MetaMask stated on Wednesday that the company is dealing with a 'continuous security incident' that affects some of its infrastructure, and as a preventive measure, it has begun to withdraw Ethereum validators that are operating under its Lido staking protocol.
The wallet developer stated that they have identified no "direct threat to the MetaMask wallet" and are working with external partners and security consultants to internally address and fix this issue. The company mentioned that they are withdrawing affected verifiers from their non-hosted staking business and are collaborating with customers and partners.
MetaMask Staking, formerly known as Consensys Staking, operates as a validator on Lido, the largest liquidity staking protocol on Ethereum. On Wednesday, Lido issued a security notice on its governance forum, disclosing these exit operations and describing the reason as an infrastructure damage incident that is currently under investigation.
Lido indicates that this move may mean giving up rewards; if these verifiers go offline in the coming days to reduce the risk of network penalties, there may also be downtime fines. The relevant verifiers have already begun the exit process, and it is expected that by the end of October 7th at the latest, the last batch of verifiers will complete their exit, although not all have yet withdrawn completely. Lido states that these exits are just one of the measures taken, and neither company has clarified whether verifiers operating elsewhere are also affected. MetaMask
MetaMask Staking (formerly Consensys Staking) operates Ethereum validators on Lido. In a security notice released on Wednesday, Lido stated that the related withdrawal was a preventive measure taken to protect customer assets, involving the Ethereum ( ETH) validators it operates.
ETH The time it takes to return to the protocol will be longer. Lido indicates that the pledged assets will gradually return to the protocol as verifiers complete their exit, withdrawal, and re-entry cycles; due to Ethereum's long entry queue, this round-trip process can take up to 45 days at most.
Both companies emphasize that the collateral arrangement is non-hosted, and MetaMask does not hold the extraction keys to customers' collateral assets. Lido states that holders of stETH do not need to take any action, and points out that their decentralized network of node operators, along with a temporary reserve fund of over 6,750 stETH, can serve as a buffer in case of disruptions.
Independent chain analysis revealed some details, but neither company has confirmed them. Researcher Kaden stated that 19 MetaMask validators won block rewards, and 18 of those payments were routed to an address funded by a Tornado Cash mixer, rather than the correct fee recipient address. The amount involved was approximately 0.36 ETH, which is less than $1,000 at current prices.
The same analysis shows that approximately 17,000 verifiers, holding a total of around 523,000 ETH, valued at about $1.4 billion, are being withdrawn as a preventive measure. There are also 821 verifiers who may be affected and have not yet left. The researcher stated that it is currently unclear whether the attackers are able to change the fee reception addresses for the entire collection, and claimed that it is "very unlikely" that they ever had the capability to withdraw the pledged ETH. However, if the methods of obtaining signature access rights differ, verifiers could potentially be deliberately penalized in principle.
The founder of Aave stated that the lending protocol, together with Lido, is monitoring the developments of the situation. The Aave market has not been affected so far; in Aave, stETH is one of the most widely used collaterals. The founder of Guy Young mentioned that the underlying assets supporting its synthetic US dollars USDe currently do not include any direct exposure to stETH or any other liquid collateral tokens, so it is expected that they will not be affected.
This is the second similar incident to occur within a little over a year with Lido. After Kiln identified what its CEO referred to as "potential damage" to its infrastructure in September 2025, it withdrew all of its Ethereum validators; just a few days ago, SwissBorg also experienced an incident related to Solana.

Neither company has specified what was damaged, how it was damaged, or who is responsible. A comprehensive investigation is underway, and updates will be provided later on.












