
MetaMask is investigating a security incident that has affected part of its infrastructure, but details have not been disclosed. The only statement from September 30 was brief: there is no threat to wallets, and validators are being withdrawn from staking as a precautionary measure. Since then, there have been no new updates.
While the company remains silent, on-chain researchers are conducting their own investigations. Researcher kaden.eth found that 19 MetaMask validators won the right to propose a block in one day, but rewards for 18 of them went not to the legitimate recipient, but to an external address funded through the Tornado Cash mixer. Analyst m4rio from Cantina clarified that the hacker's wallet is completely new, having made no transactions prior, and the received funds remain on it.
The timeline for September 30 is as follows. At 10:27, a new wallet received 0.0978 ETH from the Tornado Cash pool of 0.1 ETH via relayer reltor.eth. Around 11:00, MetaMask and Consensys validators began exiting the network. At 12:12, the first block reward arrived at the wallet via Titan Relay – 0.008168 ETH, and at 12:42, Consensys deleted 400 unused Lido keys. From 12:12 to 16:46, the attacker's address collected rewards from 18 blocks: 11 proposed by Consensys validators in Lido, two by EthFoxVault, and five by client validators. In total, about 0.36 ETH. After 16:46, rewards began arriving to the correct recipients again.
The key question is how the attacker gained access to the recipient configuration for the fees. According to kaden.eth's estimate, the attacker likely could not withdraw staked ETH, but theoretically could provoke slashing if they had access to the signing keys. In total, about 17,000 validators were proactively removed from the network with 523,000 ETH, while three compromised ones remained online, and 821 potentially affected validators were not withdrawn.




