Skip to content

Invest1 publisher3 min readPublished

Lido says MetaMask's precautionary validator exit will mean foregone staking rewards, no action needed from stETH holders

MetaMask is pulling its Ethereum validators out of Lido after an infrastructure compromise, putting the stake on a round trip Lido says can take up to 45 days. The stake earns no rewards on the way, and stETH holders share that cost, for an attack whose only documented theft so far is diverted block rewards.

The Investor · Invest desk

Illustration accompanying Lido says MetaMask's precautionary validator exit will mean foregone staking rewards, no action needed from stETH holders

What happened

  • Lido expects the last of the affected validators to have exited, though not fully withdrawn, by the end of October 7.
  • Unconfirmed onchain analysis by researcher Kaden found 18 of 19 MetaMask block rewards sent to a Tornado Cash-funded address, about 0.36 ETH in all.
  • The same analysis counts about 17,000 validators holding some 523,000 ETH being exited, with 821 potentially affected validators yet to leave.
  • Both firms say the staking arrangement is non-custodial and that MetaMask does not hold withdrawal keys for client stake.
  • Kiln, another major Lido operator, exited all of its Ethereum validators in September 2025 after a potential compromise of its infrastructure.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • constraint Because re-entry runs through Ethereum's extended entry queue, a precautionary exit keeps stake out of rewards for weeks, however small the breach that prompted it.
  • exposure Clients of MetaMask Staking outside Lido cannot yet tell whether their validators share the compromise, since neither firm has said whether they are involved.
  • precedent Two full precautionary exits at major Lido operators in about a year make emptying the validator set the expected answer to a suspected operator compromise, with the pool absorbing the yield each time.

On figures from the researcher Kaden, which neither company has confirmed, the stake being exited is about 1.45 million times the ETH the attacker is known to have diverted [6][1]. The exit protects against a different loss. Kaden said the attacker "likely never had the ability" to withdraw staked ETH, but that validators could in principle be deliberately slashed depending on how signing access was obtained [9]. Neither company has said what was compromised, how, or by whom [10].

Leaving costs yield. Lido said the move will likely mean forgone rewards, and possibly downtime penalties if validators go offline in the coming days to limit the risk of network penalties [11]. The stake then returns to the protocol in stages as validators work through exit, withdrawal and re-entry [3]. Each percentage point of annual yield on 523,000 ETH is worth about 645 ETH over 45 days, and less in practice because the stake does not all come back on the last day [2].

In my view that cost falls on stETH holders as a group, including those who never chose MetaMask as an operator, because the stake returns to the protocol whose liquid staking token they hold [3][12]. By Lido's account the 45 days describe the stake's round trip, and holders have been told no action is required [12]. Lido also pointed to its spread of node operators and an ad hoc reserve fund of more than 6,750 stETH as buffers against disruption [12]. The reserve is about 1.3% of the stake being exited [3]. It exceeds 45 days of rewards on all of that stake at any annual yield below about 10.5% [4].

If the diverted block rewards were the whole attack, the bill is yield plus whatever downtime penalties accrue [11]. Should the attacker hold signing access to validators still in the set, the slashing Kaden described becomes the live risk, and the reserve is the buffer that would be tested [9][12].

I think the first case is the likelier one, because the only theft anyone has documented is diverted block rewards [6]. The counter-case comes from the same researcher, who said it was unclear whether the attacker could alter fee recipients across the whole set [9]. A handful of redirected payments may be a narrow view of a wider access. One deliberate slashing among the remaining validators would prove the first case wrong.

Aave founder Stani Kulechov said the lending protocol was watching the situation alongside Lido [14]. He said there had been no impact on Aave markets, where stETH is among the most widely used forms of collateral [14]. Ethena founder Guy Young said the assets backing its USDe synthetic dollar did not currently include direct exposure to stETH or any other liquid staking token [15]. He said he expected no impact [15]. MetaMask said it had identified "no immediate threat to MetaMask wallets" [2].

What to watch

  • A finding from MetaMask's investigation on how the attacker got in, and whether it reached validator signing keys.
  • Whether Aave reports any change in its stETH collateral markets while the exited stake is out of the protocol.
  • Any draw on Lido's ad hoc reserve fund, the first figure that would put a price on this beyond forgone rewards.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories