MetaMask Validator Breach Drives Ethereum Exit Queue Higher

Lido exits follow infrastructure compromise as separate Safe exploit drains 114.09 ETH
TL;DR
- MetaMask began exiting Lido validators after disclosing an infrastructure security incident on September 30, 2026.
- Kaden said about 17,000 MetaMask-operated validators holding roughly 523,000 ETH were being exited as Ethereum’s withdrawal backlog reached 773,447 ETH.
- Separately, SlowMist said a FlashLoopAdapter flaw allowed an attacker to drain about 114.09 ETH from two Safe wallets without affecting Aave V3’s core contracts.
Trade smarter on Jupiter, Solana’s leading DEX built for fast execution and deep liquidity.
Swap tokens at competitive rates, route across multiple liquidity sources automatically, and access perpetuals, DCA, and advanced trading tools — all in one place!
MetaMask Staking is exiting Ethereum validators it operates through Lido after MetaMask disclosed a security incident affecting part of its infrastructure on September 30, 2026. MetaMask said its staking operation is non-custodial and does not control clients’ withdrawal keys, while Lido said stETH holders do not need to take action. Separately, an unrelated exploit involving a third-party adapter built on Aave V3 drained about 114.09 ETH from two Safe wallets.
MetaMask said it was “actively addressing and remediating the issue internally, in coordination with external partners and security advisors.” A follow-up on October 1 said there was “no indication that MetaMask wallets or customer funds have been affected.” The staking business, formerly known as Consensys Staking, does not manage withdrawal keys for client stake. The supplied account said compromised validator signing keys could still create slashing risk if misused.
Onchain security researcher Kaden said about 17,000 MetaMask-operated validators holding roughly 523,000 ETH were proactively exited after analysis found transaction-fee rewards from 18 of 19 validators that proposed blocks had been redirected to an address funded through Tornado Cash. Kaden estimated the attacker captured about 0.36 ETH. MetaMask had not confirmed those figures.

Kaden also said 821 potentially affected validators had not yet exited, including three whose fee rewards were allegedly diverted. MetaMask had not disclosed how many validators were affected, whether signing keys were exposed or whether any slashing had occurred.
Ethereum Exit Queue Reaches Nine-Month High
Lido said the final validators were expected to enter the exit process by the end of October 7. The protocol estimated that completing the exit, withdrawal and eventual re-entry cycle could take up to 45 days. Lido’s security arrangements also include an ad hoc reserve fund of more than 6,750 stETH.

The backlog was the largest since December 2025. Ethereum limits how quickly stake enters or leaves its validator set, so a large wave of exits is processed gradually rather than simultaneously.
Separate Adapter Exploit Drains Safe Wallets
SlowMist reported on October 2 that attackers exploited FlashLoopAdapter, a third-party contract used to manage leveraged Aave V3 positions. The adapter’s open() and close() access control checked ISafe(msg.sender).isModuleEnabled(address(this)), which SlowMist said was “spoofable via a fake Safe that always returns true.”

The attacker used a Morpho WETH flash loan to repay debt and unlock collateral, then manipulated the router and transaction data to move weETH and Aave-linked collateral. Around 1,306 weETH moved from one wallet, but that represented gross movement rather than the attacker’s final gain. The loss was about 114.09 ETH, valued at roughly $305,000 to $310,000. Both affected Safes belonged to the same owner, who disabled the module afterward.
The stolen funds were consolidated at 0x7a83…42f1 before being sent in batches toward Tornado Cash. Aave founder Stani Kulechov said, “This is not Aave v3 contract, it’s third party external adapter built on top of Aave, zero effect on Aave v3.” The incident therefore involved the external automation layer rather than Aave V3’s core contracts or liquidity pools.
This article has been refined and enhanced by ChatGPT.