Lido Validators Exit MetaMask After Infrastructure Breach

MetaMask has begun removing affected Ethereum validators from its non-custodial staking service following a compromise involving part of its infrastructure. Lido expects the remaining affected validators to exit by October 7, 2026, while the complete process of withdrawal and returning the stake to active validation could take up to 45 days.

MetaMask said it has not found evidence of an immediate risk to its users’ wallets.

In an update to users, the company said it was responding to an ongoing security incident and working with external partners and security specialists on remediation. As a precaution, MetaMask is exiting validators associated with the affected infrastructure.

MetaMask Staking, which previously operated as ConsenSys Staking, runs Ethereum validators through Lido. According to a disclosure on Lido’s governance forum, the operator started the exit process after investigating the infrastructure compromise.

The staking service signs transactions for the validators it operates but does not hold customers’ withdrawal keys. Consequently, MetaMask cannot use those keys to move customers’ underlying staked ETH.

stETH Holders Do Not Need to Act

Lido said stETH holders do not need to take any action following the validator exits. The affected validators could still incur costs during the process because they may stop receiving staking rewards while inactive.

Taking validators offline before they complete their exit can also result in downtime penalties, although such steps may be used as a precaution to limit potential network-related penalties.

The incident demonstrates a broader infrastructure risk in crypto staking. A compromise affecting a service provider can interrupt validator operations even when there is no reported exploit involving the underlying blockchain protocol.

The number of affected validators and the amount of ETH connected to them have not been disclosed by MetaMask or Lido.

Lido Has Dealt With Validator Exits Before

Lido says its network of independent node operators and security measures are intended to contain operational disruptions. The protocol also maintains an ad hoc reserve fund with more than 6,750 stETH.

Previous incidents provide some context. In September 2025, Kiln exited 5,726 validators across several networks after an attacker used a compromised GitHub token to gain access to its infrastructure. Lido later estimated that the incident resulted in around 207 ETH in missed protocol rewards.

In 2023, the same operator, then known as Consensys, accidentally exited 125 Lido validators and compensated affected stakers for the rewards they lost.

These examples show that large validator exits can have financial consequences, but they do not indicate that the current MetaMask incident resulted from the same type of compromise or will follow the same resolution.

Ethereum’s validator queues are also important because they determine how quickly exited ETH can be put back into active staking.

ETH May Take Weeks to Return to Staking

Lido expects the final affected validators to exit by the end of October 7, but the ETH associated with them will not necessarily return to active staking immediately.

The stake must first pass through the exit and withdrawal stages before being used to activate validators again. Lido estimates that the complete sequence could take up to 45 days because Ethereum’s entry queue remains extended.

The 45-day figure represents the potential length of the overall process, rather than a fixed period during which every affected ETH will remain inactive. Validators can move through the stages at different speeds.

During this period, exited ETH may not generate staking rewards until the corresponding validators become active again.

MetaMask and Lido said their investigation is still underway and that further information will be released as it becomes available. Key details remain unresolved, including which part of MetaMask’s infrastructure was compromised and whether systems outside its staking operations were affected.

So far, the disclosed response involves precautionary validator exits, while MetaMask reports no immediate threat to its wallets and neither party has disclosed an exploit of the Lido protocol itself.