its infrastructure and has begun pulling the related Ethereum validators as a precaution. The company stresses that it has not found any direct threat to regular MetaMask wallets or user funds so far.
Details of what happened remain limited. MetaMask is not saying which part of its infrastructure was compromised, how the attack occurred, or how many validators were directly at risk. The investigation is ongoing with the involvement of outside security experts.
In an official notice, the company clarifies that the measures concern its non-custodial staking operations. MetaMask operates validator infrastructure but does not control the keys needed to withdraw funds staked by clients.
Some validators are being pulled from Lido
The measures also cover validators that MetaMask Staking – formerly Consensys Staking – runs for the Lido liquid staking protocol.
The exit process has already begun. According to Lido, the last of the affected validators should complete their exit around October 7, but the full cycle of returning ETH and then restarting can take up to 45 days because of queues on the Ethereum network.
Some staking rewards may be lost during this period. stETH holders do not need to take any action, however.
CoinDesk also cites a third-party on-chain estimate suggesting that about 0.36 ETH in validator rewards may have been redirected in the incident. Neither MetaMask nor Lido has officially confirmed that figure.
The same researcher estimates the scale of the precautionary exit at roughly 17,000 validators with 523,000 ETH, though these figures also remain an outside estimate rather than company data.
No signs of a mass wallet hack
So far there is no evidence that attackers gained access to seed phrases, private keys or regular MetaMask user wallets.
The key difference lies in the service’s architecture: MetaMask Staking can manage validator operations but does not hold the withdrawal keys that would let it move client ETH on its own.
So the current incident looks primarily like a staking infrastructure problem rather than a compromise of the MetaMask wallet itself.
Even so, the investigation is not over, and the company has yet to disclose the key detail – what exactly was hacked and what level of access the attacker obtained.
MetaMask promises to publish more information as the investigation proceeds. For now, the company is not asking users to move funds, change wallet settings or take any special action.