MetaMask has started pulling its Ethereum validators out of Lido after a security incident hit part of its staking infrastructure. The wallet itself looks untouched, but the episode is a useful reminder of how much of DeFi sits on a handful of validator operators.
MetaMask disclosed on Wednesday, September 30, that it was dealing with a security incident affecting part of its infrastructure. In its own words, the team was "responding to a security incident" and working with clients, partners and outside security advisors. As a precaution, it began exiting the affected validators in its non-custodial staking operation. The company says it has found no immediate threat to MetaMask wallets.
Lido confirms the exits
Lido, whose protocol includes validators run by MetaMask Staking (the business formerly known as Consensys Staking), posted a security disclosure on its governance forum the same day. It described the move as a precaution following an "infrastructure compromise" and said the exits had already begun.
The timeline is the part stakers will care about:
Lido expects the last affected validators to exit by October 7, depending on network conditions.
Getting that ETH back into active staking is slower. Lido developer Will Shannon estimated the full exit, withdrawal and re-entry cycle could stretch to roughly 45 days, mainly because of the long validator entry queue.
Affected validators will miss rewards during that gap. Validators that drop offline before their exit completes could also pick up downtime penalties.
stETH holders do not need to do anything. Lido's disclosure did not ask anyone to withdraw, swap or move tokens.
Neither company has reported any slashing so far.
The diverted rewards
The sharpest detail came from outside the companies. Ethereum security researcher Kaden said on X that 19 MetaMask validators had won block rewards recently, and that 18 of those payouts went to the wrong fee recipient address. That address was funded through Tornado Cash. He put the diverted amount at about 0.36 ETH.
The mechanics matter here. A validator has a withdrawal destination for the staked principal and a separate fee recipient for block rewards. Changing the fee recipient can redirect income without touching the original stake. That fits with MetaMask's statement that it does not hold withdrawal keys for client stake, which would explain why the principal does not appear to be exposed.
Kaden also estimated that around 17,000 validators holding about 523,000 ETH were exiting. He added that roughly 821 other potentially affected validators were still running and that three suspected ones had not exited, and he said it was unclear whether the attacker could change fee recipients on all of them. If the attacker's access to signing permissions allowed more, he noted, malicious slashing would be theoretically possible.
MetaMask has not confirmed any of these figures, the Tornado Cash link or the validator counts. It also has not explained how its systems were breached, and Lido has not said which systems were compromised.
Ripple effects in DeFi
Aave founder Stani Kulechov said he was watching the situation and the Lido exits closely, and later said Aave's markets were running normally.
Some DeFi vaults saw money leave anyway. Startup Fortune reported sharp withdrawals from Sentora's curated Morpho vaults, with the RLUSD vault falling from about $426 million to $350 million in four hours and the PYUSD vault from about $409 million to $349 million. We could not independently verify those figures against a primary source, so treat them as reported rather than confirmed. Nobody has said those vaults or stETH were directly affected. Depositors seem to have pulled funds out of caution.
Not the first time
Validator operators have pulled this lever before. Staking provider Kiln began exiting its Ethereum validators in September 2025 after an investigation tied to a Solana incident involving SwissBorg. And in July 2023, Consensys Staking accidentally submitted exit messages for 125 Lido validators because of a miscommunication. That one was an error rather than a hack, and no funds were lost.
Bitnxt's view
Here is how we read it. The headline loss is tiny. About 0.36 ETH, if Kaden's numbers hold, is pocket change next to the 523,000 ETH reportedly being moved. MetaMask's team clearly chose to take the hit on rewards and downtime rather than gamble on what a compromised signing setup could do. Exiting first and explaining later is not a comfortable look, but it beats the alternative.
Recent exploit funds
What bothers us is the silence. At the time of writing there is no root cause from either MetaMask or Lido. Until that arrives, nobody outside can say whether the weak point was MetaMask's own servers, a vendor, or something shared. That decides whether other operators need to worry too.
The vault outflows are the bigger story for us. People pulled money from products that nobody said were affected. In today's DeFi stack, where staking tokens back lending markets and stablecoin vaults, one operator's bad day can move liquidity three protocols away within hours. Users who stake through a wallet interface should know which operator is actually running their validator, because that is where the risk lives, not in the brand on the screen.
For now, the practical advice is plain. Stay on official MetaMask and Lido channels, ignore any DM or pop-up claiming to be a "fix" for this incident, and never sign something you did not initiate.
What to watch next
A published root cause from MetaMask, and whether it matches Kaden's fee recipient theory
Whether the remaining validators exit cleanly by October 7
Whether Lido reallocates stake to other operators and how MetaMask Staking plans to return, if at all
Any slashing events, which none of the sources report so far
This article is for information only and is not financial advice.













































