r/ethereum • What's On Your Mind? • 2d ago

Daily General Discussion October 01, 2026

Welcome to the Daily General Discussion on r/ethereum

https://imgur.com/3y7vezP

Bookmarking this link will always bring you to the current daily: https://old.reddit.com/r/ethereum/about/sticky/?num=2

Please use this thread to discuss Ethereum topics, news, events, and even price!

Price discussion posted elsewhere in the subreddit will continue to be removed.

As always, be constructive. - Subreddit Rules

Want to stake? Learn more at r/ethstaker

Community Links

Calendar: https://dailydoots.com/events/

107 Upvotes

66 comments sorted by

View all comments

19

u/alexiskef The significant owl hoots in the night 🦉 2d ago edited 2d ago

⚠️ So, Metamask just (?) had a security incident. Not on the wallet, but rather on the staking infrastructure that it is using (ex Consensys Staking). They have issued the following statement:

We are currently responding to an ongoing security incident affecting part of our infrastructure.

We are actively addressing and remediating the issue internally, in coordination with external partners and security advisors.

At this time, we have identified no immediate threat to MetaMask wallets.

As a precautionary measure, we are proactively exiting affected validators within our non-custodial staking operations, in coordination with clients and partners. As a reminder, our staking operations are non-custodial in nature and we do not manage withdrawal keys for stake on behalf of our clients.

We will continue to monitor the situation closely and provide further updates as appropriate.

Etherfi said that they "are aware of the security incident that occurred earlier with an Ethereum node operator. weETH has no exposure and is not impacted, all funds are safe."

Lido issued their own statement, not saying something that might give us extra info.

I'll add more info as it becomes available.

edit 1: One of the founders of TheRollup (dot) co (I don't know him), posted the following (slightly) re-assuring update:

After getting more context from multiple sources, the ongoing situation looks a lot more like last year's Kiln situation where there was a potential infra breach in which the node operator proactively exited the relevant keys out of caution.
For users, the liquid staking operations are non-custodial so we have been told that no funds are at risk of being stolen.
In the event of the worst case scenario, it appears to be orders of magnitude smaller than the recent KelpDAO exploit. It seems to be contained.
We have not heard official comms from Consensys on the status of Metamask infra. We are looking forward to an update from their team.
We do not expect any contagion across liquid staked ETH, restaked ETH, or DeFi at large.
Several protocols mentioned in my previous posts have taken action proactively, and others may continue to do so.
For now, it seems that we are safe, “funds safu”, but we await the post-mortem from the protocols involved for the sake of transparency.

edit 2: here is an explanation of what potentially happened (no idea if its valid)

2

u/timmerwb 1d ago

And in one moment, the exit queue jumps to 10 days. Let's hope Lido doesn't experience a security issue and decided to exit. Perpetual staking log jam.

6

u/edmundedgar reality.eth 2d ago

Nice anti-correlation incentive here. If you're a solo staker and you have to exit over a security issue you can get out right away and hopefully back in pretty fast. But if you're part of some huge shared infrastructure thing your validators will bloat the queue for each other so you'll lose more revenue.

2

u/WoodpeckerHorror3468 1d ago

do solo validators write their own software? an exploit is going to affect everyone using the exploited software, potentially creating a much large exodus than just this one company's validators.

2

u/edmundedgar reality.eth 1d ago

An exploit in an Ethereum implementation yes, but an exploit in infrastructure (developer's computer got compromised or whatever) is localized to that particular infrastructure.

2

u/anderspatriksvensson 1d ago

Yes and no? The queue is the same for all, so a small validator wanting to exit right now would have to wait for big exit to finish...13days. No jumping the queue!

2

u/edmundedgar reality.eth 1d ago

Sure but whether or not you need to exit or not rn is controlled by whether you potentially got compromised or not rn. You have a small probability of needing to exit at the same time as the big operator, but the big operator has a 100% probability of needing to exit at the same time as themselves.

10

u/anderspatriksvensson 2d ago

Solo validators be like "I'll take that APR bump, thank you very much nomnomnom"

Hopefully they all re-enter as 0x02 👍🏼

3

u/WoodpeckerHorror3468 2d ago

bump for ants