On-chain analyst Kaden reports that a security incident involving MetaMask validators stems from tampered block reward recipient addresses. Of 19 validators that earned rewards, 18 had payments redirected to an address funded by Tornado Cash rather than the correct fee recipient. The attacker captured approximately 0.36 ETH in rewards and does not currently appear capable of extracting staked principal. Approximately 17,000 validators have voluntarily exited following the breach, representing about 523,000 ETH. Three suspected compromised validators remain active alongside 821 other potentially affected validators still running for unclear reasons. While the attacker's full capabilities regarding fee address modification remain unknown, there is theoretical risk of malicious slashing if signing permissions were broadly compromised.