MetaMask is withdrawing affected Ethereum validators from its non-custodial staking service after detecting a security issue within its infrastructure. Lido expects the last affected validators to complete the exit process by October 7, 2026, although the full withdrawal and return-to-staking process could take as long as 45 days.
MetaMask said it has not identified an immediate threat to customer wallets.
The company said in a recent user update that it was addressing an ongoing security incident involving part of its infrastructure. MetaMask is working with external security advisers and other partners while implementing precautionary measures, including removing affected validators from its staking operations.
MetaMask Staking, formerly operated under the ConsenSys Staking name, runs Ethereum validators through Lido. A disclosure on Lido’s governance forum said the operator began exiting validators after investigating the infrastructure compromise.
MetaMask controls the signing process for the validators it operates but does not hold customers’ withdrawal keys. As a result, it cannot independently transfer the underlying staked ETH on behalf of users.
No Action Required From stETH Holders
Lido said holders of stETH do not need to take any steps because of the validator exits. The incident could nevertheless result in costs for affected validators.
Validators that leave the active set may stop earning rewards during the transition. In addition, taking validators offline before they complete the exit process could create downtime penalties if the measure is used to reduce broader network-penalty risks.
The situation illustrates how failures or compromises at infrastructure providers can affect staking operations without necessarily involving an exploit of the underlying blockchain or protocol.
The scope of the incident remains unclear. MetaMask and Lido have not disclosed how many validators were affected or how much ETH is tied to them.
Previous Large-Scale Lido Exits
Lido says its distributed network of node operators and security controls are designed to limit the effect of individual infrastructure disruptions. Its protections include an ad hoc reserve containing more than 6,750 stETH.
There are earlier examples of precautionary validator exits. In September 2025, Kiln removed 5,726 validators across networks after an attacker obtained infrastructure access using a compromised GitHub token. Lido subsequently estimated that the event resulted in about 207 ETH in lost protocol rewards.
In 2023, the same staking provider, operating at the time under the Consensys name, accidentally exited 125 Lido validators and later compensated stakers for their lost rewards.
Those cases show that validator exits can create reward-related costs, but they do not establish that the current MetaMask incident involved the same attack method or will produce a similar outcome.
Ethereum’s validator queues will also influence how quickly affected ETH can return to active staking.
Why the Process Could Take 45 Days
Lido expects the final affected validators to have exited by October 7, but the associated ETH will not necessarily become available for immediate redeployment.
After exiting, the stake must move through the withdrawal process before it can be used to activate validators again. Lido estimates that the entire exit, withdrawal and re-entry sequence could take up to 45 days because of the lengthy Ethereum validator entry queue.
The estimate represents the potential duration of the complete cycle rather than a fixed lockup period for every affected ETH position. Individual validators can move through the stages at different speeds.
Exited stake may also stop generating rewards until it becomes active again.
MetaMask and Lido said their investigation is ongoing and that additional updates will be provided when more information is available. The main outstanding questions concern which part of MetaMask’s infrastructure was compromised and whether the incident extended beyond the systems supporting its staking operation.
Based on the information disclosed so far, the response centers on precautionary validator exits, with no immediate wallet threat reported and no disclosed exploit of the Lido protocol itself.

































