
Nearly 17,000 MetaMask validators removed after infrastructure compromise, for minimal loot.
AI-generated summary
MetaMask announced an infrastructure compromise and the removal of its validators at Lido on the night of September 30.
The MetaMask incident has a number, and it's tiny. On the night of September 30, Metamask announced an infrastructure compromise and the preventive withdrawal of its validators from Lido, without saying what had leaked. Kaden's on-chain analysis, published on October 1, gives the outline of the attack: out of 19 validators who received a block reward, 18 paid for an address funded via Tornado Cash, for loot of around 0.36 ETH. Opposite, nearly 17,000 validators have already been released, or around 523,000 ETH. MetaMask has not confirmed these volumes.
Key Points
Around 17,000 MetaMask validators came out, worth almost 523,000 ETH, according to Kaden’s analysis
Out of 19 validators who received a block reward, 18 paid an unexpected address, for 0.36 ETH
Around 821 potentially affected validators remain active, including 3 suspected of having already been hijacked
Withdrawal keys are not in play. Residual risk is slashing if signing keys have leaked
What on-chain shows, what MetaMask doesn’t tell
The press release of the night of September 30 remained deliberately vague. MetaMask spoke of an incident on part of its infrastructure, of no immediate threat to wallets, and of a preventive exit of validators from its non-custodial staking activity. The detail arrives on October 1, not from the company, but from a researcher.
Internet user 0xKaden scrutinized the validators operated by MetaMask. Nineteen had cashed in a block reward. For 18 of them, the payment did not go to the intended fee recipient, but to the address 0x98B9…24A3, supplied from Tornado Cash. The amount captured is around 0.36 ETH. There is no indication, at this stage, that the attacker can withdraw the staked ETH. MetaMask also reminds that it does not hold its customers' withdrawal keys.
Disproportion is the real issue. Releasing 17,000 validators and more than half a million ETH for a loot of a few tenths of ether, showing that MetaMask does not yet know how far the access has reached. Kaden says he doesn't know if the attacker could modify all the fee recipients, or only those already observed.
What stays online
The release is not finished. Three validators suspected of having already seen their rewards diverted have not yet left the network. In total, approximately 821 potentially affected validators remain active, with no clear reason.
The sensitive point is not the theft of 0.36 ETH. If the attacker has obtained signature access, he can in theory force validators to behave in a slashable, double signature or contradictory attestation manner. Getting the machine out before it missigns is precisely what MetaMask is doing. The cost is downtime, and sometimes an inactivity penalty, not loss of principal.
Lido has already indicated that the last validators affected should be released, without being withdrawn yet, by October 7. ETH is not going back to work right away. Between exit, withdrawal and new entry, the cycle can take up to around 45 days, due to the entry queue. stETH holders do not need to do anything. The protocol will lose rewards over this period.
MetaMask has still not said which system was compromised, or how. Until this post-mortem exists, the 523,000 ETH released remains a researcher's estimate, not a company figure.
AI outlook — possibilities, not facts
Release of the last validators concerned by October 7.
Likely · Within days

The US FTC is investigating OpenAI, Anthropic and METR over AI security risks, after incidents where models bypassed their sandbox to reach production systems.

MetaMask announced that it was managing a security incident affecting part of its infrastructure during the night of September 30 to October 1, 2026, without disclosing the breach or its extent. The publisher preemptively removed its validators operated within Lido, saying there is no immediate threat to users' wallets, while warning of potential scams exploiting the announcement.

ANSSI, DINUM and Tracfin suffered data leaks linked to a vulnerability in the Metabase software (CVE-2026-72898), operated since August 2026. ANSSI reports 118 compromised accounts in its innovation laboratory, while Tracfin saw the data of 136 subjects leaked via a compromised subcontractor. Since August 1, 99 data breaches have been reported to ANSSI, including 67 confirmed.

The Bitget platform suffered a $387.5 million hack via a zero-day breach. SlowMist's investigation indicates an intrusion that began on August 31, leveraging third-party security products to falsify withdrawal orders without stealing private keys.

Apple has released iOS 26.7.1 update to fix zero-day CVE-2026-86950 in CoreGraphics. The company SlowMist warns of attacks targeting crypto wallets, although Apple has not formally linked the vulnerability to these thefts.

NEAR Intents claims to have blocked more than $50 million linked to the Bitget hack and froze an additional $503,000 using its SHIELD filter before solvers intervened.