Fears of a potentially major MetaMask liquid staking exploit spread across the crypto market on Wednesday, but emerging details suggest the incident is considerably more contained than initially feared, with user funds currently believed to be safe.
MetaMask confirmed on Sept. 30 that it was responding to a security incident affecting part of its infrastructure and had begun proactively exiting affected Ethereum validators. However, the company said it had identified “no immediate threat” to MetaMask wallets and stressed that its staking operations are non-custodial.
The announcement initially triggered speculation about a much larger problem. The Rollup founder Andy Cavanaugh said early information suggested a small percentage of Ethereum’s supply could effectively be “held hostage” by issues affecting a liquid staking provider.
After speaking with multiple sources, however, Cavanaugh walked back those concerns, saying the incident appeared more comparable to last year’s Kiln situation, where validators were proactively exited following an infrastructure compromise.
“We do not expect any contagion across liquid staked ETH, restaked ETH, or DeFi at large,” Andy said in an update, adding that the situation appeared contained.
The incident centers on MetaMask Staking, formerly known as Consensys Staking, which operates Ethereum validators on behalf of clients and protocols including Lido.
MetaMask has not yet disclosed exactly what was compromised or how an attacker may have gained access. It said only that part of its infrastructure was affected and that it was working with external partners and security advisers to address the issue.
Lido subsequently confirmed that MetaMask Staking had started exiting Ethereum validators from its protocol following an investigation into an infrastructure compromise. The final affected validators are expected to exit by Oct. 7.
The precautionary exits are significant because Ethereum validators use signing keys to participate in network consensus. If signing infrastructure is compromised, an attacker could potentially cause validators to behave improperly and expose them to penalties or slashing.
Exiting validators can therefore limit the potential damage even if there is uncertainty over which systems or credentials were exposed.
The situation resembles the precautionary response taken by staking provider Kiln in 2025. Kiln exited thousands of validators after discovering compromised infrastructure, rather than leaving potentially exposed validator keys active.
The crucial distinction is that MetaMask’s staking operation is non-custodial.
MetaMask said it does not control the withdrawal keys associated with its clients’ staked ETH. That means a compromise involving validator infrastructure or signing keys does not automatically give an attacker the credentials required to withdraw the underlying ETH to an attacker-controlled address.
This is also why comparisons with the KelpDAO exploit appear increasingly misplaced.
The April KelpDAO attack resulted in the loss of 116,500 rsETH worth roughly $292 million after attackers compromised infrastructure involved in LayerZero’s cross-chain verification system. The attackers were ultimately able to trigger the release of assets through a forged cross-chain message.
So far, there is no evidence of an equivalent mechanism allowing assets to be drained in the MetaMask incident.
Lido has also said stETH holders do not need to take action. Meanwhile, no direct threat to ordinary MetaMask wallets has been identified.
The main financial exposure currently appears to involve lost staking rewards and potentially downtime penalties rather than stolen principal.
The validator exits will not immediately return everything to normal.
Lido expects the affected ETH to gradually return to the protocol as validators move through Ethereum’s exit, withdrawal and eventual re-entry process. The entire cycle could take up to approximately 45 days because of the network’s extended validator entry queue.
During that period, some staking rewards could be lost. Validators deliberately taken offline before completing their exits could also incur downtime penalties, though doing so may reduce the risk of more serious penalties if their signing infrastructure has been compromised.
For stETH holders, however, Lido says no action is currently required. Its distributed node-operator structure means MetaMask Staking represents only part of the infrastructure supporting the liquid staking protocol.
The biggest unanswered questions are therefore technical rather than financial: what exactly was compromised, whether any validator keys were misused, how attackers obtained access, and whether infrastructure outside MetaMask’s staking operation was affected.
Until MetaMask publishes a fuller post-mortem, those questions remain unresolved. But the information available so far points toward a precautionary validator shutdown designed to contain an infrastructure breach rather than the widespread liquid staking exploit initially feared.
Check your email to confirm
We sent a confirmation link to . Confirm it to activate your Kyroo cashback — you can do this anytime.
You're in! Taking you to {partner} in ...