MetaMask separates the incident from its wallets
The key issue is the actual scope of the compromise. MetaMask initially said that part of its infrastructure was experiencing a security incident, before beginning to remove some of the Ethereum validators operated as part of its staking activities.
This caution is a reminder that crypto attacks now target infrastructure and validation systems just as much as the wallets themselves.
Joseph Lubin has now gone further. According to him, the investigations conducted so far show no impact on users’ wallets, their funds, recovery phrases or private keys.
That is partly due to how MetaMask works: the wallet is non-custodial. The recovery phrase and private keys used to control assets are held by the user, not by MetaMask on a centralized infrastructure. Lubin therefore stresses that this sensitive part was outside the scope of the incident.
That does not mean the incident was insignificant. MetaMask has nevertheless begun withdrawing several validators operated for its clients, including through Lido.
Validator keys were replaced
To understand MetaMask’s response, it is important to distinguish between two types of keys.
A validator key allows an Ethereum validator to participate in the network’s operation. It is used in particular to sign attestations and propose blocks. Its compromise can disrupt the validator, create operational risks or result in certain penalties.
A withdrawal key, meanwhile, controls the destination to which staked ETH can ultimately be withdrawn.
In other words, one lets the validator do its job. The other lets users recover the money.
Lubin says that MetaMask and its teams do not hold their clients’ withdrawal keys. Even if part of the validator infrastructure had been compromised, the attacker therefore would not automatically have had the means to transfer the staked ETH to their own wallet.
As a precaution, MetaMask and its partners nevertheless carried out a rotation of validator keys, meaning that potentially exposed keys were replaced. This operation requires some validators to exit and then re-enter the Ethereum staking system.
The distinction matters in an environment where malware is already targeting the keys, passwords and data used to access crypto wallets directly. No such compromise has been identified here.
Validators remain the area to watch
Lido confirmed on September 30 that MetaMask Staking was withdrawing some of its validators after the incident was discovered. The last affected validators were expected to have left their active role by October 7, although the full return of the ETH may take much longer.
Lido says the entire exit, withdrawal and possible return-to-queue cycle can take up to 45 days. Staking rewards may therefore be lost during this period, and some validators could incur minor penalties related to their unavailability.
stETH holders are not, however, being asked to take any specific action. Lido also emphasizes the non-custodial nature of the system and MetaMask’s lack of control over the keys that would allow its clients’ funds to be withdrawn directly.
This case illustrates an important distinction that is sometimes overlooked when a major crypto name announces an incident. “MetaMask suffered a compromise” does not automatically mean “MetaMask wallets were hacked.”
BrefCrypto already noted in its guide to crypto wallet security that the recovery phrase is the central key to a non-custodial wallet. As long as it remains under the user’s exclusive control, a vulnerability affecting a peripheral service does not necessarily provide access to the funds.
The investigation is not yet fully complete, however. MetaMask continues to work with its partners and security specialists to determine the precise origin and scope of the compromise.
For now, the separation of the keys appears to have served its purpose: the staking infrastructure was affected enough to force validators to exit, without providing access to clients’ ETH or MetaMask wallets.