MetaMask Pulls Validators as Small ETH Theft Raises Major Alarm

Written by

in

Key Highlights

  • An attacker appears to have redirected about 0.36 ETH in rewards from 18 of 19 MetaMask validators.
  • Blockchain analyses indicate that hundreds of thousands of ETH may have been moved toward the validator exit queue.
  • Although the apparent theft was small, potential exposure of validator signing keys could have created a much larger slashing risk.

MetaMask Validator Incident Redirected Rewards but Raised Larger Security Concerns

Ethereum validators generally stake 32 ETH, but MetaMask says its staking operation is non-custodial and that it does not control customers’ withdrawal keys. Those keys allow the underlying stake to be withdrawn. As a result, an attacker who tampered with validator settings would not automatically gain access to the staked ETH itself.

On-chain researcher Kaden’s reconstruction instead points to the validators’ fee-recipient address, where block tips and other payments are sent. Kaden reported that 19 MetaMask validators received block rewards and payments, but 18 directed those funds to an incorrect fee-recipient address. The address had previously been funded through the ether mixing service Tornado Cash, and the diverted payments totaled approximately 0.36 ETH.

A separate reconstruction traced the activity to roughly four and a half hours on September 30. The apparent amount taken was small, but the incident raised a much larger concern: whether an attacker had obtained validator signing keys capable of disrupting or penalizing a broader group of Ethereum validators.

Why MetaMask Took Broad Action on Validator Exits

Changing a validator’s fee recipient can redirect block tips without moving its 32 ETH stake. The risk becomes substantially greater if an attacker obtains validator signing keys. While those keys cannot simply be used to withdraw the stake, they may allow proof-of-stake validators to commit offenses punishable under Ethereum’s slashing system.

Slashing destroys part of a validator’s stake and removes the validator from service. Kaden said three exploited validators had not yet exited when the analysis was published and estimated that approximately 821 potentially affected validators remained active.

Blockchain data infrastructure firm Bitquery conducted a separate analysis and counted 16,965 validators holding 565,056 ETH that had either exited or entered the exit queue by October 1. The figures differ from Kaden’s because the researchers examined different groups of validators at different times. Neither estimate has been publicly confirmed by MetaMask.

Bitquery also estimated that a hypothetical simultaneous slashing event involving roughly 17,000 validators could have destroyed about 22,000 ETH. Its reconstruction found that no validators had been slashed. That potential loss helps explain why MetaMask initiated a defensive operation far larger than the apparent reward diversion itself.

Ethereum Validator Exits Could Take Up to 45 Days

Liquid-staking infrastructure provider Lido expects the affected validators it uses to complete the exit process by the end of October 7. However, returning that ETH to active earning status will take longer. Validators must complete Ethereum’s exit process, withdraw their funds and later rejoin through the entry queue.

Lido estimates that the full process could take approximately 45 days. During that period, the exited stake will not earn validator rewards. The delay is also affected by existing congestion in Ethereum’s validator queues.

Validator queue data from beaconcha.in showed approximately 393,795 ETH waiting to leave Ethereum’s validator set. The estimated time to clear the exit queue was four days and six hours, followed by another withdrawal delay.

Lido said stETH holders do not need to take action. MetaMask has given wallet users the same guidance and warned them not to provide recovery phrases to anyone claiming to offer protection. For now, the on-chain record shows approximately 0.36 ETH apparently diverted, hundreds of thousands of ETH moving toward validator exits and potentially weeks of lost earning time. The available evidence indicates that the attacker reached validator rewards, but MetaMask has not said exactly how close the intruder came to the underlying stake.

Why This Matters

The incident highlights the difference between access to validator rewards and access to staked ETH. Redirecting a fee recipient can affect tips without directly controlling withdrawal keys, but compromised validator signing keys could expose users to slashing, forced exits and extended periods without rewards.

The size of the defensive response also reflects the potential scale of the risk. Even though the apparent diversion was about 0.36 ETH, analyses indicated that thousands of validators and hundreds of thousands of ETH may have been involved in exit activity. The affected validators’ return to active staking will depend on Ethereum’s exit and entry queues, which could keep the financial impact going well beyond the initial incident.

Frequently Asked Questions

How much ETH was apparently diverted from MetaMask validators?

Kaden’s analysis identified approximately 0.36 ETH in redirected block rewards and payments. The funds were associated with 18 of 19 MetaMask validators examined.

Could the attacker withdraw the validators’ 32 ETH stakes?

Not automatically. MetaMask says its staking operation is non-custodial and that it does not control customers’ withdrawal keys. However, access to validator signing keys could potentially enable actions that trigger Ethereum’s slashing penalties.

How long could affected validators remain out of service?

Lido estimated that the complete exit, withdrawal and re-entry process could take approximately 45 days. During that time, the exited stake would not earn validator rewards.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *