Loading market data...

MetaMask Pulls Validators From Lido After Security Incident, Says User Wallets Safe

MetaMask Pulls Validators From Lido After Security Incident, Says User Wallets Safe

MetaMask disclosed a security incident affecting part of its infrastructure and is pulling affected validators out of its non-custodial staking operation. The company said it found no immediate threat to user wallets. It hasn't said which systems were hit.

The exits are a precaution, not a scramble. MetaMask didn't ask anyone to move funds or change settings, and it's working through the response internally with outside partners and security advisors. More detail is promised as the investigation continues.

What MetaMask actually runs

MetaMask operates Ethereum validators, the machines that lock up ETH to secure the network and earn rewards. Some of those validators sit inside Lido, the staking service that hands users stETH in return for deposited ETH. MetaMask inherited that setup when it split from Consensys in September and took over the staking unit formerly known as Consensys Staking.

So the exposure is on the staking side, not in the wallet software people use to hold tokens. That distinction matters. The company is being explicit that wallets are untouched.

The exit runs through Oct. 7

Lido said the last affected validators should stop running by the end of Oct. 7. From there, the ETH flows back into Lido gradually and gets staked again, a process that could take about 45 days. stETH holders keep their tokens the entire time. Lido told them they don't need to do anything.

Lido also has a reserve fund of more than 6,750 stETH to absorb any disruption during the wind-down. That's the buffer if the re-staking queue gets messy.

Worth noting: validator exits aren't instant. Ethereum's exit queue processes requests in order, and a 45-day re-staking window suggests the protocol is expecting the process to take its time.

The July disclosure still hangs over this

This incident lands roughly two months after Consensys said it found a hidden North Korean developer working on MetaMask code. That's not evidence the two are connected — MetaMask hasn't drawn a line between them. But it's the second time this year the company has had to talk publicly about its own security posture.

MetaMask's validator exit is the kind of event scammers love. Fake security alerts asking for recovery phrases tend to follow real security news. A single phishing signature can drain a wallet, and users getting an email or DM about "the MetaMask incident" should treat it as hostile until proven otherwise.

What's still unanswered

MetaMask hasn't named the systems affected, hasn't said how many validators are exiting, and hasn't put a number on the value involved. All of that is expected to come out as the investigation wraps. The concrete deadline on the calendar is Oct. 7, when Lido expects the last affected validators to go dark. After that, the slow re-staking clock starts ticking.