
Security incident leads to diverted rewards and a record-high Ethereum withdrawal backlog
AI-generated summary
Ethereum limits the rate at which validators can exit to maintain network stability. MetaMask operates a non-custodial staking service.
MetaMask is pulling thousands of Ethereum validators after a security breach redirected rewards, creating a network-wide backlog for stakers trying to exit.
Onchain security researcher Kaden said about 17,000 MetaMask-operated validators holding roughly 523,000 ETH were proactively exited after an analysis found that transaction-fee rewards from 18 of 19 validators that proposed blocks had been diverted to an address funded through Tornado Cash, an Ethereum-based privacy protocol that allows crypto transactions to be mixed and anonymized.
The attacker appears to have captured only about 0.36 ETH, according to Kaden. The bigger concern is how the attacker gained enough access to alter fee recipients and whether that access extended to validator signing keys, which could trigger slashable behavior.
MetaMask has not confirmed those figures or disclosed the cause of the incident. Instead, the company said that part of its infrastructure had been compromised and that it was exiting affected validators as a precaution while working with clients, partners and security advisers. It said it had identified no immediate threat to MetaMask wallets.
The company also said its staking operation is non-custodial and that it does not control clients' withdrawal keys. That separation would prevent an attacker with only validator-level access from withdrawing the underlying stake, but it would not eliminate the possibility of penalties if signing keys were compromised and misused.
Kaden said 821 potentially affected validators had not yet exited, including three among those whose fee rewards were allegedly diverted. It remains unclear why they are still active or whether the attacker retained access to change additional fee recipients.
MetaMask has yet to disclose how many validators were affected, whether signing keys were exposed or whether any slashing has occurred.
Meanwhile, the security incident and the exits are already rippling through Ethereum's staking infrastructure.
About 773,447 ETH was waiting to leave the validator set on Wednesday, according to Validator Queue data, implying a 13-day, 10-hour wait before an exiting validator clears the queue. A further withdrawal sweep delay was estimated at 7.6 days.
That is the largest exit backlog since December 2025 and above the roughly 476,000 ETH waiting during a previous surge in May, according to Validator Queue's historical data.
The bottleneck reflects a safeguard built into Ethereum rather than an inability to process transactions.
Ethereum limits how quickly stake can enter or leave its validator set to prevent abrupt changes from destabilizing its proof-of-stake consensus. The Validator Queue showed a churn rate of 256 ETH per epoch, with each epoch lasting about 6.4 minutes. At that rate, a large burst of exits must be processed gradually rather than simultaneously.
The additional 7.6-day sweep period begins after validators clear the exit queue and become withdrawable. Ethereum then cycles through eligible validators and transfers balances to their designated withdrawal addresses.

Ethereum validators face a crucial configuration choice ahead of the Glamsterdam upgrade on the Sepolia testnet on Oct. 6, where they must manually override default software settings to test an aggressive 200 million gas limit.

MetaMask is exiting its Ethereum validators from the Lido protocol due to an ongoing security incident affecting its infrastructure. The non-custodial move impacts thousands of validators while users' funds remain safe.

Base's Cobalt upgrade, scheduled for mainnet on Sept. 30, will allow B20 token issuers to configure balance seizures separately from ordinary transfer restrictions using a new seizeWithMemo function.

Uniswap Labs’ StablePair hook for Uniswap v4 uses a configured reference rate to fee trades in USDC/USDT and USDC/USDG pools, aiming to capture rebalancing value for liquidity providers while exposing them to inventory risk if token values diverge from the benchmark, with governance controlling the benchmark and upgrade limits preventing certain fee-skimming mechanisms.

Bitcoin Improvement Proposal BIP461 introduces a deterministic ECDSA signing procedure to detect deviations that may indicate wallet key leakage. Authored by Liam Gilligan and merged as a draft on Sept. 16, it requires no consensus change. The proposal enables comparison of signatures across independent signers to identify non-compliant behavior, though mismatches alone cannot confirm theft or malicious intent.

Google launched Gemini 4 Argon, its new frontier AI model, claiming top performance in coding and cyber defense benchmarks. Argon scored 77.9% on DeepSWE v1.1, supports up to 1 million tokens per response, and shows improved resistance to indirect prompt injection at 0.7% on Gray Swan's test. The model is being rolled out via Google's Fairwind Program to vetted security teams and includes no built-in cyber guardrails to enable offensive security research, with wider availability planned for paid API users and Google AI Ultra subscribers at introductory pricing of $2 per million input tokens and $10 per million output tokens.