SSV Network Analyzes September 2025 Slashing Incident Impact
Joerg Hiller Sep 10, 2025 20:40
SSV Network's post-mortem reveals external factors behind the September 2025 slashing incidents affecting multiple validators. The protocol remains uncompromised.

In an in-depth post-mortem investigation, SSV Network has disclosed the findings of slashing incidents that occurred on September 10, 2025. The incidents, which affected a total of 40 validators, were confirmed to be caused by external factors, with the SSV protocol itself remaining uncompromised, according to SSV Network.
Incident Overview
The first incident was detected on September 10, involving a single validator. Approximately 1.5 hours later, a second, more significant incident impacted a cluster of 39 validators. Both were swiftly escalated and thoroughly investigated. The findings revealed that these incidents were not due to any failure within the SSV protocol, but rather operational errors in key management outside of the SSV infrastructure.
Key Takeaways
The post-mortem highlighted several critical lessons for validator operators:
- Validator Key Management: Ensure keys are confined to a single, trusted environment to prevent double-signing and potential slashing.
- Single Cluster Instance: Only one instance of a cluster should be active at any time to avoid redundancy issues.
- Slashing Protection: Slashing protection is crucial, particularly during maintenance or migrations, and is effective when keys are managed within SSV’s infrastructure.
SSV Network emphasizes that their design inherently reduces slashing risk by distributing responsibilities across multiple operators, but this protection is compromised if keys are operated outside the network.
Detailed Findings
For the first incident, logs and telemetry data confirmed that a double-signing violation occurred, but it was not initiated by SSV Nodes. For the second incident affecting 39 validators, it was determined that an internal maintenance mistake by Ankr, a key partner, led to the simultaneous operation of validator keys in separate infrastructures, causing the slashing.
Community and Partner Cooperation
SSV Network has extended gratitude to partners like Ankr for their quick response and transparency during the investigation. The network also appreciated the community's constructive engagement, which is deemed essential for maintaining network resilience.
Current Status
The SSV protocol continues to operate securely, with no required changes for operators or stakers. The incidents have been attributed to external operational errors, reinforcing the importance of robust key management practices.
Image source: Shutterstock