after some onchain sleuthing, i think this is what happened:
19 metamask validators had won block rewards, and 18 of the rewards were not paid to the correct fee recipient but instead to this tornado funded account: 0x98B9231de84334c1d48BA0b72CF13f92484924A3
~17k validators proactively exited, ~523k eth total, unknown whether the attacker had the ability to change all fee recipients
it appears that 3 of the exploited validators have not yet been exited, and that 821 potentially impacted validators in total have yet to exit, unclear why
attacker only stole ~0.36 eth in rewards and likely never had the ability to withdraw any staked eth. however, depending on how the attacker managed to get signing access, they could potentially cause the validators to be intentionally slashed
Security Update: We are responding to a security incident affecting part of our infrastructure.
At this time, we have identified no immediate threat to MetaMask wallets.
As a precaution, we are proactively exiting affected validators within our non-custodial staking operations, in coordination with clients, partners and security advisors.
We’ll share further updates as appropriate.
metamask.io/news/user-update…