metamask logo bg
MetaMask says no user funds were hit in validator security incident
The wallet provider is exiting roughly 17,000 Ethereum validators as a precaution after an attacker diverted a small amount of staking rewards
MetaMask says there is no evidence that user wallets or funds were affected by the security incident it disclosed this week.
The incident did not leave MetaMask untouched, though. It hit the company’s Ethereum validator infrastructure, which sits behind its staking product.
What happened to MetaMask’s validators
MetaMask reported the incident on September 30, 2026. On October 1, it confirmed it had found no sign that customer accounts or assets were compromised.
One on-chain researcher found that an attacker diverted approximately 0.36 ETH in rewards tied to 18 of the 19 affected validators.
Around 17,000 validators are now exiting because of the breach. Together they hold around 523,000 ETH. MetaMask began exiting a subset of its Ethereum validators, working with its associated partners.
Exiting a validator means taking it offline entirely. The staked ETH gets returned, and the validator stops working.
The final validator exits are expected to finish by October 7, 2026.
The news moving money, markets, and the world—before your day starts.
Daily. Free. Join 34,000+ readers across crypto, finance, and policy.
Why users don’t need to do anything
MetaMask says users do not need to take any action. Their funds and settings can stay as they are.
The reason comes down to how MetaMask’s staking is built. The setup is non-custodial, and MetaMask does not control users’ withdrawal keys. One set of credentials lets a validator do its daily job. A separate key decides where the staked money ultimately goes. MetaMask never held that second key, so an intruder in its validator systems would not have had the keys to the vault.
MetaMask also warned users to stay alert for phishing as the situation unfolds.
The company has said its investigation is still ongoing. It has not yet detailed how the original compromise happened or its full scope.
The Lido factor and the cost of caution
Lido, a key partner in MetaMask’s staking setup, has flagged a real cost for participants. Stakers might miss out on rewards during the exit and re-entry period, which could stretch up to 45 days. Lido also warned of potential penalties during that cycle.
The attacker reportedly got away with about 0.36 ETH. In return, roughly 523,000 ETH worth of validators is being pulled offline.
What this means for Ethereum staking
Non-custodial staking was designed for exactly this scenario. When the operator’s systems get breached, the people who own the funds should still control where those funds go. However, users still depend on the operator’s infrastructure to earn rewards. If that infrastructure is compromised, rewards can be skimmed and validators may need to be shut down. Custody protects your principal. It does not fully protect your yield.
MetaMask has not yet explained how the attacker got in. Until it does, the industry cannot tell whether this was a one-off failure or a pattern that other staking providers should check for in their own systems.