BREAKING
Oct 3Someone Stole Less Than $1,000 From MetaMask's Validators. MetaMask Is Pulling $1.4 Billion of ETH Out of Staking Because of It●Oct 2The SEC Just Told Fund Managers They Can Hold Your Crypto Keys Themselves. The Catch: Every Quarter They Have to Write Down That Nobody Else Will●Oct 1Two Appeals Courts Just Said Kalshi Sports Bets Are Gambling. The CFTC, Run by One Man, Is Rewriting the Dictionary So They Aren't.●Sep 30Two Weeks After Its Engineers Were Charged Over HYPE Perps, Robinhood Says It Will Sell HYPE Perps to Every American●Sep 29Senate Investigators Checked 846 Sanctioned Iran Wallets. 84% of Them Ran on Tether●Sep 2853 Memecoins on Robinhood Chain Turned Out to Be One Crew. They Took $18.4M, and Each Rug Paid for the Next●Sep 27KelpDAO Is Suing LayerZero for the $292M Hack. Its Evidence: LayerZero Signed Off on the Exact Setup That Got Drained●Sep 26The SEC Is About to Be Two People. 'Crypto Mom' Hester Peirce Just Quit, and Nobody Has Been Nominated to Replace Her●Sep 25Hackers Took $351.6M From Bitget Without Stealing a Single Private Key. They Forged the Transfer Orders and Bitget's Own Signing Machines Approved Them●Sep 24BitMEX Invented the 100x Perpetual Swap, Beat a Criminal Case With a Presidential Pardon, Then Lost to the Product It Created. Leave Money There Now and It Costs You $50 a Month●Oct 3Someone Stole Less Than $1,000 From MetaMask's Validators. MetaMask Is Pulling $1.4 Billion of ETH Out of Staking Because of It●Oct 2The SEC Just Told Fund Managers They Can Hold Your Crypto Keys Themselves. The Catch: Every Quarter They Have to Write Down That Nobody Else Will●Oct 1Two Appeals Courts Just Said Kalshi Sports Bets Are Gambling. The CFTC, Run by One Man, Is Rewriting the Dictionary So They Aren't.●Sep 30Two Weeks After Its Engineers Were Charged Over HYPE Perps, Robinhood Says It Will Sell HYPE Perps to Every American●Sep 29Senate Investigators Checked 846 Sanctioned Iran Wallets. 84% of Them Ran on Tether●Sep 2853 Memecoins on Robinhood Chain Turned Out to Be One Crew. They Took $18.4M, and Each Rug Paid for the Next●Sep 27KelpDAO Is Suing LayerZero for the $292M Hack. Its Evidence: LayerZero Signed Off on the Exact Setup That Got Drained●Sep 26The SEC Is About to Be Two People. 'Crypto Mom' Hester Peirce Just Quit, and Nobody Has Been Nominated to Replace Her●Sep 25Hackers Took $351.6M From Bitget Without Stealing a Single Private Key. They Forged the Transfer Orders and Bitget's Own Signing Machines Approved Them●Sep 24BitMEX Invented the 100x Perpetual Swap, Beat a Criminal Case With a Presidential Pardon, Then Lost to the Product It Created. Leave Money There Now and It Costs You $50 a Month●
BTC -- --%
ETH -- --%
Fear & Greed F&G 67 Greed
ESC
Type to search articles
Someone Stole Less Than $1,000 From MetaMask's Validators. MetaMask Is Pulling $1.4 Billion of ETH Out of Staking Because of It
BREAKING

Someone Stole Less Than $1,000 From MetaMask's Validators. MetaMask Is Pulling $1.4 Billion of ETH Out of Staking Because of It

The attacker got about 0.36 ETH. That’s under $1,000.

To make sure they can’t get any more, MetaMask is shutting down roughly 17,000 Ethereum validators holding about 523,000 ETH, around $1.4 billion, and taking them out of Lido’s validator set.

The thief made off with pocket change. The stake being pulled is more than a million times the amount stolen. (MetaMask hasn’t confirmed the validator count or ETH total. Those figures come from onchain tallies reported by Decrypt and others.)

What Happened

On September 30, someone got into MetaMask’s staking infrastructure. MetaMask Staking, formerly Consensys Staking, runs validators for Lido, the largest liquid staking protocol on Ethereum.

The attacker didn’t touch staked ETH. They changed the fee-recipient address, the setting that tells a validator where to send the tips users pay to get their transactions into a block.

Researcher Kaden spotted it onchain. Of the 19 MetaMask validators that won block rewards in the window, 18 sent their tips to the wrong address, a wallet funded through Tornado Cash. According to reporting on the onchain data, the redirect ran for about four and a half hours, from roughly 12:12 to 16:46 UTC.

Total take: about 0.36 ETH.

MetaMask called it an “ongoing security incident” affecting part of its infrastructure and said it was “proactively exiting affected validators within our non-custodial staking operations.” It added: “At this time, we have identified no immediate threat to MetaMask wallets.”

Why Pull $1.4 Billion Over $1,000?

The amount stolen doesn’t matter much. What matters is that someone could change validator configuration at all.

If an attacker can rewrite where a validator sends its rewards, the question is what else they can reach. Signing keys are the obvious worry. A compromised signing key can be used to make a validator sign conflicting messages, and that gets it slashed, with real stake destroyed. That’s a much bigger risk than lost tips.

The setup is non-custodial. MetaMask says it doesn’t manage withdrawal keys for its clients’ stake, so the attacker shouldn’t be able to withdraw the principal. Exiting the validators is the safe option: if a validator isn’t running, it can’t sign anything.

Neither MetaMask nor Lido has said how the attacker got in, what exactly was compromised, or who did it. Both say updates will follow as the investigation goes on.

The Cost of Playing It Safe

The exit isn’t free, and it isn’t quick.

  • Exits run through October 7. Decrypt reported 821 potentially affected validators were still waiting to exit at last count.
  • Ethereum’s exit queue hit 773,447 ETH, its biggest backlog since December 2025, according to CryptoSlate. That’s about a 13-day wait, plus roughly 7.6 days for the withdrawal sweep.
  • Getting back in is slower. The entry queue was around 27 days. Lido estimates the full exit, withdrawal and re-entry cycle could take up to 45 days.
  • Rewards are lost along the way. Lido says the exits will “likely mean foregone rewards” and “possibly downtime penalties if validators go offline.”

For stETH holders, Lido’s message is that “no action is required.” It also pointed to its reserve fund of more than 6,750 stETH as a buffer.

Even so, roughly half a million ETH earning nothing for up to six weeks is a real cost. All of it traces back to a fee-recipient change that netted the attacker under $1,000.

The Bigger Picture

This comes at the end of a bad stretch for crypto security. Bitget lost about $388 million in September after an attacker used a zero-day in a third-party security product to steal admin credentials. NEAR Intents lost $3.8 million to an exploit on October 1.

MetaMask is different because the loss was tiny and the response was huge. That’s a defensible call. Take the $1.4 billion offline now, and you avoid explaining later why a slashing event happened after you’d already spotted someone inside the system.

It also shows how concentrated Ethereum staking is. One operator’s infrastructure problem took more than half a million ETH out of active validation and pushed the network’s exit queue to a nine-month high.

Why This Matters for Crypto Jobs

Staking infrastructure security has become a board-level problem. Consider what this incident needs:

  • Validator and node ops engineers. Exiting 17,000 validators, rotating infrastructure and bringing everything back up cleanly in 45 days is a lot of ops work, and it doesn’t stop once the incident is closed.
  • Key management and signer security. The real worry here is signing keys. People who’ve built remote signers, HSM setups, distributed validator tech (DVT) or slashing-protection systems are the ones staking operators want right now.
  • Incident response and onchain forensics. The public breakdown of the fee-recipient redirect came from an independent researcher reading chain data. Teams that monitor fee recipients, MEV payouts and validator behavior in real time will hire people who can do that work.
  • Infra security at exchanges and wallets. After Bitget’s third-party zero-day and now this, every custodian and staking provider is checking its internal access paths. Cloud security, IAM and red-team skills are getting crypto-specific job offers.
  • Liquid staking protocol risk roles. Lido and its competitors need people who can model operator concentration, exit-queue liquidity and reserve buffers. This incident gives them a live case study.

The attacker got away with less than $1,000. Fixing what they exposed will take people with these skills.

Want to work on the infrastructure that keeps $1.4 billion of staked ETH from getting slashed? Browse open Web3 security, DevOps and protocol roles at Cryptogrind and get hired where the hiring is happening.

How did this hit?

Discussion

Comments are powered by GitHub. Sign in with your GitHub account to chime in.

Related jobs on Cryptogrind

View all

Looking for your next crypto role?

Browse hundreds of Web3 and crypto positions on Cryptogrind — from smart contract engineers to DeFi analysts.

Browse jobs